Dominic Jainy stands at the forefront of the modern digital landscape, where the convergence of artificial intelligence and interconnected hardware is reshaping how we work and live. With a deep professional background in machine learning and blockchain, Jainy has witnessed firsthand how the promise of the Internet of Things—efficiency, automation, and cost reduction—is often undermined by a fragile security foundation. In this conversation, we explore the evolving threat landscape where low-cost, unpatched devices create massive openings for cybercriminals. Jainy explains why the traditional perimeter-based security model is failing and how a zero-trust architecture, rooted in continuous verification and microsegmentation, provides the only viable path forward for the modern enterprise. We delve into the tactical challenges of managing thousands of endpoints, the struggle with legacy hardware that cannot support modern encryption, and the cultural shifts necessary to protect mission-critical data in an age of escalating supply-chain risks.
How does the rapid expansion of IoT devices fundamentally shift the risk profile for modern enterprises compared to traditional IT assets?
The explosion of IoT devices has dramatically widened the attack surface in ways that many IT teams are still struggling to visualize or control. Unlike traditional laptops or servers, which usually come with robust, built-in security features, IoT devices are notoriously vulnerable because they are often designed for low cost rather than high security. These systems frequently offer poor visibility, making it nearly impossible for security teams to track exactly what is connected to their network at any given moment. Because these devices often lack support for standard endpoint protection software, they become silent harborers for unpatched vulnerabilities and weak, factory-default credentials that hackers find incredibly easy to exploit. When a malicious actor compromises one of these devices, they don’t just stay there; they use it as a persistent backdoor to scan the entire network, eventually reaching mission-critical components. The result is a constant, underlying tension where a single pre-compromised sensor could lead to a massive botnet or a catastrophic ransomware attack that disrupts operations across the entire organization.
Why has the “never trust, always verify” philosophy emerged as a more practical solution for IoT than standard perimeter-based security?
The problem with perimeter-based security is that it relies on implicit trust—once a device is inside the “walls” of the network, it is often free to communicate with almost anything else. In the world of IoT, where devices are constantly being added and updated, that trust is a massive liability. Zero trust shifts the focus away from the perimeter and places enforcement directly on the network, ensuring that every single request is continuously validated regardless of where it originates. By employing network-based behavioral analytics, we can spot anomalies that suggest a device is behaving in a way it wasn’t intended to, such as a smart thermostat trying to access a financial database. This approach relies on microsegmentation to sharply restrict device communications to only what is strictly necessary for its function. If a device is compromised, this “least-privilege” policy ensures the threat is contained, preventing the lateral movement that often leads to data theft or total system failure. It replaces a “set it and forget it” mentality with a rigorous, data-driven cycle of verification that matches the high-stakes nature of modern cyber threats.
In environments managing thousands of endpoints, how does shifting enforcement from the device to the network solve the inherent scalability problems of IoT security?
Scalability is perhaps the greatest hurdle for any CISO dealing with an IoT rollout, especially when you are looking at thousands of endpoints scattered across different geographic locations and business units. If you tried to manage security individually on each device, you would immediately run into walls created by different operating systems, limited firmware capabilities, and varying hardware constraints. Zero trust solves this by moving the policy enforcement layer to the network itself, allowing for a centralized management strategy that applies to every device, regardless of its internal limitations. This method lets organizations automate enforcement, ensuring that a security policy updated in the central hub is instantly applied to all thousands of endpoints simultaneously. It takes the burden off the low-cost, resource-constrained device and places it on the more robust network infrastructure, which is better equipped to handle the computational load of continuous validation. This centralization not only saves time but also eliminates the inconsistent enforcement that occurs when IT teams are forced to use a patchwork of different security tools for different device types.
What are the primary hurdles you encounter when trying to apply modern authentication methods to resource-constrained or legacy IoT hardware?
The reality of many industrial and enterprise environments is that they are filled with legacy systems and resource-constrained devices that simply weren’t built for the modern internet. These devices often cannot support standard, network-based identity methods such as mutual authentication, public key infrastructure enrollment, or device attestation because they lack the processing power or memory. When we try to force-fit these modern security protocols, we often encounter significant latency issues that can hinder the real-time capabilities of critical IoT platforms, potentially causing operational delays. Furthermore, many of these endpoints use non-standard or proprietary protocols that don’t play well with common security software, leading to massive interoperability issues. Beyond the technical friction, there is also an organizational cultural shift required to move away from legacy workflows; without proper management, the sheer complexity of creating granular policies for such a diverse fleet can lead to muddled security postures. These “security gaps” are where the most dangerous risks hide, requiring a more creative, agentless approach that combines identity-based methods with sophisticated behavioral analytics to maintain protection.
Could you walk us through the phased approach a CISO should take to establish a robust zero-trust foundation without disrupting ongoing operations?
Implementing zero trust is a marathon, not a sprint, and it must begin with an exhaustive phase of discovery and inventory. You cannot protect what you cannot see, so the first step is to identify and classify every existing IoT device, documenting its function, its protocol, and its typical communication patterns to understand its inherent risk level. Once the landscape is clear, we define protection boundaries, which involve specifying exactly which external resources each group of devices needs to communicate with to perform its job. With those boundaries set, we move to the microsegmentation phase, where we create and enforce strict least-privilege access policies that prevent any unnecessary lateral communication. For those tricky devices that cannot support agents, we develop context-aware policies that rely on behavioral analytics to flag any deviation from the norm. Finally, the process must be circular; you must constantly measure and adjust, using tools to track metrics like lateral-movement reduction and policy-enforcement rates. This phased approach allows the organization to tighten security incrementally, ensuring that they are restricting dangerous communication flows without accidentally shutting down mission-critical operations.
What is your forecast for the future of IoT security within the enterprise landscape?
I believe we are moving toward a future where “security by design” will no longer be an optional luxury but a regulatory and operational requirement for all IoT manufacturers. Over the next few years, we will see a significant shift as the NIST Cybersecurity Framework and standards like IEC 62443 become more deeply integrated into the procurement process, forcing vendors to improve built-in protections. However, even as devices get smarter, the complexity of our networks will continue to outpace them, making zero-trust architecture the permanent, foundational standard for enterprise security. We will likely see AI-driven automation take a lead role in managing these networks, where machine learning models can detect and isolate a compromised sensor in milliseconds, far faster than any human operator could. Ultimately, the successful enterprises will be those that view security not as a hurdle to innovation, but as the very foundation that allows them to scale their IoT ambitions with confidence and resilience. The financial and reputational stakes are simply too high to rely on anything less than a “never trust, always verify” mindset as we move into a more connected, yet more volatile, digital era.
