CISA’s IoT Crackdown: What 21 Billion Devices Mean Now
The scale problem: 21 billion devices and counting
| Metric | Figure | Source |
|---|---|---|
| Global connected IoT devices (2025) | 21.1 billion, +14% YoY | IoT Analytics |
| Breaches traced to unpatched firmware | 60% | IoT Security Foundation |
| Routers running firmware that will never be patched | 32% | ORDR / Forescout |
| Average vulnerabilities per router/switch | 32 | Forescout |
| Edge vulnerabilities fully remediated | 54% (32-day median) | Verizon 2025 DBIR |
| Peak DDoS traffic from a hijacked-IoT botnet | 29.7 Tbps | Cloudflare, Q3 2025 |
Inside CISA’s BOD 26-02
- Immediate: Patch where feasible.
- 3 months (by May 5, 2026): Complete inventory of end-of-support edge devices.
- 12 months (by February 5, 2027): Decommission those devices.
- 18 months (by August 5, 2027): Full removal from the network.
- 24 months (by February 5, 2028): Continuous discovery process in place permanently.
The breaches that forced the issue
BadBox 2.0
Aisuru and Kimwolf
RondoDox against enterprise infrastructure
Why zero trust breaks down in IoT and OT
“We all agree: zero trust is necessary. But it’s been hard to implement. It doesn’t matter what you read or which framework you follow. The core issue is that we have a concept with principles and tenets, but not enough guidance on how to implement it.” Morey Haber, Chief Security Advisor, BeyondTrust, via Network World
“The biggest security incidents in 2026 will stem from compromised identities within supposedly zero trust environments. The illusion of control will persist until identity management becomes contextual and adaptive, powered by AI that can interpret intent, not just credentials.” Ariel Parnes, COO, Mitiga (former IDF Unit 8200 colonel), via SecurityWeek
“We will eventually get there, but timelines extend well beyond 2026 due to fundamental structural barriers. Private data exchanges must simultaneously secure data flows across partners’ legacy systems, cloud environments, and on-premise infrastructure, while maintaining operational compatibility with hundreds of exchange participants at varying security maturity levels.” Dario Perfettibile, VP and GM of European Operations, Kiteworks, via SecurityWeek
What enterprise security teams should do now
- Inventory first. CISA’s own timeline gives federal agencies three months just to find every end-of-support edge device. If a federal agency needs that long, assume your enterprise network has blind spots too.
- Benchmark against 32 days. Use the DBIR’s median remediation time as your internal SLA target, and track what percentage of your edge vulnerabilities actually get fully closed, not just acknowledged.
- Segment what you can’t authenticate. If a device can’t run MFA or a client certificate, it goes on an isolated network segment with active behavioral monitoring, not on the same trust tier as your laptops.
- Watch the procurement deadline. By January 4, 2027, vendors selling consumer IoT to the U.S. federal government must carry the FCC’s Cyber Trust Mark. That’s a voluntary label today. It becomes a de facto procurement filter in eighteen months, and enterprise buyers will likely start asking for it too.
Frequently asked questions
How many IoT devices are there in 2026?
What percentage of IoT breaches are caused by unpatched firmware?
What is CISA BOD 26-02?
Does zero trust work for IoT devices?
Where this goes next







