Cybersecurity

Hundreds of thousands of (forgotten) IoT and OT devices are exposed to the internet

The “set and forget” approach — where you buy a device, set it up, and then forget all about it — could have serious consequences, including risks to human life. A new research result from DTU Compute shows that thousands of IT systems worldwide can easily be exposed to cyber-attacks. Review the IT systems of all connected devices and only connect them to the internet if it is necessary, the researchers advise.

Smart City with IoT and OT systems. Graphics: Copilot
Smart City with IoT and OT systems. Graphics: Copilot

Advice

How should you react according to the new knowledge about exposed OT and IoT systems? The advice builds up depending on whether you are an organisation or an individual.

For individuals:

  • Change default configurations and credentials
  • Disable unnecessary internet connections
  • Be aware that many devices communicate online even if it is not obvious

And for organisations:

  • Use VPNs for remote access
  • Implement secure authentication and access control (e.g., bearer token authentication with role-based access control), limiting access to only what is required
  • Enable encryption (e.g., DTLS) and rotate certificates before they expire
  • Monitor exposed systems continuously
  • Use Cyber Threat Intelligence (CTI) services to identify ongoing threats
Source: DTU

Relatively small numbers in Denmark, but…

The research showed a big difference between IoT and OT. IoT devices tend to go online and offline frequently and are harder to track over time. OT devices, however, are designed to remain online almost constantly — close to 100% uptime.

In the study, about 50% of vulnerable OT devices remained unchanged from one year to the next, which suggests they may be abandoned. For IoT devices, the number was closer to 20%.

The United States shows the largest exposure, partly because of its size and differences in regulation and behaviour.

“In Denmark, the number of findings is relatively small, which is good. Most of what we found were building automation systems, such as heating systems – often in hotels. But even one vulnerable OT system can be critical — for example, a railway system.”

In contact with relevant organisations

Naturally, a significant responsibility rests on researchers when they possess such important knowledge.

During the work, they have collected insights and feedback from both researchers and industry, and the results have been published in conferences and journals.

The DTU researchers also work with CERT organisations, such as DKCERT; expert teams that monitor cyber threats and help organisations respond to and mitigate cyber-attacks. Additionally, they conduct ethical disclosure campaigns, where they inform organisations about vulnerabilities and suggest ways to mitigate them.

“In cybersecurity, we use threat models, but in simple terms: if a system is accessible from the internet without authentication or access control, it is a risk. The key message is that many devices remain connected to the internet while staying vulnerable over long periods,” says Ricardo Yaben.

He and Emmanouil Vasilomanolakis have been working on this line of research for a couple of years now. The new paper, for example, is an extension of their previous work that received best paper awards.

Facts

  • Paper: Digital ghost ships: abandoned, neglected, and obsolete IoT & OT devices exposed to the Internet
  • Authors: Ricardo Yaben and Emmanouil Vasilomanolakis, Technical University of Denmark
  • The paper has been accepted for publication in IEEE Transactions on Network and Service Management: DOI 10.1109/TNSM.2026.3699092
  • The research focuses on identifying Digital Ghost Ships (DGSs) using common scanning tools to find indicators of security misconfigurations and misuse.
  • Moreover, Ricardo Yaben and Emmanouil Vasilomanolakis compared two Internet-wide scans conducted one year apart, focusing on security issues in eight IoT and OT protocols: MQTT, CoAP, XMPP, Modbus, OPC UA, RTPS, DNP3, and BACnet.
  • During the first scan (S1) they found 675,896 DGSs, and 75,007 during their second scan (S2).
  • Lastly, they examined the IP reputation of the vulnerable devices and found that 7,424 (S1) and 792 (S2) DGSs were reported at least once.