The module shares Domain 7 (10% in blueprint v5.0 as of Oct 11, 2026) with mobile platforms. IoT means cheap, numerous, internet-reachable devices with default credentials, exposed web and cloud interfaces and unencrypted local traffic. OT means a handful of controllers that move physical things, where a reboot is an outage. The IT vs OT security comparison turns that difference into a priority order you can apply under time pressure.
IoT botnets connect this module to the denial-of-service module: hijacked cameras and routers become the flood. Classify the malware behind them the way the virus vs worm vs trojan file does, by how it spreads; self-propagation across the internet is what made those botnets so large.
IoT architecture in five layers
- Edge technology: sensors, actuators and their radios
- Access gateway: bridges local protocols to IP
- Internet layer: transport between the site and the cloud
- Middleware: device management, data handling, access control
- Application: the dashboards and phone apps people touch
Four communication models
Device-to-device, device-to-cloud, device-to-gateway and back-end data sharing. A home hub that translates Zigbee traffic for a cloud service is the device-to-gateway model; two smart plugs talking over Z-Wave with no hub are device-to-device.
Attack names on each side
On the IoT side the outline's names are mostly about radios and scale: rolling-code attacks that capture and replay the unlock codes of key fobs and garage remotes, Sybil attacks where one node forges many identities to distort a mesh, jamming that drowns the channel, and ransomware that locks the device rather than the data.
On the OT side the targets are the control loop itself: HMI-based attacks that show operators false values, changes to PLC logic, replay of captured control commands, and attacks aimed at the safety instrumented system. Stuxnet is the textbook case: malware that altered controller logic while operators saw normal readings.
Countermeasures that score
Inventory comes first, because you cannot protect a device nobody knows is there. Then unique credentials per device from the day it is installed, unused services such as Telnet and UPnP switched off, and vendors chosen for publishing a vulnerability disclosure process. In OT, add strict change control: nothing touches a controller's logic without a ticket and a second pair of eyes.