The Future of Work · A Deep Dive

Past The Device: A Working Guide to Securing IoT in the Age of Autonomous Systems

A decade of “secure the device” checklists hasn’t secured the device. The connected estate has grown into a system nobody fully owns, and now AI agents are starting to act on what it produces. A working guide to the problem that actually needs solving, and the maturity model to solve it with.

A long read, built to be returned to. Opinion frames the argument; the evidence is grounded in current reporting from the U.S. Department of Justice, CISA, NSA and Five Eyes partners, Dragos, Fortinet, PwC, IoT Analytics, and Cloudflare's threat research unit.

01 — THE FRAME

A decade of checklists, and the failure they didn’t fix

In March 2026, the U.S. Department of Justice, working with police in Canada and Germany, took down the command-and-control infrastructure behind four botnets called Aisuru, KimWolf, JackSkid and Mossad. Between them they’d infected more than three million devices: routers, DVRs, webcams, off-brand Android streaming boxes. The largest attack they launched hit 31.4 terabits per second and lasted 35 seconds. Cloudflare’s threat team described the traffic volume as roughly the entire populations of the UK, Germany and Spain typing a web address and hitting enter at the same instant.

Here’s the part worth sitting with. The way these devices got infected was not new. Default credentials. Firmware nobody patched. Routers and cameras exposed to the open internet with no segmentation behind them. It’s the same recipe that built the Mirai botnet in 2016, the one that took down Dyn’s DNS infrastructure and briefly broke half the internet. A decade of “secure the device” guidance sat between those two events, and the failure mode didn’t change. Only the scale did: Mirai’s biggest attack against Dyn ran to roughly 1.2 terabits per second. Aisuru’s biggest ran to 31.4. Same playbook, twenty-five times the punch, ten years apart.

That’s the uncomfortable starting point for this guide. If you go looking for the classic IoT security literature, most of it reads like a checklist written for a smaller, calmer internet: change the default password, encrypt the data, patch the firmware, log the activity. The advice isn’t wrong. It’s exactly right, in fact, which is what makes the last decade so damning. We knew the answers and the answers didn’t stick, because the thing that failed was never really about any single device. It was about how the whole system around the device was built, owned, and, increasingly, who or what is now allowed to act on it.

Ten years of “secure the device” advice produced a botnet twenty-five times more powerful than the one that started the genre. The lesson isn’t that the advice was wrong. It’s that the device was never the actual unit of the problem.

This guide takes a different starting point. Instead of another list of things to lock down, it gives you a way to read your own estate: a maturity model with three tiers, device, system, and autonomous system, that tells you not just what’s exposed but what kind of exposure you’re carrying and what a serious response actually looks like at each level. Most organisations are stuck fighting tier one with tools built for it a decade ago. Very few have reached tier two. Almost nobody is ready for tier three, and tier three is already live in production, because the same AI agents reshaping every other part of the enterprise are now being pointed at the telemetry these devices produce.

Lead Form

Enter Your Details to Continue Reading

By submitting your details, you agree to receive emails from us, including resources, updates, and marketing communications. Unsubscribe anytime — your data stays private and is never sold, rented, or shared outside Eristotle.