TrendSane

The Next Cybersecurity Problem May Be an Unpatched Physical Device

The Next Cybersecurity Problem May Be an Unpatched Physical Device

Published on Oct 1, 2026 · 7 min read

The next serious cyber weakness may not be a forgotten laptop or a leaked cloud credential. It may be a device bolted to a wall, installed above a ceiling, attached to a patient or embedded in a production line. Sensors, access-control panels, building-management gateways, infusion pumps and industrial controllers increasingly communicate with wider networks. That connectivity delivers useful data and remote control. It also turns physical infrastructure into part of the digital attack surface.

Connected device cybersecurity is difficult because these systems cannot always be managed like conventional computers. A server can often be restarted during a maintenance window. An elevator controller, hospital imaging system or process-control device may operate continuously, depend on specialist vendors and require careful testing before any software change. In some settings, taking equipment offline can interrupt care, operations or safety systems.

The consequence is a growing gap between the speed of software vulnerabilities and the slow, highly constrained lifecycle of physical equipment. Security is no longer solely an IT problem. It is an operational, engineering, procurement and governance problem.

The security perimeter now reaches into physical systems

Connected devices collect information, exchange commands and sometimes directly influence the physical world. A building system can change temperatures, control lighting, unlock doors or manage alarms. A medical device can support diagnosis or therapy. An industrial control system can regulate pressure, flow, motion, temperature or chemical processes.

Many such devices were designed for long service lives and predictable local environments, not for frequent software updates or hostile network conditions. Some use embedded operating systems, proprietary software and protocols built for reliability rather than modern authentication and encryption. Others are connected indirectly, through gateways, remote support tools, maintenance laptops or cloud management services.

This does not mean every older device is easily compromised, or that a vulnerability automatically produces physical harm. Exploitation usually depends on factors including network access, configuration, attacker capability and available safeguards. But the potential impact changes when a digital intrusion can disrupt a facility, halt a production process or interfere with equipment that people rely on.

Why patching an embedded device is not a routine update

On office computers, the standard security advice is familiar: install updates, use endpoint protection and replace unsupported systems. Those measures remain important, but they are incomplete for embedded systems security.

Physical devices can have narrow maintenance windows, limited storage and processing capacity, or update mechanisms that require an on-site technician. An update may need to be validated against a particular hardware configuration and connected workflow. A change that is harmless on a desktop computer could alter timing, interoperability or reliability in a safety-sensitive environment.

Vendor dependency is another obstacle. The organization that operates a device may not control its firmware, may need a service contract to obtain updates, or may discover that software support ended years before the hardware reaches the end of its useful physical life. In complex facilities, responsibility may be split among IT teams, facilities managers, clinical engineering staff, equipment suppliers and outsourced maintenance firms.

That is why the phrase unpatched devices can be misleading if it suggests simple neglect. Sometimes a patch exists but has not been tested. Sometimes it must be scheduled around operations. Sometimes no supported update is available. The security response must account for those different realities.

Building automation can become an overlooked entry point

Modern buildings contain networks of HVAC equipment, smart meters, cameras, lighting controls, elevators, visitor systems and electronic access controls. These systems are valuable targets because they often have broad visibility into a site and, in some cases, authority over physical access or environmental conditions.

Building automation security becomes especially challenging when operational networks are poorly separated from corporate networks, guest Wi-Fi, contractor connections or internet-facing management interfaces. A remote vendor connection intended for maintenance can become a route into a building-management environment if access is overly broad or weakly monitored.

The practical risk is not limited to dramatic scenarios. An intrusion could cause uncomfortable or unsafe operating conditions, disrupt access workflows, create costly downtime or provide attackers with a foothold for moving elsewhere in an organization. Facilities teams therefore need the same clarity about assets, access paths and support status that security teams expect for servers and laptops.

Medical device security has to balance protection and patient care

Healthcare organizations face a particularly difficult trade-off. Medical equipment must remain available for clinical use, yet it can include long-lived computers, networked instruments and specialized embedded devices. Security changes may require clinical review, vendor guidance and validation that the device will continue to perform as intended.

US regulators, including the Food and Drug Administration, have increasingly emphasized cybersecurity across the medical-device lifecycle. Manufacturers submitting certain devices to the FDA are expected to address cybersecurity in their design and post-market plans, including vulnerability monitoring and processes for managing updates. Coordinated vulnerability disclosure has also become an important way for researchers, manufacturers and providers to handle flaws responsibly.

Still, the presence of a disclosed vulnerability should not be treated as proof of imminent patient risk. Hospitals need to assess the specific device, its network exposure, compensating controls, clinical role and manufacturer recommendations. In many cases, the safest immediate response is not an emergency update but tighter segmentation, restricted remote access and heightened monitoring while a validated remediation path is prepared.

OT cybersecurity is different from conventional IT security

Industrial control system security has its own logic. Information technology primarily handles data and business applications. Operational technology, or OT, monitors and controls processes in factories, utilities, transport systems and other industrial environments.

In OT, confidentiality matters, but availability and safety can be more immediate concerns. A poorly planned scan, configuration change or reboot may interrupt machinery or interfere with a process. Older controllers can remain in service for decades, and their communications may be tightly integrated with engineering workstations, sensors and human-machine interfaces.

Cybersecurity agencies such as CISA routinely publish advisories affecting industrial control products and other connected equipment. Those advisories are a reminder that vulnerabilities can emerge in components deep inside operational environments, including software libraries, remote-management functions and network-facing interfaces. The appropriate response is not necessarily to apply every update instantly; it is to assess exposure and deploy changes through a controlled, safety-aware process.

You cannot secure devices you cannot see

The visibility problem is often the first and largest weakness. Organizations may not have a reliable inventory of every connected device, its software version, owner, location, network relationship or support status. Shadow connectivity can arise when a contractor installs a gateway, a department buys an appliance, or an older system remains connected after its original project ends.

Without that inventory, risk assessment becomes guesswork. Teams cannot easily determine whether a newly disclosed flaw affects their environment, which devices are exposed to remote access, or which systems depend on a vulnerable component.

A practical baseline for connected device cybersecurity

  • Build and maintain an asset inventory that includes device type, owner, location, firmware or software version, support status and network connections.
  • Segment networks so building, clinical and industrial systems do not have unnecessary paths to business systems or the public internet.
  • Limit privileged and remote access with least-privilege permissions, multifactor authentication where feasible, and tightly controlled vendor access.
  • Use passive monitoring where appropriate to identify unusual traffic without disrupting fragile operational systems.
  • Apply compensating controls when updates are unavailable, such as firewall rules, protocol filtering, access restrictions and isolated management networks.
  • Test recovery plans for equipment failure, ransomware disruption and loss of a critical management system.
  • Buy for the lifecycle by requiring clear security support periods, vulnerability disclosure policies, update mechanisms and, where relevant, software component documentation.

Security has to become part of infrastructure ownership

No single tool solves the problem of long-lived connected equipment. Antivirus may not run on a controller. Password changes cannot repair insecure firmware. Network segmentation reduces exposure but does not eliminate a flaw. Virtual patching and traffic filtering can provide valuable protection, but they require accurate knowledge of normal communications and disciplined maintenance.

The durable answer is to treat physical infrastructure as part of the organization’s digital estate from the day it is purchased to the day it is retired. That means assigning an accountable owner, budgeting for support and replacement, documenting supplier responsibilities, and planning for secure decommissioning as well as deployment.

As more devices become connected, the question is not whether an organization has a cyber perimeter. It is whether it understands where that perimeter now exists. Increasingly, it runs through the systems that heat buildings, deliver care, move materials and keep essential services operating.

Image by StefanCoders on Pixabay.