Buying a connected device is no longer only a purchasing decision. It can also be a cybersecurity decision that stays with an organisation for ten or fifteen years.
That is especially true in connected buildings and distributed estates. CCTV, access control, lighting, HVAC, lifts, meters, alarms and environmental sensors increasingly connect to networks, cloud platforms and remote-management systems.
The benefits are significant; facilities teams can monitor assets remotely, identify faults earlier, reduce unnecessary site visits and use energy or water more efficiently. But every new connection also creates another asset, data flow and access path that needs to be understood and managed.
Procurement teams do not need to become cybersecurity specialists. Their role is to make sure security is considered before a product is selected and contracted, rather than discovered as a problem after hundreds of devices are installed.
The IoT Security Foundation's Building Technology Procurement Guide makes the same point: connected technology should be procured with cybersecurity, resilience and lifecycle risk built into the process from the outset.
For procurement teams, that means involving the right stakeholders, matching controls to risk and asking suppliers for evidence rather than broad assurances.
Why IoT Changes the Risk of an Ordinary Building Purchase
Historically, many building systems operated largely separately from corporate IT.
A lighting controller managed the lights. An access system opened doors. An HVAC system controlled the temperature.
That boundary is becoming less clear.
Modern operational technology, or OT, can share network infrastructure with traditional IT, exchange data with business applications or depend on cloud services and remote support. This convergence can make buildings more efficient, but it also changes the consequences of a security weakness.
A thermostat or smart light fitting can hold little valuable data itself. The more important question is what the device can reach, what it can control and what could happen if it were compromised.
If a poorly secured building asset can communicate with more sensitive systems, an attacker could use it as a route towards something more valuable. Equally, if a connected access-control, alarm, or CCTV system becomes unavailable, the operational impact will matter even if no data is stolen.
That is why low-value IoT devices should not automatically be treated as low-risk.
Procurement Decisions Can Lock in IoT Risk for 10 to 15 Years
The lifespan of building technology makes this particularly important.
Phones and laptops are replaced relatively frequently. HVAC systems, CCTV, access control, and other building infrastructure can remain in place for a decade or longer. Once equipment is installed across a large building or estate, replacing it early can be disruptive and expensive.
Procurement should therefore look beyond whether a product appears secure on day one.
The better question is whether the organisation can keep it secure throughout its working life.
Ask how long security updates will be provided, how newly discovered vulnerabilities will be handled, how customers will be notified, who controls supplier access, what happens at end of support and whether another provider could take over if the original supplier can no longer support the system.
These are not purely technical questions. They affect contracts, warranties, service levels, maintenance costs, business continuity, and replacement planning.
In other words, they belong in procurement.
Regulation is Making Cybersecurity Evidence Part of Supplier Due Diligence
The regulatory direction is also clear. The EU Cyber Resilience Act introduces cybersecurity requirements for products with digital elements across their lifecycle.
Its reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026, while most of the Act's provisions apply from 11 December 2027.
The exact legal obligations will depend on the product, organisation, and market, so businesses should take appropriate legal advice.
But the procurement lesson is straightforward: cybersecurity evidence is becoming a normal part of supplier due diligence.
Teams that start asking for that evidence during sourcing are in a much stronger position than those trying to introduce requirements after a supplier has been selected.
IoT Procurement Should Not Sit with One Department
One of the most useful recommendations in the IoT Security Foundation guidance is the creation of a Procurement Project Steering Group.
The principle is simple: no single department has the full picture.
Procurement understands tendering, pricing, and supplier negotiation. IT and cybersecurity understand networks, applications, identity, software risk, and access controls. Facilities teams know how the equipment will be used, maintained and physically accessed.
Legal and compliance can assess contractual liability and data obligations. Finance can examine support, maintenance, and replacement costs. Physical security may need to assess the consequences of failures in CCTV, access control, or alarms.
Sustainability teams may also have a role where connected technology is intended to reduce energy, water use or unnecessary travel.
Each stakeholder sees a different part of the risk. The important point is to involve them early.
Bringing cyber or IT teams into a project after the preferred product has already been chosen limits their ability to influence the design. Security requirements are much easier to specify while suppliers are still competing for the work.
Not Every IoT Device Needs the Same Level of Security
A risk-based approach is essential.
Treating every connected product as equally dangerous creates unnecessary cost and bureaucracy. Treating every connected product as harmless creates obvious gaps.
Compare a vending machine that reports stock levels with a biometric access-control system protecting a restricted area.
Both may be connected devices, but the consequences of compromise are very different.
The IoT Security Foundation uses Assurance Classes to help organisations match security expectations to the risk presented by a device or system.
Procurement teams do not need to turn this into a complex process. The underlying principle is simple: the higher the potential impact, the stronger the evidence and controls you should expect from the supplier.
For a low-impact sensor, a proportionate security review may be sufficient. For technology that processes sensitive data, controls physical access, affects safety or connects to critical systems, procurement should expect much stronger evidence.
What Should Procurement Ask IoT Suppliers in an RFP?
This is where procurement has real leverage.
Suppliers are more likely to provide detailed evidence while competing for a contract than years later when the technology is already embedded in the estate.
Avoid broad questions such as "Please describe your cybersecurity." They invite broad marketing answers.
Ask for specifics instead: how are passwords and device credentials managed?
Ask whether devices use unique credentials, whether factory credentials must be changed before go-live and how privileged credentials are stored, rotated and revoked.
Shared default passwords should be treated as a serious warning sign.
For how long will security updates be provided?
Do not accept "for the supported life of the product" without asking the supplier to define that period.
Where the support period is material to the purchase, consider making it a contractual commitment.
How is data protected at rest and in transit?
Ask what data the product stores, where it is stored, what encryption is used and how data is protected while moving between the device, network, cloud platform and business systems.
How are vulnerabilities reported and fixed?
Ask for the supplier's vulnerability disclosure policy, how customers are notified, how issues are prioritised and the expected timescales for remediation.
How is remote access controlled?
Establish who can access deployed devices, how supplier access is authenticated, whether access can be time-limited and how sessions are logged or reviewed.
Can the supplier provide a Software Bill of Materials?
For higher-risk products, ask whether the supplier can provide and maintain a Software Bill of Materials (SBOM).
An SBOM is an inventory of the software components inside a product. Modern devices typically depend on operating systems, libraries and third-party components.
If a serious vulnerability is later discovered in one of those components, an SBOM can help teams determine which products are affected.
What happens at end of support?
Ask how customers will be notified, whether extended support is available, how data can be exported and what migration options exist.
What security evidence can the supplier provide?
Depending on the risk, this might include security architecture documentation, relevant certifications or assurance evidence, penetration-test summaries, vulnerability-management processes, update policies and secure-development practices.
The objective is not to collect documents for the sake of it.
It is to distinguish mature suppliers with repeatable security processes from those relying on vague claims.
IoT Security Starts on Installation Day
Buying a secure product is only part of the job. It can still be deployed insecurely.
Factory credentials could never be changed. Unnecessary services remain enabled. Old firmware installed. Remote support left permanently open.
Devices may also be connected to parts of the network they never need to reach. Day-one configuration should therefore be part of the security plan.
Organisations should confirm that default credentials have been removed or changed, unused services are disabled, administrative access is restricted and devices begin life on supported firmware.
They should also record what has been installed, where it is located, which network or connectivity service it uses and who owns it operationally.
That asset record matters. Connected estates have a habit of accumulating forgotten technology. Years later, teams can discover a networked device with no clear owner, support route or update status.
Basic inventory discipline makes that much less likely.
Connectivity Should Also Be Part of the IoT Security Review
Device security gets a great deal of attention. Connectivity sometimes gets much less, and that is a mistake.
Where and how an IoT device connects can materially affect its exposure.
Devices placed directly on corporate or building networks can be perfectly appropriate, but they require careful segmentation and control over what each device can communicate with.
For some use cases, managed cellular connectivity provides another architectural option.
Giving a device its own cellular connection can reduce the need to place that asset directly on an internal LAN.
It does not remove cyber risk. The device still needs secure software, strong credentials, appropriate access controls and lifecycle management.
But cellular connectivity can help organisations create clearer separation between deployed IoT assets and sensitive corporate systems.
Cellhire's IoT connectivity services support options including private APNs, private and public IP addressing, L2TP and IPsec tunnelling, VPN connectivity and centralised SIM management through the portal.
Our CCTV and security case study shows how that can work in practice.
A national CCTV provider deployed multi-network IoT SIMs with a dedicated IPsec VPN across hundreds of camera sites, creating an encrypted private path between the SIM estate and the organisation's monitoring infrastructure.
The lesson for procurement is broader than any one technology: connectivity is part of the system architecture and should be reviewed alongside the device, platform and support model.
Availability is Part of IoT Security Too
Security is not only about preventing unauthorised access.
Availability also matters.
A CCTV camera that is difficult to compromise but regularly loses connectivity still fails its operational purpose. The same applies to alarms, access-control systems, payment terminals and monitoring equipment.
For cellular IoT deployments, resilience can therefore be a procurement requirement.
A device that depends on one mobile network also depends on that network providing usable service everywhere the device operates.
Cellhire's unsteered multi-network IoT SIMs can access all four major UK mobile networks, and our global IoT proposition currently provides access to more than 400 networks across 185+ countries.
That does not mean outages disappear.
It means a device can have alternative network options when coverage or service conditions change.
For systems that need to remain connected, resilience and cybersecurity should be considered together.
Secure IoT and Sustainable Procurement Can Support the Same Goals
Many IoT projects are designed to use resources more intelligently.
Smart meters can improve visibility of energy or water consumption. Remote monitoring can reduce unnecessary journeys. Sensors can identify abnormal conditions before an engineer needs to travel.
Connected systems can help facilities teams understand how buildings and equipment are performing.
These benefits are only durable if the technology remains secure, supportable and operational.
A device that reduces resource use but becomes unsupported after a few years is a weak long-term purchase. So is a system that reduces manual monitoring but introduces unnecessary security exposure.
Good procurement therefore looks at the whole lifecycle: can the technology remain secure, useful, connected, supportable and manageable for as long as the organisation expects to depend on it?
IoT Security Checklist for Procurement Teams
Before approving a connected product or system, procurement should be able to answer:
- What happens if the device stops working or is compromised?
- What information does it store or process?
- Which other systems can it communicate with?
- How long will security updates be provided?
- Does the supplier have a clear vulnerability disclosure process?
- Can it provide an SBOM where proportionate?
- How is remote access controlled and logged?
- Who owns patching after installation?
- How will the equipment be securely decommissioned?
- How will the device connect to business systems?
- What level of connectivity resilience is required?
- Who owns the asset and its security risk throughout its lifecycle?
If several answers are unclear, the project probably needs more work before the contract is signed.
Good IoT Security Begins Before the Purchase Order
The most expensive time to discover an IoT security problem is after a large deployment has gone live. Procurement teams are in a strong position to prevent that.
They can bring IT, cybersecurity, facilities, legal, finance and other stakeholders into the conversation before the specification is final. They can ask suppliers for evidence. They can put long-term support and security requirements into the commercial agreement.
They can define decommissioning responsibilities before the first device is installed.
And they can make connectivity part of the security design rather than treating it as a commodity bought at the end.
Cellhire provides managed IoT connectivity including multi-network SIMs, private APN and IP options, VPN and tunnelling options, and centralised SIM management.
Its solutions support applications including security and CCTV, asset tracking, logistics, retail, industrial manufacturing and remote connectivity.
For further reading, explore our IoT connectivity solutions, IoT case studies and guide to IoT security blind spots.
Planning an IoT Procurement Project?
Bring connectivity into the conversation early.
Cellhire's IoT specialists can help assess coverage, resilience, private networking and SIM-management requirements before devices are deployed.
Organisations can also test our IoT connectivity with a 60-day IoT SIM trial, including two trial SIMs and access to the SIM Management Portal, to evaluate connectivity with their own hardware and use case.



