The 2025 IBM X-Force Threat Intelligence Index ranks IoT as the third most frequent attack surface in enterprise infrastructure, a layer that has quadrupled in size over the past twelve months and now accounts for nearly 17 percent of all incidents observed by incident response teams. The figure goes beyond a simple statistic; it signals a fundamental shift in the geography of threat.
A particularly telling detail is the focus attackers have placed on two previously overlooked layers: enterprise-grade network cameras and smart HVAC controllers. According to field analysis published by Mandiant for Q2-2025, more than 63 percent of initial intrusions into internal networks began through IoT endpoints still running default credentials. Notably, in 82 percent of those cases, the victim organization had not even registered the vulnerable devices in its asset inventory, meaning it did not know what it was supposed to be protecting.
Gartner forecasts that the global installed base of enterprise IoT devices will reach 25 billion units by the end of 2026. That expansion has not been matched by an equivalent uptake of dedicated security platforms for this layer. The resulting gap is the main fuel for the latest wave of attacks. Attackers no longer need to breach core servers directly; a temperature sensor in the server room is enough to serve as the entry point.
One recurring pattern in the documented cases of 2025 is the exploitation of remote management protocols that lack encryption. Many older devices still rely on Telnet or early versions of SNMP. A simple port scan hands an attacker a list of reachable targets, and within minutes an initial foothold inside the target network is established.
What separates today’s attackers from those of the past shows up in the post-intrusion phase. Instead of immediate destruction or extortion, many groups quietly convert the compromised IoT device into a staging base, a platform for lateral movement, data exfiltration or even hosting command-and-control infrastructure. This pattern makes detection harder for security teams, since the traffic generated by an IP camera looks, at first glance, indistinguishable from its normal behavior.
In Iran, the challenge is compounded. The import of devices with proprietary firmware and the absence of an official update cycle for many of the brands commonly found in the local market have created a situation in which even known security patches cannot be applied. Security teams in organizations are frequently dealing with equipment that has been abandoned by its vendor.
The first practical step is building an accurate inventory of every device connected to the network, one that is updated on a regular basis. The second step is logically separating these devices from the main network through VLANs or micro-segmentation. The third step is replacing default credentials and disabling unencrypted protocols. Taken together, these three measures alone can shut down a large portion of the known intrusion paths.
In the end, it must be accepted that IoT is no longer a peripheral item in an organization’s security policy. The field data from 2025 makes it clear that every connected device represents a potential attack surface, and neglecting that reality carries a cost far heavier than the price of prevention.
The Razban team, within the Razban Atlas technology group, is ready to help organizations identify and harden their IoT infrastructure.