Security is not a layer you bolt on at the end of an IoT architecture. It cuts across every other layer, device, connectivity, edge, data, analytics and application, and the cost of treating it as an afterthought is now measurable: the average IoT security incident costs around $330,000, rising past $7 million for a breach involving connected medical devices (Swif, 2026).
What the security layer actually does
The security layer covers device authentication and identity, encrypted communication, access control, vulnerability management and incident response across an entire IoT deployment. It is not a single product; it is a set of practices and controls that need to be designed in from the device layer upward, because a vulnerability introduced at the hardware stage is far more expensive to fix once thousands of units are already in the field.
Why this matters more in 2026: the threat picture
The scale of the problem has grown sharply. Malicious IoT botnet activity increased roughly five-fold over the past year, with compromised devices climbing from around 200,000 to close to 1 million and now accounting for more than 40% of all DDoS traffic, according to Nokia’s Threat Intelligence Report (Swif, 2026). Three malware families, Mirai, Mozi and Gafgyt, account for roughly 75% of all malicious IoT payloads, and IoT malware attacks rose 124% in a single year, with more than 17 million attacks blocked against IP cameras alone (Swif, 2026).
Routers and network infrastructure, not endpoint devices, are now the riskiest category: routers account for more than half of devices carrying the most dangerous vulnerabilities, averaging around 32 vulnerabilities per device (Swif, 2026). Whatever device you are securing, its network path is a genuine part of the attack surface, not a separate concern.

Zero trust and device identity: the shift underway
Zero trust has moved from an emerging best practice to an operational expectation across regulated industries and hybrid IT/OT environments in 2026. For IoT specifically, this means device-level authentication rather than network-level trust alone, continuous validation of device identity rather than a one-time check at connection, and microsegmentation that isolates each device from every other device on the network rather than assuming anything inside the perimeter is safe (TrustCloud, 2026).
The practical foundation for this is machine identity: devices need cryptographic credentials, typically issued through digital certificates and public key infrastructure, that prove who they are before they are allowed to communicate, with mutual authentication verifying both sides of a connection rather than just the device (Device Authority, 2026).
Regulation is no longer optional
The regulatory floor has been rising. The EU Cyber Resilience Act’s incident reporting obligations begin on 11 September 2026, with its main obligations, security by design, vulnerability handling and lifetime patching, applying from 11 December 2027 (Swif, 2026). The US IoT Cybersecurity Improvement Act and frameworks such as ETSI EN 303 645 and ISO/IEC 27400 are pushing towards a more consistent baseline across a previously fragmented set of national and sector-specific rules (GlobalSign, 2026).
If you are shipping a connected product into the EU or a regulated sector, these are not future considerations. Security-by-design and a documented patching commitment need to be part of the product plan now, not a retrofit once a regulator asks.
What to check before you commit
- Device identity and authentication, not just network-level trust. Confirm each device has a unique, cryptographically verifiable identity rather than a shared credential.
- The network path, not just the endpoint. Routers and gateways are currently the highest-risk category; secure the whole path, not only the device at the edge.
- A real patching and update commitment, matched to how long the device is expected to remain in the field, and tested for what happens if an update fails.
- Which regulations actually apply to you, based on where you sell and what sector you serve; the EU Cyber Resilience Act and equivalent frameworks are no longer optional for many products.
- Incident response readiness, not just prevention. Confirm there is a plan for detection, containment and disclosure before an incident happens, not during one.
Related reading
- Understanding the Device Layer: sensors, actuators, embedded compute and hardware security
- The IoT Connectivity Layer: Choosing How Your Devices Talk to the World
About this page
Written by Mark Searle, founder of IoT Heart and an IoT connectivity professional with more than 20 years’ experience across network engineering, solution architecture and commercial connected services. This page is based on publicly available industry reporting and regulatory documentation, current as of August 2026; the threat landscape and regulatory requirements change quickly, so verify current obligations with a qualified advisor before relying on this as compliance guidance.
Want the practical version of updates like this delivered twice a month? Join the IoT Heart Briefing.
Sources
- Swif – IoT Security Statistics for 2026: Devices, Botnets, and the New Regulatory Floor
- TrustCloud – Zero-trust identity in 2026: What security leaders need
- Device Authority – The State of IoT Identity Security in 2026: Why Machine Identity Is the New Perimeter
- GlobalSign – IoT Security in 2026: Regulation, Standards & Trust
