Security & IntelligenceIoT security
IoT security for cameras, sensors and connected devices
For offices, shops, warehouses and factories full of devices nobody looks after. We list every connected device, replace default passwords, update firmware, move devices onto separate networks and keep watch over them. Industrial controllers on the production floor included.
- A full inventory
- every device, with owner and firmware
- Separate networks
- cameras and machines away from office PCs
- Watched over time
- alerts on new or unusual devices
Every device, known and ownedOffice and warehouse · first scan
- cam-lobby-01IP camera · firmware current · own network OK
- printer-2fdefault admin password Fix
- hvac-ctrlbuilding controller · on office LAN Move
- badge-gateaccess control · updated OK
Example · not a real system
01Why devices are a risk
Smart devices nobody looks after
Cameras, printers, badge readers, meeting-room screens and machine controllers all run software. They are often installed once and forgotten.
Default passwords
Many devices ship with the same password for everyone, and it never gets changed.
Firmware never updated
Known flaws stay open for years because nobody owns the updates.
Everything on one network
A hacked camera on the office network is a door to your PCs and servers.
Devices nobody knows about
Equipment added by suppliers or staff that is not on any list.
What we look after
Cameras and video recorders
Security cameras, NVRs and the apps used to view them.
Screens and printers
Smart TVs, meeting-room systems and network printers.
Network and access
Routers, access points, badge readers and smart locks.
Sensors and machines
Building controllers, sensors, PLCs and connected machines.
02What we do
Find them, lock them down, keep them apart
We start by finding every device on your networks. Then we fix the settings that matter most and separate devices from the computers that hold your data.
- Device discovery and inventory
- Default passwords replaced
- Firmware updates, with a plan
- Unused services and remote access closed
- Network segmentation with VLANs and firewall rules
- Alerts for new or unusual devices
- Rules for suppliers who install devices
- Industrial IoT and production networks
One device, five checksIP camera · lobby
- Default password replaced
- Latest firmware installed
- Cloud P2P access turned off
- Moved to the camera network
- Clock sync and logs to server
- WARNNew device: camera net
- INFOSupplier test unit
- OKMoved to quarantine
- OKRemoved after visit
03What is included
IoT security, item by item
Most devices can be made much safer without replacing them. We start with the ones that are exposed or could reach your data.
Inventory
A list of every connected device and who is responsible for it.
- Network discovery, with your permission
- Make, model, firmware and location
- An owner for each device
Secure configuration
Settings that close the most common ways in.
- Unique, strong passwords
- Unused services and ports turned off
- Remote and cloud access reviewed
Firmware and updates
A plan to keep devices current without surprises.
- Check of available updates
- Tested, scheduled installs
- Replacement plan for unsupported devices
Network segmentation
Devices on their own networks, with only the traffic they need.
- Separate networks for cameras, guests and machines
- Firewall rules between segments
- Safe remote access for suppliers
Monitoring
Know when something new or unusual appears.
- Alerts for new devices
- Unusual traffic and failed logins
- Periodic reports
Industrial IoT
Controllers, sensors and machines on the production floor.
- Office and production networks kept apart
- Changes planned around production
- Work with your machine suppliers
04How we work
From a device list to a network you control
We plan every change around your operations. Cameras keep recording and machines keep running.
-
Discover
We scan your networks, with your permission, and walk the premises to find every connected device.
Read-only first -
Prioritize
Devices are ranked by how exposed they are and by what they could reach.
Riskiest first -
Fix and separate
Passwords, firmware, settings and separate networks, planned around your operations.
Around your shifts -
Monitor
Alerts for new or unusual devices and a regular check of the inventory.
Reports in EN or IT
05Questions
What people ask about their devices
Not sure how many devices you have? That is a good place to start. Write to us and we will suggest a first step.
Production comes first. On factory floors, every change is agreed with you and with your machine suppliers before we touch anything.
Do we have to replace our devices?
Usually not. Most devices become much safer with new passwords, updates, better settings and their own network. We suggest replacing only devices that no longer receive updates and cannot be isolated.
Will this stop production or the cameras?
Changes are planned with you, device by device, in agreed windows. On production lines we work around shifts and together with your machine suppliers.
Our suppliers manage some devices remotely. Is that a problem?
It can be, if access is always open or shared. We set up controlled remote access, so suppliers can work when needed and you can see who connected and when.
Do you cover industrial controllers and production networks?
Yes, with care. We focus on keeping office and production networks apart, controlling remote access and keeping an inventory. Changes to machines are always agreed with you and the machine supplier.
How do we keep it up over time?
With an inventory that stays current, alerts for new devices and a periodic review. We can do it for you, or train your IT team to do it.
How many devices are on your network right now?
If the honest answer is “not sure”, start there. Tell us about your sites and we reply by email with a plan for a first inventory.