Best Practices for Device Onboarding
The old approach was simple: install a thermostat, plug in a camera, connect a badge reader, and move on. Security was an afterthought. The devices were on the network. They worked. That was enough.
That approach is now a liability.
Commercial buildings today run on dozens, sometimes hundreds, of connected devices. HVAC sensors. Smart locks. IP cameras. Occupancy detectors. Access control panels. Visitor management kiosks. Each one is a potential entry point. And most of them were deployed with default credentials, no network segmentation, and zero ongoing monitoring.
The threat is not theoretical. Attackers have breached corporate networks through unsecured building management systems. A poorly configured smart lock has exposed an entire access control database. A camera with a default password has become the pivot point for a ransomware attack.
The question is not whether your building has IoT vulnerabilities. It is how many, and what you are doing about them.
1. Why Unmanaged IoT Devices Are a Different Kind of Risk
Traditional IT security focuses on computers, servers, and software. IoT devices operate in a different category. They often run stripped-down operating systems that cannot support traditional endpoint security agents. Firmware updates are infrequent, inconsistent, or ignored entirely. And because they perform a specific physical function, facility managers treat them as infrastructure rather than technology assets.
This creates a perfect storm of exposure:
- Devices are installed and forgotten, often with factory-default usernames and passwords still active
- They sit on flat, unsegmented networks alongside business-critical systems
- Nobody owns them from a security standpoint; facilities owns the function, IT does not want to touch them
- Vendors may have end-of-life’d the firmware, leaving known vulnerabilities permanently unpatched
2. What Secure-by-Default Device Onboarding Actually Means
Secure-by-default is not a product. It is a process. It means that before any IoT device touches your network, a defined set of security protocols has been applied. The device is hardened at installation, not patched reactively after a breach.
A proper onboarding process includes:
- Credential rotation: Every device gets a unique, strong password at deployment. Default credentials are never left in place.
- Network segmentation: IoT devices are isolated on dedicated VLANs, separating them from business systems and reducing lateral movement risk.
- Firmware verification: The latest stable firmware is applied before the device goes live, and a schedule for future updates is established.
- Asset inventory: Every device is logged with its make, model, firmware version, network location, and assigned owner.
- Access control: Management interfaces are restricted by IP, role, and authentication method. Remote access is secured through VPN or zero-trust architecture.
3. The Role of Network Architecture in IoT Security
How your network is designed determines how far an attacker can travel if a single device is compromised. A flat network, where every device can communicate with every other device, is the most dangerous configuration for IoT-dense environments.
The industry standard for commercial buildings is micro-segmentation by device class. Security cameras live on one VLAN. Access control on another. Building automation systems on a third. Business computers and servers on a fourth. Each segment has firewall rules that allow only the specific traffic required for that system to function.
This architecture does not eliminate risk. It contains it. If a thermostat is compromised, the attacker is isolated to that segment. They cannot use it to pivot to your HR system or financial data.
4. Ongoing Monitoring: Because Onboarding Is Not Enough
Secure onboarding establishes a baseline. Monitoring maintains it. IoT devices can be compromised after deployment through firmware exploits, credential theft, or physical tampering. Without continuous visibility, you will not know something is wrong until damage has been done.
Effective IoT monitoring includes:
- Anomaly detection for unusual traffic patterns or unexpected outbound connections from device segments
- Alerting for failed authentication attempts on management interfaces
- Regular audits of device inventory to identify unauthorized additions (shadow IoT)
- Firmware update tracking with documented EOL status for every device class on the network
5. How HS Tech Group Builds Secure IoT Environments
For 30 years, HS Tech Group has designed and deployed security, AV, and automation systems for commercial facilities across Maryland. We have watched IoT evolve from a convenience technology into a core infrastructure layer, and we have adapted every phase of our deployment process to reflect that reality.
Every commercial installation we design begins with a network architecture review. We work with your IT team or network provider to ensure that devices are segmented correctly before a single endpoint goes online. We apply credential protocols at installation and document every device in a structured asset register.
We also leverage the Alarm.com platform for unified device management, providing our commercial clients with a single pane of glass for monitoring security, access, and automation systems. This integration gives facility managers real-time visibility and gives us the ability to identify anomalies before they become incidents.
We do not hand you a system and walk away. We build environments where security is the starting point, not the afterthought.
How many unmanaged devices are sitting on your building network right now?
If you do not have a complete answer to that question, you have a gap worth closing. Contact HS Tech Group to schedule a commercial security assessment and get a clear picture of your IoT exposure before someone else does.

