
Last year, the number of connected Internet of Things (IoT) devices grew to over 18.8 billion, a 13% YoY increase, and that growth is expected to continue. Although many of these devices are compliant, the sheer volume of insecure devices are outpacing security measures and regulatory oversight.
In 2023, it was reported that, on average, 54% of organisations experienced weekly attacks on IoT devices. Although policy and standards have stepped in to establish security benchmarks for IoT, the many legacy devices still in use remain vulnerable to attack. Additionally, many devices are designed to be inexpensive and rushed to market, and as a result, lack adequate security and oversight. This has created a vast ecosystem where vulnerabilities persist.
While this paints a rather bleak picture of IoT security, it serves as a reminder that security is always a process rather than a destination. Regulation and standards have helped mitigate the number of attacks, but as the market matures, standards bodies and governments are already mapping out strategies to reinforce security across the entire ecosystem.
IoT security is unique in its scale and diversity. Unlike traditional IT systems, connected devices are often small, resource-constrained, and long-lived. Many early-generation products were never designed to be updated, leaving insecure devices in homes and businesses for years.
The challenge is compounded by consumer behaviour. A large portion of buyers in both the b2b and consumer markets are driven by cost, which continues to play a major role in the purchase journey. This has allowed cheap, insecure products with little or no support to flourish. Even when policies exist, enforcement at the point of sale can be weak, leaving buyers with little protection.
Meanwhile, the attack surface continues to grow. Each new device added to a network creates another potential entry point. And with the number of devices still increasing, even if the proportion of insecure devices declines and overall security improves, the absolute number of vulnerable products will remain significant for years to come.
Regulation in the market has been one of the most effective ways to defend against this growing security concern. In collaboration with governments, standards have been developed to ensure that both business and consumer devices have a strong baseline of protection.
When work on IoT standards began, only 7% of IoT products on the European market had any kind of vulnerability reporting mechanism. Today, that figure is estimated to be over 30%. While not perfect, it represents an almost fivefold improvement, driven in part by countries like the UK enforcing stricter regulations on connected devices.
Another example of regulation was the banning of universal default passwords. This single enforcement measure dramatically reduced the spread of IoT botnets, which for years had exploited weak or unchanged credentials. Since the standard took hold, attackers have been forced to adopt more sophisticated methods, demonstrating that the baseline security bar has been raised.
Elsewhere, consumer labelling initiatives are gaining ground by giving buyers clear information about whether a device meets basic security standards. This is especially important for businesses that need to meet “best practice” security to remain compliant. However, it’s not a perfect system: some cheap products will simply bypass this by printing or painting on fake labels that make their devices appear compliant.
But this is set to change. Comprehensive legislation, such as Europe’s Cyber Resilience Act, is poised to embed security by design into all products with digital elements. While these frameworks are complex, their long-term impact will help normalise security, much like electrical safety standards or data protection laws such as GDPR.
Even with stronger regulation, legacy devices and new technological risks remain significant hurdles.
Legacy equipment is perhaps the hardest to address. Devices already deployed, especially in critical or long-lived environments like energy or healthcare, may remain insecure for years. Without a process for secure updates or clear end-of-life policies vulnerabilities, will persist. In the majority of cases, time will be the only kill switch, as legacy devices are gradually discovered and replaced.
On top of this, a new threat emerging through Artificial intelligence (AI) presents a particular challenge for IoT devices. Gartner forecasts that, this year, more than half of AI data analysis will occur at the point of capture on IoT edge systems. Although the benefits to consumers are positive, this development dramatically expands the attack surface.
At the same time, we’re on track to reach quantum computing capabilities by the end of the decade, meaning all devices will need to transition to quantum-safe software. The challenge is that many IoT devices are small, and resource-constrained, and the new algorithms designed to protect them may exceed their power and processing limits. As a result, we could be living with millions of legacy devices which are left vulnerable at the end of the decade.
Regulation and policy interventions are not a silver bullet, but they are proving to be among the most effective tools for raising the security baseline and enforcing accountability across the industry.
Ultimately, success will depend on a combination of smart regulation, robust enforcement, and ongoing education for manufacturers and consumers. The goal is not perfection, but steady progress, improving security in stages. Introducing too many barriers at once can have the opposite effect, as complexity hinders adoption.
The next stage in regulating IoT should focus on eliminating the most obvious weaknesses and increasing accountability, making insecure products harder to sell and ensuring as many devices as possible remain secure.
Alex Leadbeater is TC Cyber Chair at ETSI
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543