Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 14 2026
Security

How State and Local Governments Can Secure IoT Devices

Better visibility, segmentation and planning protect connected infrastructure from cyberthreats before vulnerabilities become serious problems.

State and local governments often buy connected Internet of Things (IoT) devices to solve immediate operational problems, then deal with security after the equipment is already on the network.

That sequence creates trouble.

Water and wastewater systems use connected equipment for monitoring and control. Transportation agencies deploy traffic sensors, cameras and smart crosswalks. Police departments rely on body cameras and connected license plate readers. Each IoT device must be identified, updated and monitored, but who holds the responsibility for that work is not always clear.

The better approach is to establish the IoT security program before adding more equipment.

Click the banner below for insights into operational security for smart devices.

 

Start With Accurate Asset Discovery and Device Inventory

Asset discovery is one of the first problems governments need to solve.

Devices may connect through fiber, cellular service or other networks, while individual departments purchase and manage equipment independently. Central IT teams can end up with an incomplete picture of what is connected.

The problem is especially common with operational technology. Water, wastewater and power systems are often managed separately from traditional IT. Public safety departments also have their own technology requirements and procurement processes.

If IT does not know a device exists, security staff cannot monitor it or account for its vulnerabilities.

Agencies should know what devices they have, where they connect and who owns them. They also need to assign responsibility for firmware updates. That job might belong to government staff, the manufacturer or a contractor, but it cannot be left ambiguous.

Connected devices that stay online for years without timely firmware updates pose significant and unnecessary IoT security risks to government networks.

READ MORE: Patch management protects government services.

Integrate IoT Security Into Procurement Earlier

Operational departments and IT teams do not always approach technology decisions from the same perspective.

Water operators are focused on delivering water. A 911 center prioritizes uptime and accessibility. Police departments want equipment that supports officers in the field.

Those priorities make sense, but they can lead departments to select technology without involving security staff early enough.

I’ve seen cases where IT learned that another department was preparing to purchase equipment that did not meet applicable security requirements. By then, the product had already been selected.

A documented onboarding process can prevent that.

Governments should establish standard operating procedures for evaluating new vendors and devices before purchase and deployment. I am a big believer in checklists, because they force an organization to answer practical questions before a device reaches the network.

Who owns it? Who updates it? What systems does it need to communicate with? Does a vendor need remote access? What security requirements apply?

Answering those questions during procurement is much easier than discovering the answers after deployment.

DIVE DEEPER: Artificial intelligence changes government procurement.

Strengthen Network Security Through Device Segmentation

After agencies identify their connected devices, they need to control how those devices communicate.

Network segmentation limits what a device can reach. A traffic sensor, camera or other connected system should have access to the resources it needs without receiving broad access to the rest of the government network.

Agencies also need to know who can connect to those systems. Third-party contractors may require remote access for maintenance, which makes identity and access controls part of the device security problem.

Monitoring matters for the same reason. Security teams should be able to identify unusual communications, including a device contacting an unexpected external destination.

Logging and threat detection tools provide the data, but collecting logs is not the same as monitoring them. Someone has to review that information and respond when activity looks suspicious.

Many local governments do not have enough cybersecurity personnel to handle that work entirely in-house. A managed detection and response provider may fill that role, but the agency still needs oversight and clear responsibility for responding to threats.

LEARN MORE: Government security operations are using AI tools.

Build Your IoT Security Program Before Buying Devices

The broader problem is that organizations often start purchasing security products before deciding what their security program should look like.

They identify a gap, buy something to address it and repeat the process when the next problem appears. That can leave an agency with plenty of technology but no consistent method for deciding which risks deserve attention.

Governments should start with a framework.

The Center for Internet Security’s CIS Controls and the National Institute of Standards and Technology’s Cybersecurity Framework give agencies a structure for assessing their security programs. From there, they can identify gaps and decide whether they call for new technology, outside services or changes to internal processes.

That planning should also govern connected device purchases.

Before another department puts a camera, sensor or other smart device on the network, the agency should already know how that device will be inventoried, approved, updated, segmented and monitored.

This article is part of StateTech’s CITizen blog series.

 

CITizen_blog_cropped_0.jpg

Jackyenjoyphotography/Getty Images