Walk through most small business offices today and you'll find a handful of devices nobody thinks of as computers: a smart doorbell at the front entrance, a Wi-Fi thermostat in the server closet, a networked printer in the corner, maybe a smart TV in the conference room. Every one of them runs an operating system, holds an IP address, and talks to the internet. And nearly every one of them was installed by whoever unboxed it, plugged it into the same network as the payroll system, and never touched the settings again. That's the whole problem in one sentence: these are computers that get treated like appliances, and attackers have noticed.
How IoT devices quietly turn into an attack surface
Consumer and prosumer smart devices are built to be cheap and fast to set up, which usually means a default administrator password printed in the manual, remote access enabled out of the box so an app can reach it from anywhere, and a manufacturer that has little financial incentive to keep shipping firmware updates once the device is a couple of years old. Security researchers and botnet operators both know this, and they scan the entire internet looking for devices that are still running factory credentials or an old, vulnerable firmware version. Once one is found, it can be used two ways: as a stepping stone into whatever network it's connected to, or as one more machine in a botnet used to launch attacks against someone else entirely. Either way, the business that owns the device usually has no idea anything happened, because nobody was watching a thermostat's traffic in the first place.
Why this matters for a small business
- These devices usually sit on the main network. Without a separate network for smart devices, a compromised camera or printer is on the same segment as the point-of-sale system, the accounting login, and the file server.
- Default credentials rarely get changed. Whoever installed the device was focused on getting it working, not securing it, and it's often nobody's job to circle back.
- Firmware support has a shelf life. Most consumer IoT vendors stop shipping security updates within a few years, so a known vulnerability can stay open for the rest of the device's working life.
- Nobody's monitoring them. IT teams track servers and laptops. A smart doorbell or thermostat usually isn't on anyone's asset list, so unusual behavior goes unnoticed indefinitely.
What actually stops it
- Put every smart device on its own VLAN or guest network, isolated from point-of-sale systems, servers, and employee workstations, so a compromised device has nowhere useful to go.
- Change every default password at setup, including ones the installer app doesn't prompt for, and use a unique password per device where the interface allows it.
- Disable UPnP and remote administration unless a specific device genuinely needs it, since both make a device reachable from outside your network by design.
- Keep a written inventory of every connected device, its firmware version, and who's responsible for it, so nothing is running invisibly.
- Set a recurring reminder to check for firmware updates, since almost none of these devices update themselves the way a laptop or phone does.
Where this fits
- The business Wi-Fi segmentation post, for the VLAN design that keeps a compromised smart device away from anything that matters.
- The zero trust security post, for why being on the network shouldn't automatically mean being trusted by it.
- The shadow IT post, for the same unmanaged-device problem showing up in software instead of hardware.
- The network design page and the cybersecurity services page, for where segmentation and device management fit into a full security program.
FAQs about IoT device security
What is IoT device security for a small business?
IoT device security means treating smart cameras, thermostats, doorbells, printers, and other network-connected hardware as computers on your network, not appliances. That means changing default passwords, keeping firmware current, and keeping these devices off the same network segment as point-of-sale systems, accounting logins, and file servers.
Can a smart camera or thermostat really get a business hacked?
Yes. IoT devices are frequently sold with a default admin password that's never changed, and vendors often stop shipping firmware updates within a few years of release. Attackers scan the internet for exposed devices running known vulnerable firmware and use them as an entry point into whatever network they're sitting on, or recruit them into a botnet.
How do I secure IoT devices on a small business network?
Put every smart device on its own VLAN or guest network isolated from business systems, change every default password and disable remote administration and UPnP, keep a written inventory of every connected device with its firmware version, and set a recurring reminder to check for updates since most of these devices don't update themselves.
Not sure what's actually connected to your network?
30 minutes with a DoD-cleared engineer. We'll help you inventory every smart device on your network, confirm none of them are still running factory credentials, and make sure they're segmented away from the systems that actually matter.
Book your free security assessment