The device nobody signed for
In December 2024 the Government Accountability Office reported on how 23 federal civilian agencies were doing against a requirement Congress gave them in 2020: maintain an inventory of their internet-connected devices. Three agencies said they would miss the September 2024 deadline. Six gave no timeframe at all. One reported that it has no IoT devices requiring an inventory.
That last answer is the one worth sitting with. It is almost certainly not dishonest. It is what happens when the question gets routed to the office that manages laptops and servers, and the devices in question were bought by someone else.
Why inventories fail in the middle
Network-connected equipment arrives through three doors and only one of them is IT. Facilities buys building automation, HVAC controllers, badge readers and cameras. Operations buys sensors, scales, scanners and machine controllers. Clinical and lab teams buy instruments with embedded computers and a support contract that forbids patching. Each of those purchases is legitimate, budgeted and approved. None of them triggers a security review, because the purchase order says equipment, not computer.
By the time security sees the device it is racked, cabled, in production, and someone's process depends on it. What follows is not a security conversation. It is a negotiation with a business owner who was never told there was a decision to make.
The water sector version
This is not theoretical, and the clearest public example is the water sector. EPA and CISA published a joint fact sheet on internet-exposed human machine interfaces at water and wastewater systems: the operator screens that control pumps and chemical dosing, reachable from the open internet, sometimes with no authentication in front of them. The guidance in it is not sophisticated. Take the interface off the public internet. Put authentication in front of it. Know that it exists.
That last one is the hard part, and it is the same failure as the federal inventory. You cannot take something off the internet if nobody has written down that it is there.
Three questions that do more than a tool
Before anyone buys a discovery platform, three questions will tell you most of what you need to know about your exposure.
First, what is on the network that nobody owns. Not unmanaged in the IT sense. Unowned, meaning there is no named person who would be called if it failed or started behaving strangely.
Second, who signed for it. Every device has a purchase record somewhere. That record names a business owner, and the business owner is the person who can tell you what it does, what it connects to, and whether it can be patched or replaced at all.
Third, what does it talk to. A device that only speaks to its own controller is a contained problem. A device that reaches the internet, or reaches the network your finance systems sit on, is a different problem carrying the same purchase price.
Those three answers produce an inventory that is actually useful, because it carries ownership and consequence rather than an IP address and a MAC.
Then make it somebody's job
Inventories go stale because building one is a project and maintaining one is a habit. The habit has to attach to something that already happens, and the most reliable hook is procurement. Any purchase above a threshold that plugs into a network or a wall gets one question added to the approval: does this connect to anything, and who owns it. That single line catches most of what would otherwise arrive unannounced.
Every governance framework assumes this work is done. NIST guidance, CMMC, ISO 27001 and essentially every regulated-industry audit begin with asset identification, because you cannot apply a control to a thing you have not named. Agencies did not miss the IoT inventory deadline because the requirement was unclear. They missed it because inventory is the hardest unglamorous work in the field, and it never has a deadline of its own until someone else sets one.
Where to start
If you are not confident what your own answer to the first question would be, that is worth an hour of somebody's attention before it is worth a purchase order. We run a short discovery call for exactly this. No scan, no tools, no pitch, just a straight read on what is on your network and who owns it: https://www.netsecurely.com/service-page/free-discovery-call-15-to-30-minutes
Sources: GAO-25-107179, Internet of Things: Federal Actions Needed to Address Legislative Requirements, published 4 December 2024, https://www.gao.gov/products/gao-25-107179 . EPA and CISA joint fact sheet, Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems, https://www.epa.gov/system/files/documents/2024-12/joint-factsheet-epa-cisa-internet-exposed-human-machine-interfaces-508c.pdf




Comments