ChannelPro Network: IAM for IoT
On March 1, 2022, Larry Trowell was featured in a ChannelPro Network article titled, IAM for IoT. Preview the article below, or read the full article online here.
+ + +
IDENTITY AND ACCESS MANAGEMENT is hard enough when it’s mostly users you have to worry about. When large volumes of vulnerable IoT devices are involved as well, the challenges only get greater.
“IAM is already a complex subject, and the addition of IoT devices makes the entire process much more complex,” says Larry Trowell, principal consultant at NetSPI, a penetration testing-as-a-service security company in Minneapolis.
In IT, IAM “is used to streamline user digital identities, and to enhance the security of user-facing front-end operations,” says Dimitrios Pavlakis, a senior analyst at ABI Research. Policies for passwords, email, accounts, and more can be automated, like onboarding, to meet security requirements and compliance rules. These advantages apply to IoT devices as well as users, but there are numerous hurdles.
For instance, domain controllers used by many companies often have trouble supporting IoT devices with limited client intelligence, according to Trowell. Even cloud solutions prepared for IoT devices “may not be able to operate with the level of access businesses feel they should,” he notes. Multiple IoT devices may need to maintain identities and roles between various accounts, leading to security gaps within this complex environment.
Explore More News
Canvas breach puts global education cyber risk in focus
ITBrief interviewed NetSPI's Field CISO, Nabil Hannan, for a May 24, 2026 article about a major data breach in Instructure's Canvas learning management system disrupting final exams at universities.
Microsoft is working on a patch for ‘YellowKey’ attack on BitLocker, offers temporary fix
CSO Online interviewed NetSPI's VP of Research, Karl Fosaaen, for a May 20, 2026 article about how Microsoft is working on a patch for a zero-day vulnerability dubbed "YellowKey" (CVE-2026-45585).
AI-powered Continuous Pentesting
NetSPI® launches AI-powered Continuous Pentesting to help organizations validate and reduce risk through their Human-led, AI-accelerated platform that supports continuous penetration testing and agentic MCP integrations.