ABI whitepaper warns end of “trust me” for IoT

  • August 25, 2026
  • Steve Rogerson

Rising regulatory, legal and procurement expectations are shifting IoT cyber security from asserted trust towards documented, defensible security assurance, according to a whitepaper from ABI Research.

The whitepaper finds that IoT cyber security is moving beyond technical best practice and becoming an issue of corporate governance, procurement accountability and reasonable care.

As US federal policy, regulatory scrutiny and enterprise risk management converge ahead of January 2027, organisations will increasingly need documented, defensible evidence that connected devices meet recognised cyber-security baselines.

The shift represents what ABI Research describes as the end of “trust me” security. For decades, organisations have relied on manufacturer claims, supplier assurances, contractual promises and internal processes to establish trust in connected products. As regulatory and legal scrutiny increases, those assertions are giving way to a need for objective evidence that recognised security requirements have been met.

Next year marks a turning point for connected device security as trust can no longer rest on vendor claims alone. For boards, CIOs, CISOs and procurement leaders, the question is shifting from whether a breach can happen to whether the organisation can demonstrate that it exercised reasonable care in selecting, deploying and governing IoT devices.

ABI Research estimates there were 19bn IoT connections globally in 2025, with that number forecast to grow to 37bn by 2030. As the number of connections nearly doubles and connected devices proliferate across homes, workplaces, healthcare environments, schools, industrial sites and public sector infrastructure, the expanding attack surface creates risks ranging from lateral movement and data compromise to service disruption, unauthorised surveillance and broader network exposure.

The US Cyber Trust Mark is significant not only as a consumer-facing label, but as an operational and evidentiary benchmark for organisations. With technical roots in NIST IoT cyber-security guidance and FCC oversight, the programme establishes a measurable baseline that can help organisations evaluate connected devices and demonstrate due diligence.

This shift could also change how routine procurement decisions are viewed following a cyber-security incident. Device selection criteria, vendor representations, security certifications, internal reviews, risk sign-offs and lifecycle management policies are increasingly subject to scrutiny from regulators, insurers, auditors and boards. The whitepaper finds the absence of documented security assurance could become a central consideration in determining whether an organisation exercised reasonable care.

The emergence of the US Cyber Trust Mark is also helping elevate cyber security beyond an IT responsibility and into the realm of board-level governance. Organisations that cannot demonstrate appropriate security assurance for their connected infrastructure may face avoidable governance, operational and legal risk.

The whitepaper recommends manufacturers begin evaluating product portfolios, certification readiness, testing requirements and documentation; enterprises incorporate Cyber Trust Mark considerations into procurement, vendor due diligence and cyber-security risk assessments; and retailers prepare for cyber-security assurance to play a greater role in product differentiation and consumer trust.

These findings are from ABI Research’s “Y27: The governance reckoning for IoT security” whitepaper, which can be downloaded at go.abiresearch.com/whitepaper-y27-the-governance-reckoning-for-iot-security.