Skip to content
Review Open access

Cybersecurity in the IoT Era: Protecting the Expanding Internet of Things

Aug 2026 · Recent Progress in Science and Engineering · 0 citations · 14 references

TL;DR

It is argued that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and where current technological and regulatory responses fall short of that goal is identified.

Abstract

The Internet of Things (IoT) is transforming industries and daily life by connecting billions of devices, enabling smart homes, cities and industrial systems. This rapid expansion, however, introduces significant cybersecurity vulnerabilities, leaving IoT systems increasingly exposed to both established and emerging attack techniques. This paper presents a structured critical review of IoT cybersecurity, distinguished from prior general surveys by three contributions: first, a cross-layer mapping of named, dated case studies to the specific Security-by-Design principles that would have mitigated them; second, a comparative, feasibility-based evaluation of lightweight cryptographic primitives and blockchain consensus protocols for resource-constrained devices, rather than a descriptive overview; and third, a critical appraisal of the operational limitations of AI-based and blockchain-based defences, including adversarial manipulation, data scarcity and energy cost, set against the claims commonly made for these technologies. We examine the current state of IoT security across the perception, network and application layers; the common vulnerabilities that affect these systems, from insecure device design and weak default credentials to unencrypted communications; and the real-world consequences of these flaws through recent, named case studies, including the Aisuru botnet which is active since 2024 and 2024 vulnerability disclosures affecting Mitsubishi Electric and OMRON industrial controllers. We argue that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and we identify where current technological and regulatory responses fall short of that goal.

Read PDF

Similar papers

Review Open access Aug 2026

A Comprehensive Review of Cybersecurity Threats, Vulnerabilities, and Mitigation Techniques in the Internet of Things (IoT)

The ways in which artificial intelligence, blockchain technology, edge computing, and Zero Trust Architecture will transform IoT security paradigms are examined, which will reveal long-standing issues such as resource limitations, device heterogeneity, and scaling challenges.

Muhammad Sami Intizar, Maria Sikandar, Aqsa Siddique et al. · 0 citations
Review Open access Aug 2026

A Systematic Review of Smart Home IoT Security: Applications, Threat Taxonomy, Privacy Risks, and Emerging Defensive Solutions

It is suggested that scalable smart home security requires coordinated progress in protocol standardization, enforceable device update lifecycles, gateway-level anomaly detection, and privacy-preserving local analytics rather than reliance on a single technical solution.

Dalibor Radovanovic, Nikola Savanović, Jelena Janackovic et al. · 0 citations
Conference Aug 2026

Blockchain-Enabled Cybersecurity Techniques, Challenges, and Future Directions for Secure Smart Grids

The smart grid systems are increasingly becoming digital where the system is taking a new direction into greater operational efficiency and real time energy management. The increased number of Internet of Things (IoT) devices and communication networks has widened the area of attack as well, thus smart grids are vulnerable to more sophisticated cyber attacks like false data injection, denial-of-data manipulation and service attacks. The traditional centralized security controls are not sufficient because of the limitation of single point failure, scalability limitations, and demand decentralized and resilient security controls. The use of blockchain technology in this regard has become a potential solution in order to improve the level of security by utilizing the transparent, decentralized, and immutable features of the technology. To provide cybersecurity approaches of smart grid systems, a taxonomical structure of blockchain technology is proposed in this paper. Besides that it shows the categorization of the various techniques into secure data management, secure energy trading, device authentication, data integrity assurance and communication protection. A detailed analysis of existing works was undertaken to determine their efficiency based on the security, scale and complexity of implementation. The results of the review describe some of the major challenges, such as latency and energy overhead and provide future research opportunities on effective smart grid security frameworks.

F. Basheer, Hari Gobind Pathak, Meena Malik et al. · 0 citations
Conference Aug 2026

Novel Cybersecurity and the Internet of Things (IoT) for Safeguarding Smart Grids: A Robust Architecture to Prevent Attacks on Specific Infrastructure

Energy networks are evolving into smart grids due to the expansion of the Internet of Things. Control is automated, monitored, and adjusted by intelligent network systems. While this method does enhance sustainability, efficiency, and reliability, it does so at the expense of cybersecurity. Critical infrastructure concerns have grown as a result of smart grids’ reliance on the Internet of Things. Smart meters, sensors, communication gateways, and controllers all fall under this category. Supply of electricity, confidentiality of data, and safety of the nation are all under risk from assaults on grid parts. To protect smart grid infrastructure from targeted attacks, this project employs an Internet of Things architecture driven by cybersecurity. Regions of the grid will be protected by multilayer security, advanced threat detection, and communication protocols. The most important things are ensuring the data is secure, authenticating devices, responding adaptively, and detecting anomalies in real-time. The smart grid’s visibility, resilience, and risk reduction are enhanced by a combination of centralized intelligence and decentralized security measures. Cybersecurity for smart grids is challenging because to the large amount of data, the number of devices involved, and the requirements for real-time operations. These concerns of cybersecurity based on the Internet of Things are addressed in this article. Scalability is ensured while infrastructure is protected. Sustainable, dependable, and environmentally friendly power systems are a result of secure IoT design.

Muruganantham Angamuthu, R. Alazaidah, Arumai Shiney et al. · 0 citations
Review Open access Aug 2026

Blockchain-Driven Cybersecurity Framework for Smart Digital Ecosystems

Overall, this review demonstrates that blockchain-based cybersecurity frameworks provide a secure, transparent, and resilient foundation for protecting smart digital environments against increasingly sophisticated cyber threats while supporting trustworthy and scalable digital transformation.

M. Kayla, Crispinus Ode, Marion Sanaipei · 0 citations
Preprint Aug 2026

CERTIoT-6G: Continuous Cybersecurity Certification for IoT Devices in 5G/6G Networks

The massive adoption of Internet of Things (IoT) devices across critical domains such as healthcare, smart cities, industrial automation, and critical infrastructure introduces significant cybersecurity and regulatory challenges. Current and forthcoming European regulations, including the Cyber Resilience Act (CRA) and the NIS2 Directive, require manufacturers, operators, and other organizations to ensure secure-by-design devices, continuous vulnerability management, and resilient operation throughout the device lifecycle. Traditional certification mechanisms remain static, manual, and difficult to scale across heterogeneous IoT ecosystems. This paper presents CERTIoT-6G, a Security-as-a-Service (SECaaS) framework that enables automated cybersecurity certification and continuous compliance monitoring of IoT devices operating in 5G and future 6G networks. The framework integrates automated compliance analysis, real-time traffic monitoring, and adversarial testing capabilities. We validate the CERTIoT-6G framework on different IoT device categories operating in an advanced 5G testbed. Evaluation results reveal critical compliance gaps, particularly in traffic encryption and availability under unstable conditions, and demonstrate that the framework produces actionable verdicts mapped to regulatory requirements across heterogeneous device types. Furthermore, we show that the monitoring pipeline has a negligible impact on live 5G traffic.

Evangelos Lempesis, F. Palmese, Hamed Haddadi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.