As a research house with a key focus towards primary research methods, Kaleido conducts multiple surveys throughout the year to understand the requirements and perceptions of various ecosystem actors and customers. With cellular IoT security becoming an increasingly important topic in the industry, this year Kaleido conducted a survey with questions dedicated to two groups, security professionals and a more generalised IoT audience.
The full results and analysis of the dedicated cellular IoT security survey will be revealed later in the year via a whitepaper release and a webinar diving into the most pertinent elements. That said, this blog offers a useful opportunity to highlight some of the findings that have been uncovered during 2024. Notably, some of the most critical findings have tallied quite closely to the themes that were brought up in the initial blog in this series: compliance and asset visibility.
Compliance & Asset Visibility Are
Critical Security Challenges
Undoubtedly, the survey has underlined the growing importance of regulatory compliance within IoT. According to survey responses across 13 different market segments, 66% of IoT security professionals reported that the ability to demonstrate compliance with industry regulations was very, or extremely important.
The strength of this response should not be surprising: after all, regulations established by governments and their organisations, and liabilities that go with them, are increasingly coming into force. As a result, companies within impacted segments are under ever-increasing pressure to ensure that they are able to demonstrate that security best practices have been followed.
Blog Author
Historically, securing an appropriate budget to implement security best practices has perhaps been something of a challenge. After all, it is often bucketed into the cost centre, rather than the profit centre, and is thus an area where some organisations may seek to streamline operations as it does not directly impact profits.
However, the threat of liabilities associated with regulatory breaches introduces a new paradigm: the risk of heavy fines and the impact on brand image.
It is often said that the best security solution is only as good as the weakest link in the chain. Invariably, there is a human element that contributes to security weakness, and thus we have to consider how to mitigate this insofar as is possible. Data encryption, secure-by-design principles and opting for secure communications technologies such as cellular all contribute to this, but risk can never be fully avoided by implementing these approaches.
This is especially pertinent in IoT, where devices are often in the field for lengthy periods of time, and are often constrained in terms of processing power. Therefore, the one of the most important parts of maintaining IoT device security is to continuously monitor how the device is behaving and with what it is communicating with.
This brings us to our second survey finding: 44% of IoT security professionals reported that gaining visibility into all connected assets across the device estate represented a core challenge for them in the context of security.
With Regulations Tightening Security
Solutions Offer Valuable Differentiation
Interestingly, less than 10% of enterprises surveyed in a separate outreach concerning IoT connectivity reported that they did not expect their connectivity service provider to offer tools to monitor device behaviour in terms of IP targets, DNS use and so on.
This metadata is often important to serve as an indicator for potentially malicious behaviour but is relatively uncommon in terms of the connectivity management tooling offered in the cellular IoT world. While common approaches to security by cellular IoT connectivity service providers often involve the use of private APNs and VPNs to hide traffic from the public Internet, devices are not immune from compromise. Indeed, while cellular technology is renowned as being highly secure for IoT operations, the fact that networks established over 20 years ago are still in operation means that vulnerabilities can and do exist. To a lesser extent, the same is true for 5G networks, despite the promise of end-to-end security.
The fact is that regulations surrounding IoT will almost certainly intensify over the coming years as organisations’ dependency on IoT for business outcomes increases in importance; unsurprisingly, this perception was echoed by our IoT security professional survey audience. While there will inevitably be a portion of regulatory-impacted customers who will outsource management and security responsibility, enterprises that prefer to retain full control over their operations and security risk profile will look to their ecosystem service providers for the tooling required to monitor their assets and ensure that malicious device behaviour is halted in a timely manner, if and when it occurs.
Connectivity Ecosystem Developments to Meet
Market Demands & Opportunities
Connectivity service providers understand the critical importance of cybersecurity for businesses in today’s regulatory landscape. With an increasing demand for visibility and protection, there are key opportunities in the cellular IoT connectivity market, with key players leading the way in implementing best practices to safeguard against liability.
Aeris Communications: The global IoT solution provider, based in San Jose, California, made a significant acquisition in 2023 by adding the Ericsson IoT Accelerator and Connected Vehicle Cloud businesses to their portfolio. This move cements Aeris as one of the largest IoT connectivity providers globally.
Aeris recently unveiled its ‘IoT Watchtower’ service, seamlessly integrated into its connectivity proposition. IoT Watchtower utilises an agentless software approach, eliminating the need for any device software modifications. This service equips its connected customers with essential features such as network layer device visibility, anomaly and malware detection, and Zero Trust policy enforcement.
Shield-IoT: As an OEM solution provider, Shield-IoT positions itself as an enabler for MNOs and MVNOs to offer revenue-generating opportunities as part of a competitive differentiation set. Shield-IoT powers many of the IoT cybersecurity services that cellular IoT connectivity providers offer.
Shield-IoT’s agentless IoT cybersecurity SaaS platform offers operational device visibility, threat management, and compliance across any SIM-connected device or application at scale.
The Shield-IoT platform offers comprehensive threat management solutions, including anomaly detection, threat intelligence, and customer-configurable deterministic rules. This empowers business customers to respond effectively to any threat and generate automated compliance reports with the platform. These features act as insurance policies against data breaches or other events.
Conclusion
Although the full research engagement process has not been finalised yet, it is interesting to note trends arising from discussions for Kaleido’s annual Connectivity Vendor Hub. Here, around 30 vendors’ Connectivity Management Platform and eSIM products are thoroughly analysed and benchmarked to provide a clear indicator of where vendor work and customer demand is leading development. IoT security has often been a key topic in those discussions, with end-to-end security, transparency, reactivity and visibility forming key vendor goals. It is evident that the market understands how regulation, compliance and emerging end-customer demand are impacting requirements. This will remain a key a topic that Kaleido continues to follow closely over the coming years.




