On 20 September 2016, the security journalist Brian Krebs's website was hit by a distributed denial of service attack that his provider measured in excess of 620 gigabits per second, an order of magnitude beyond what most mitigation services were built to absorb. A month later, on 21 October, the same class of attack was directed at the DNS provider Dyn, and large parts of the consumer internet became unreachable across the eastern United States. Flashpoint's analysis described tens of millions of IP addresses associated with the attack. The traffic was not coming from compromised servers or rented cloud capacity. It was coming from digital video recorders, IP cameras, home routers and similar consumer devices, recruited by a piece of malware called Mirai whose entire technique was to try a short list of default usernames and passwords over telnet. That is the part worth sitting with. There was no exploited vulnerability, no sophisticated implant, no zero-day. The malware logged in. Hundreds of thousands of devices had been shipped with credentials the owner could not change, would never change, or did not know existed, and the aggregate result was an attack capability that could take a major infrastructure provider offline. The source code was published publicly in early October 2016, which guaranteed that the technique would not remain a single actor's tool, and CISA issued a formal alert on 14 October. Variants have been in continuous circulation ever since.
Each event links to its supporting source. This is a selective chronology, not a performance comparison.
The structural problem Mirai exposed
The incident is usually filed under DDoS. It is more accurately a lesson about incentives in the device market, and that lesson has not been resolved. The economics of connected devices are unforgiving. A camera selling for a small margin cannot support a security programme, an update mechanism, a vulnerability response function or a ten-year patching commitment. The manufacturer's incentive is to ship cheaply; the buyer's incentive is to buy cheaply; and neither party bears the cost when the device is conscripted into an attack on someone else. The victim is a third party entirely. This is a textbook externality, and markets do not fix externalities on their own. The second structural point is longevity. These devices stay installed for a decade or more. A building's camera system, a manufacturing sensor network, a set of network-attached controllers — all of them outlive the vendor's support commitment, and frequently the vendor. An organisation's IoT estate is therefore an accumulating population of unpatchable endpoints, and it grows through procurement decisions that security teams never see, because a camera is bought by facilities and a sensor is bought by operations. The third is visibility. Most organisations cannot enumerate their connected devices. They know their servers and their laptops. They do not know how many cameras are on the network, who installed them, what firmware they run, or whether they are reachable from the internet — and a device nobody knows about cannot be segmented, monitored or patched.
What actually works
Device hardening is necessary but insufficient, because you cannot harden what you cannot patch. The controls that hold up are network and procurement controls. Segmentation is the primary defence. Connected devices belong on isolated network segments with tightly controlled egress. A camera needs to reach its recorder. It does not need to reach the internet, and it certainly does not need to reach the finance system. Egress filtering on device segments defeats most of the value of a compromise: a conscripted device that cannot send traffic outbound cannot participate in an attack. Inventory before anything else. Passive network discovery to find what is actually connected, because the asset register will be wrong. Expect the count to surprise people. Procurement standards with teeth. No default credentials, documented update mechanism, stated support lifetime, vulnerability disclosure contact, and the ability to disable unused services. These requirements cost nothing to specify and eliminate the worst of the market. Credential change as a commissioning gate. The device is not in service until default credentials are replaced and unnecessary management interfaces are disabled. No internet exposure without a documented reason. Remote management convenience is how most of these devices end up reachable, and it is almost never necessary. Monitoring for outbound anomalies. A device suddenly generating heavy outbound traffic or contacting unfamiliar destinations is the observable signature of conscription. An end-of-life rule. When the vendor stops issuing updates, the device is replaced or fully isolated. Without a written rule this never happens.
Practical Guidance for IoT Security Assessment
- Discover devices passively before trusting any asset register. The gap between what is recorded and what is connected is the finding that gets the programme funded.
- Segment connected devices and control egress tightly. This single control neutralises most of what a compromised device could do.
- Make credential change a commissioning checklist item. Not a policy statement — a gate that stops a device entering service.
- Put security requirements in device procurement specifications. Support lifetime, update mechanism, no default credentials, disclosure contact. Facilities and operations buy these devices; the requirements must live in their process.
- Identify anything internet-reachable and justify it individually. Remote management convenience is the most common reason and rarely a good one.
- Write an end-of-life rule and enforce it on a schedule. Unsupported devices accumulate silently and represent permanent exposure.
- Extend the inventory to building systems, not just IT devices. HVAC, access control, lifts, lighting and energy management are on your network and are rarely in scope.
- Monitor outbound traffic from device segments. Conscription is visible in egress patterns long before anyone reports a problem.
The Regional Dimension
The Gulf has an unusually large and unusually new connected device estate, which cuts both ways. The scale is the product of a building boom coinciding with the smart infrastructure era. Purpose-built cities, large mixed-use developments, new airports, ports, stadiums and transport systems were designed with pervasive instrumentation from the outset — surveillance, access control, environmental monitoring, energy management, traffic systems, and increasingly public infrastructure sensing at city scale. National smart city programmes across the UAE and Saudi Arabia have accelerated this further. Few regions have deployed as many connected devices as quickly. The positive consequence: much of the estate is recent, which means better baseline security than the decade-old equipment common in older markets. The negative consequence is more important. Large regional deployments are typically delivered by systems integrators and main contractors as part of a construction package, commissioned under schedule pressure, and handed over to a facilities management company that operates them for years afterwards. Security ownership in that chain is genuinely unclear. The integrator's obligation ended at handover, the facilities operator's contract covers availability rather than patching, and the asset owner assumed someone was responsible. The result is thousands of devices in a building with no named party accountable for firmware, credentials or monitoring — and that gap is a regional pattern rather than an occasional failure. The critical infrastructure dimension raises the stakes. Energy, water, ports, aviation and industrial facilities across the region run operational technology with equipment lifecycles measured in decades, increasing IP connectivity, and a history that makes destructive attacks a live concern rather than a hypothetical one — the Shamoon-era wiper campaigns remain the reference point in regional boardrooms. The convergence of cheap connected devices with OT environments that were designed for isolation is the specific risk worth prioritising here. Regulators have moved. National cybersecurity authorities in the UAE and Saudi Arabia have issued controls covering connected and operational technology, critical sector regulators have imposed requirements on infrastructure operators, and large government projects increasingly carry device security requirements in the tender documents. For regional buyers this is genuinely useful leverage: the security specification is easiest to enforce at procurement, and public sector procurement here is now asking for it. One further local factor: much of the device estate is installed and maintained by external parties holding remote access for support, frequently through the vendor's own tooling rather than the customer's. That access path is the same problem as the devices themselves, one layer up, and it is usually ungoverned by the contract.
The objection worth taking seriously
The fair criticism of all this advice is that it asks the wrong party to solve the problem. An organisation that inventories, segments, monitors and replaces its devices has protected itself from a fraction of the risk, because the botnets are built from devices in homes and small businesses that will never do any of this. The consumer router in an apartment is the raw material, and no enterprise security programme touches it. The externality is unaddressed by enterprise diligence, which means the attack capability persists regardless of how well any individual organisation performs. That is an argument for regulation — device security legislation in several jurisdictions has begun to mandate unique default credentials, disclosure policies and support lifetimes — and it is a slow instrument against a device population already installed. There is also an honest resourcing point. The full programme described above assumes a security function with network engineering support, monitoring capability and influence over procurement across facilities and operations. Most mid-market organisations have none of that. The compressed version worth doing: find out what is connected, put it on its own network segment with no inbound internet access and restricted outbound, change default credentials, and stop buying devices from vendors who will not state a support lifetime. That is achievable, and it removes most of the realistic exposure. And a proportionality note. For the majority of organisations, the risk from a compromised camera is not that they become a DDoS participant — that is the internet's problem more than theirs. It is that a poorly segmented device provides a foothold on the internal network. Framing the business case around lateral movement is both more accurate and considerably more persuasive than framing it around bandwidth.
Common Questions
What made Mirai effective if it used no vulnerabilities?
Scale and defaults. It scanned for devices with factory credentials on exposed management services and logged in. The technique was trivial; the population of vulnerable devices was enormous, and the aggregate bandwidth of hundreds of thousands of consumer devices exceeded what most targets could absorb.
What is the single most valuable control for connected devices?
Network segmentation with tight egress filtering. It works even for devices you cannot patch, cannot inventory fully and did not know you had, which is why it outranks device hardening in practice.
Who owns device security in a building handed over by a contractor?
Nobody, unless it is written down — and that is the finding in most regional assessments. Assign it explicitly in the facilities management contract or the operations agreement, with named responsibility for firmware, credentials, monitoring and end-of-life replacement.
Has AI changed this picture?
On both sides, and not symmetrically. Attackers now use automated tooling to find and exploit device populations faster, and the devices themselves have become more capable targets: many contain enough compute to be worth conscripting for more than bandwidth. The more significant shift is that connected devices are increasingly sold with embedded intelligence — cameras that classify, sensors that make decisions locally, controllers that act without a human in the loop — which means a compromised device can now produce wrong decisions rather than just wrong traffic, and a camera that reports what it was told to report is a harder problem than one that floods a link. Defensively, anomaly detection on device behaviour is genuinely improved, because normal behaviour for a fixed-function device is narrow and deviations are easy to model. That is the one area where the defender's position is clearly stronger than it was a decade ago.
IoT Security Assessment — find what is connected, segment it, filter its egress; you cannot patch most of it, and the attack needed no vulnerability at all.
