Smart city with particle glowing light connection design

How the cyber attack surface is expanding across IoT and IIoT

As IoT and IIoT adoption grows, the cyber attack surface expands, requiring new approaches to investigation, resilience and forensic readiness.


In brief

  • IoT and IIoT devices are becoming more prevalent across critical infrastructure, potentially expanding the cyber attack surface and introducing new risks.
  • Investigations can be strengthened further by improving how evidence is preserved and retained over time.
  • Forensic readiness by design helps organizations investigate incidents and strengthen operational resilience.

The Internet of Things (IoT) is often associated with connected home devices, from closed circuit television (CCTV) systems to appliances such as air conditioning units. However, the use of sensors and smart devices extends far beyond home. Today, IoT is embedded across industries, from defense and healthcare to the critical infrastructure that underpins industrial societies enabling large-scale, interconnected systems.


In today’s environment, particularly in the energy sector, industrial facilities are increasingly embedded with connected devices. They enable early identification of potential failures and preventative maintenance activities. These technologies also support condition and corrosion monitoring, real-time performance optimization, sustainability management, safety monitoring as well as remote oversight of equipment, both onshore and offshore.


IoT devices can function independently or as part of interconnected systems across broader networks. These capabilities are no longer optional, they are becoming essential to everyday operations, driving cost and efficiency savings. This, in turn, enables better data-driven decisions leveraging both historical and real-time data while supporting predictive capabilities.


However, IoT and industrial IoT (IIoT) devices often lack advanced security capabilities commonly found in personal computers or mobile devices1. When connected to mission critical systems, they can become the weakest link in the security chain, creating an attractive target for both state and non-state actors.

 

IoT and IIoT are expanding the cyber attack surface


IIoT is now deeply embedded across sectors such as oil and gas, utilities, manufacturing and telecoms, and forms a critical component of modern national infrastructure. At the same time, this increased connectivity has introduced new risks. Sensors, controllers, gateways and data pipelines are increasingly targeted as attack vectors, particularly in environments where security controls are yet to keep pace with ongoing digitization.


IoT and IIoT devices operate within systems that run in harsh conditions, interface directly with physical processes, and integrate with legacy operational technology that was not designed for connectivity. The result is a complex and expanding evidence surface, where multiple devices, systems and environments are interconnected.

Why IoT forensics is becoming essential

As attacks powered by artificial intelligence increase exponentially, IIoT forensics is becoming a critical component of incident response and resilience planning.

Traditional forensic models were designed for single locations or devices. In contrast, IoT and IIoT environments span multiple jurisdictions, with data distributed across countries and subject to different regulations.

When an incident occurs, investigations can span across edge devices, engineering workstations, local gateways, on-premises systems and vendor-managed cloud platforms. In many cases, valuable evidence can be lost as normal operational activity continues uninterrupted.

The challenge of preserving evidence across IIoT environments

Data retention across IoT environments varies significantly. Some data may be retained for months, while other records are overwritten in hours or days. As a result, investigations are often delayed or constrained, not because evidence never existed, but because it was not preserved long enough to be useful.

IoT adoption in energy grew at least
12%
12%
year-over-year, reflecting deep dependence on connected industrial devices.

Recent research indicates that IoT is one of the fastest growing emerging technologies worldwide, with enterprises ranking it alongside 5G and quantum computing as a top investment priority. IoT adoption in energy grew by more than 12% year-over-year, reflecting how deeply utilities and infrastructure systems now depend on connected industrial devices2.


Why forensic readiness must be built by design


This shift requires the organizations to rethink the questions they ask. It is no longer sufficient to detect and respond to an incident, but whether they can investigate when issues arise.


Forensic readiness by design acknowledges that incidents will occur and focuses on limiting their impact. It involves understanding where evidence exists, setting realistic expectations for logging and retention, and ensuring that evidence can be accessed and validated in a repeatable and defensible way.


Investigative access must be controlled, approved and logged, rather than executed as an ad hoc response under pressure.


Operational resilience depends on investigation capability


In real-world scenarios, IIoT telemetry and device data can reconstruct incidents more accurately than traditional IT logs or human reporting. However, this data often resides within gateways or vendor-managed cloud platforms with limited retention.


Investigations extend beyond attribution. They help determine whether an incident was caused by equipment failure, misconfiguration, human error or a targeted attack. Without reliable evidence, organizations may risk applying incorrect fixes or leaving vulnerabilities unaddressed.

Conclusion

The evolution of IoT and IIoT has changed the nature of cyber incidents. Evidence is now more distributed, more fragile and increasingly tied to systems that keep infrastructure and economies running.

Forensic readiness is therefore no longer a niche technical concern but a core part of operational resilience. As IT, OT and IIoT environments continue to integrate, organizations face a critical question: are they building systems that can be both secured and effectively investigated when it matters most?


Summary

IoT and IIoT adoption is expanding across critical infrastructure, introducing new cyber risks and evolving investigation challenges. Evidence is often distributed, short-lived and difficult to preserve. Forensic readiness by design helps organizations improve incident investigation, strengthen resilience and make more informed decisions following failures or attacks.

Related articles

When the world shifts overnight, can you operate at the speed of trust?

Risk operating models must become strategy-first, trigger-based and governance-forward. Learn how Risk Strategists are leading the way.

Reimagine your cyber guardrails to accelerate AI value

In a nonlinear, accelerated, volatile and interconnected cybersphere, enterprise-wide AI adoption is safer and faster with cybersecurity guardrails.

About this article

Contributors