A smart speaker orders your groceries. A fitness band tracks your heart rate. A CCTV camera watches your shop after closing hours. All of these are part of the Internet of Things (IoT), a network of everyday objects that talk to each other and to the internet without needing a human to press a button. This convenience comes at a cost, though. Every connected device is also a potential doorway for a hacker, and that is exactly why cyber security has become inseparable from IoT.

Table of Contents

What makes IoT different from regular computing

A laptop or a smartphone usually runs a full operating system, gets frequent security updates, and has a screen where you can see if something looks wrong. Most IoT devices do not work this way. A smart thermostat, a doorbell camera, or a fitness tracker is built to be cheap, small, and always on. Manufacturers often prioritise features and price over security, which means many devices ship with weak default settings and are never updated after they leave the factory.

This gap between “smart” and “secure” is what makes IoT such an attractive target. A single vulnerable device connected to a home or office network can become the weak link that lets an attacker into everything else on that network, including laptops, servers, and payment systems.

Why IoT devices are so easy to compromise

The Open Web Application Security Project (OWASP) maintains a well-known list of the most common IoT weaknesses, and a few of them show up again and again in real attacks.

Weak or default passwords

Many IoT devices come with a factory-set username and password, such as “admin” and “admin,” printed right on the box or listed in the manual. If the owner never changes it, the device is essentially left unlocked. Attackers do not even need sophisticated tools; they simply try a short list of common default credentials across millions of devices until some of them work.

Insecure network services and outdated software

Once a device is set up, it often runs in the background for years without anyone checking whether its firmware needs an update. Unlike phones, which nudge users toward regular updates, many IoT gadgets have no visible interface for patching, so known vulnerabilities remain open indefinitely.

Lack of encryption

Some devices send data, including video feeds, voice recordings, or location details, across the network without encrypting it. This means anyone intercepting that traffic can read or misuse the information.

Poor device management

Businesses that deploy hundreds of sensors or cameras often struggle to even keep track of how many devices they have, let alone monitor them for suspicious activity. An unmanaged device is effectively invisible to a security team until it starts behaving badly.

Common IoT weakness Why it matters
Default credentials Lets attackers log in without any real hacking effort
Unpatched firmware Leaves known bugs open for months or years
No encryption Exposes data in transit to eavesdropping
No visibility or inventory Makes it hard to spot a compromised device

A real-world lesson: the Mirai botnet

The clearest example of what can go wrong is the Mirai botnet, which surfaced in 2016. The malware scanned the internet for IoT devices such as home routers, digital video recorders, and security cameras, then tried a short list of factory default usernames and passwords to log in. According to a technical alert from the US Cybersecurity and Infrastructure Security Agency (CISA), Mirai used a list of just 62 common default credentials to identify and infect vulnerable devices at scale.

Once infected, these devices were turned into an army of bots that flooded targeted websites and services with traffic, knocking large parts of the internet offline for hours. What made the attack so effective was not clever code but simple neglect: thousands of device owners had never bothered to change a default password. The incident is still used as a textbook case of how a small oversight in consumer electronics can snowball into a global disruption.

How India is responding to IoT security risks

As IoT adoption grows across Indian homes, hospitals, and industries, regulators have started building a formal security framework rather than leaving it entirely to manufacturers.

Mandatory testing and certification

The Department of Telecommunications, through the Telecommunication Engineering Centre, has issued a Code of Practice for Securing Consumer IoT, which requires connected devices sold, imported, or used in the country to undergo testing and certification before they reach the market. The goal is to catch weak security design, such as unchangeable default passwords, before the device is ever sold.

A dedicated certification scheme

The Standardisation Testing and Quality Certification Directorate under the Ministry of Electronics and Information Technology runs the IoT System Certification Scheme, which evaluates everything from sensors and gateways to cloud components and user interfaces. Devices are certified at different assurance levels depending on how sensitive the data they handle is, giving buyers a way to compare the security of competing products.

Incident reporting through CERT-In

When a cyber incident does occur, including one involving IoT devices, organisations are expected to act quickly. Directions issued by the Indian Computer Emergency Response Team (CERT-In) require covered entities to report qualifying cyber security incidents within a strict time window and to retain system logs for later investigation. IoT-related attacks are explicitly listed among the categories that must be reported, reflecting how mainstream this risk has become for regulators.

Practical steps to stay protected

Good IoT security does not need to be complicated. Most of it comes down to habits that any student, household, or small business can adopt.

For individuals

  • Change default passwords on every new device the moment it is set up.
  • Keep firmware updated by checking the manufacturer’s app or website periodically.
  • Separate networks by putting smart home gadgets on a guest Wi-Fi network instead of the same one used for banking or work.
  • Disable unused features like remote access or voice recording if they are not actually needed.

For businesses

  • Maintain a device inventory so every connected sensor, camera, or terminal is accounted for.
  • Segment networks so a compromised device cannot reach sensitive systems like payment servers.
  • Monitor traffic for unusual patterns that might indicate a device has been hijacked.
  • Choose certified devices where possible, favouring vendors who follow recognised security standards rather than the cheapest option on the shelf.

Why this matters for commerce and retail

IoT is no longer just a home gadget story. Retail chains use connected point-of-sale systems, warehouses use IoT sensors to track inventory, and logistics firms use GPS trackers on shipments. A breach in any of these systems does not just leak data; it can halt operations, expose customer payment details, or damage a brand’s reputation overnight. Understanding IoT security is therefore becoming a practical business skill, not just a technical one, for anyone entering e-commerce or retail management.

What do you think? If a business you managed relied on dozens of connected devices, from smart locks to inventory sensors, how would you decide which ones need the strictest security controls first? And do you think mandatory certification, like the schemes being rolled out in India, is enough to fix the default password problem, or does real change have to start with the buyer?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://owasp.org/www-project-internet-of-things/
  2. https://www.cisa.gov/news-events/alerts/2016/10/14/heightened-ddos-threat-posed-mirai-and-other-botnets
  3. https://www.tec.gov.in/pdf/M2M/Securing%20Consumer%20IoT%20_Code%20of%20pratice.pdf
  4. https://www.stqc.gov.in/iot-system-certification-scheme-iotscs
  5. https://www.medianama.com/2025/07/223-cert-in-cybersecurity-audit-rules-india/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

E-Commerce

1 Introduction to E-commerce

  1. Introduction
  2. Meaning of E-Commerce
  3. E-Commerce Web Portal
  4. E-Commerce Software
  5. E-Commerce APIs
  6. M-Commerce and Multi-channel Commerce
  7. Use of Emerging Technologies in E-Commerce
  8. Why E-Commerce
  9. Evolution of E-Commerce
  10. Types of E-Commerce
  11. Advantages and Disadvantages of E-Commerce

2 E-Commerce Business Models

  1. Introduction
  2. What is a Business Model?
  3. Key Elements of a Business Model
  4. E-Commerce Business Models to Understand Target Customer
  5. E-Commerce Design Models
  6. Implementing E-Commerce Models
  7. E-Commerce Revenue Models
  8. Impact of COVID on E-Commerce

3 Technology used in E-Commerce

  1. Introduction
  2. Design Considerations of E-Commerce
  3. Essential Technology Features Required
  4. Difference between App Based and Web-Based Business
  5. Building, Designing and Launching E-Commerce Website
  6. SDLC Cycle for Designing E-Commerce Solutions
  7. Architectural Framework and Network Infrastructure
  8. Impact of Emerging Technologies on E-Commerce
  9. Digital Platforms and E-Commerce
  10. Digitalisation and Digital Transformation in Businesses

4 Electronic Governance

  1. Introduction
  2. Meaning of E-Governance
  3. Differences between E-Government and E-Governance
  4. Differences between E-Governance and E-Commerce
  5. Advantages of Employing Digital Technologies in Governance
  6. Gartnerโ€™s Evolution Model of E-Governance
  7. E-Governance in India
  8. Digital India
  9. E-Governance initiatives in India

5 E-Payment

  1. Introduction
  2. Overview of Payment System
  3. Meaning of E-Payment
  4. Difference between E-Payment & Conventional Payment
  5. Payment Gateways
  6. Steps about Functioning of a Payment Gateway
  7. Types of Payment Gateways
  8. Types of Payment Methods
  9. Requirements Metrics of a Payment System
  10. Merits of E-Payment System
  11. Risks Involved in E-Payment

6 E-Banking

  1. Introduction
  2. Concept of E-Banking
  3. Importance of E-Banking
  4. Technology used in Banking
  5. EFT (Electronic Fund Transfer)
  6. NEFT (National Electronic Fund Transfer)
  7. RTGS (Real Time Gross Settlement)
  8. IMPS (Immediate Payment Service)
  9. UPI (Unified Payments Interface)
  10. Difference between NEFT, RTGS & IMPS
  11. Virtual Currency
  12. Automated Clearing House
  13. Automated Ledger Posting
  14. Distributed Ledger Technology

7 Website Development

  1. Introduction
  2. Meaning of Website
  3. Evolution of Website
  4. Website Usage
  5. HTTP & HTTPS Protocols
  6. Types of Website
  7. Development of Website
  8. Ingredients Required for Website Development
  9. Website Hosting

8 Electronic Commerce Software

  1. Introduction
  2. E-commerce Software Platform
  3. Types of Software Platforms
  4. Shopify – An Online Store Builder
  5. E-Auction Processes the Real-Time Visibility
  6. PayPal Holdings Online Payments
  7. SAP Commerce Cloud
  8. Functions of E-Commerce Software Platforms
  9. Advanced Functions of E-Commerce Software
  10. E-Commerce Software for Small & Midsize Companies
  11. E-Commerce Software for Midsize to Large Business
  12. E-Commerce Software for Large Business
  13. Planning Electronic Commerce Initiatives
  14. Strategies for Developing E-Commerce Websites
  15. Managing E-Commerce Implementations

9 Web Server Hardware and Software

  1. Meaning of Server
  2. Web Server Essentials
  3. Different Types of Web Server
  4. Characteristics of a Web Server
  5. Functioning of a Web Server
  6. Mail Server
  7. Process of Sending E-mails
  8. Operating System
  9. Windows
  10. Linux
  11. Linux vs. Windows
  12. Web Server Hardware
  13. Hardware used in Web Servers
  14. Web Server Software
  15. Application Server Software
  16. Web Server & Application Server
  17. Web Site and Internet Utility Programs

10 Cyber Security

  1. Meaning of Cyber Security
  2. Cyber Security Impact on E-Commerce
  3. Cyber Security Relevance
  4. Information Security V/s Cyber Security
  5. Basics of Cyber World
  6. Need & Concepts behind Security
  7. IoT and Cyber World
  8. Cyber Crime and Law
  9. Security Barriers

11 Cyber Security Measures

  1. Role of Cyber Security Analysts
  2. Essential Cyber Security Measures
  3. Precautionary Cyber-Security Measures Enterprise Takes
  4. IoT and its Impact
  5. Vulnerable Information on Internet
  6. Vulnerabilities of Systems
  7. Internet Vulnerabilities
  8. Wireless Security Challenges
  9. Malicious Software
  10. Hackers and Computer Crime
  11. Cyber Crime
  12. Global Threats: Cyber terrorism and Cyber Warfare
  13. Cyber Forensic
  14. Securing the Business on Internet
  15. Securing Network Transactions
  16. Security Measures and Enforcement

12 IT Act 2000

  1. Definition
  2. Formulation of IT Act 2000
  3. Amendments in IT Act 2000
  4. Digital Signature & Encryption
  5. Attribution
  6. Acknowledgement and Dispatch of Electronic Records
  7. Regulation of Certifying Authorities
  8. Digital Signatures Certificates
  9. Duties of Subscribers
  10. Penalties and Adjudication
  11. Procedure, Working & Legal Position in Digital Signature
  12. Appellate Tribunal
  13. Offences and Cyber-Crimes
  14. E-Signature and Digital Signature
  15. Encryption

13 E-Tailing

  1. E-tailing
  2. E-tailing Models
  3. E-retail Mix-Sale the 7Cs
  4. E-tailing in India

14 E-Services

  1. Meaning of E-Services
  2. Benefits of E-Services
  3. FinTech
  4. eFinancial Services
  5. eTravel Services
  6. eAuction Services
  7. eLearning
  8. Virtual Communities and Web Portals
  9. Online Learning
  10. ePublishing Services
  11. Online Entertainment

15 App Based Commerce

  1. What is an App?
  2. Classification of Apps
  3. Types of Apps
  4. Steps for App Development
  5. Mobile Development Frameworks
  6. App Store
  7. Apps for Various Domains & Segments