Start With Accurate Asset Discovery and Device Inventory
Asset discovery is one of the first problems governments need to solve.
Devices may connect through fiber, cellular service or other networks, while individual departments purchase and manage equipment independently. Central IT teams can end up with an incomplete picture of what is connected.
The problem is especially common with operational technology. Water, wastewater and power systems are often managed separately from traditional IT. Public safety departments also have their own technology requirements and procurement processes.
If IT does not know a device exists, security staff cannot monitor it or account for its vulnerabilities.
Agencies should know what devices they have, where they connect and who owns them. They also need to assign responsibility for firmware updates. That job might belong to government staff, the manufacturer or a contractor, but it cannot be left ambiguous.
Connected devices that stay online for years without timely firmware updates pose significant and unnecessary IoT security risks to government networks.
READ MORE: Patch management protects government services.
Integrate IoT Security Into Procurement Earlier
Operational departments and IT teams do not always approach technology decisions from the same perspective.
Water operators are focused on delivering water. A 911 center prioritizes uptime and accessibility. Police departments want equipment that supports officers in the field.
Those priorities make sense, but they can lead departments to select technology without involving security staff early enough.
I’ve seen cases where IT learned that another department was preparing to purchase equipment that did not meet applicable security requirements. By then, the product had already been selected.
A documented onboarding process can prevent that.
Governments should establish standard operating procedures for evaluating new vendors and devices before purchase and deployment. I am a big believer in checklists, because they force an organization to answer practical questions before a device reaches the network.
Who owns it? Who updates it? What systems does it need to communicate with? Does a vendor need remote access? What security requirements apply?
Answering those questions during procurement is much easier than discovering the answers after deployment.
DIVE DEEPER: Artificial intelligence changes government procurement.
Strengthen Network Security Through Device Segmentation
After agencies identify their connected devices, they need to control how those devices communicate.
Network segmentation limits what a device can reach. A traffic sensor, camera or other connected system should have access to the resources it needs without receiving broad access to the rest of the government network.
Agencies also need to know who can connect to those systems. Third-party contractors may require remote access for maintenance, which makes identity and access controls part of the device security problem.
Monitoring matters for the same reason. Security teams should be able to identify unusual communications, including a device contacting an unexpected external destination.
Logging and threat detection tools provide the data, but collecting logs is not the same as monitoring them. Someone has to review that information and respond when activity looks suspicious.
Many local governments do not have enough cybersecurity personnel to handle that work entirely in-house. A managed detection and response provider may fill that role, but the agency still needs oversight and clear responsibility for responding to threats.
LEARN MORE: Government security operations are using AI tools.
Build Your IoT Security Program Before Buying Devices
The broader problem is that organizations often start purchasing security products before deciding what their security program should look like.
They identify a gap, buy something to address it and repeat the process when the next problem appears. That can leave an agency with plenty of technology but no consistent method for deciding which risks deserve attention.
Governments should start with a framework.
The Center for Internet Security’s CIS Controls and the National Institute of Standards and Technology’s Cybersecurity Framework give agencies a structure for assessing their security programs. From there, they can identify gaps and decide whether they call for new technology, outside services or changes to internal processes.
That planning should also govern connected device purchases.
Before another department puts a camera, sensor or other smart device on the network, the agency should already know how that device will be inventoried, approved, updated, segmented and monitored.

