Critically examine how massive IoT density and private 5G networks expand the cybersecurity threat landscape. What measures should CERT-In adopt to protect this critical infrastructure?
Massive IoT deployment and private 5G networks shift cyber risk from isolated device faults to large-scale, real-time disruption. Their scale, low cost and linkage to physical processes make them attractive targets for criminals, hacktivists and state-backed actors.

Expanded threat landscape
- Huge attack surface: Billions of remotely reachable devices create countless entry points.
- Weak device security: Default passwords, poor encryption, insecure updates and limited hardware protections leave many IoT devices exposed.
- Botnets and DDoS: Compromised devices can be weaponised to disrupt banks, utilities and public services.
- Cyber-physical impact: Private 5G connects sensors, machines and control systems, so breaches can alter operations, not just steal data.
- Virtualisation risks: Cloud-native cores, software-defined functions and slicing increase misconfiguration, slice escape and lateral movement risks.
- Supply-chain exposure: Multi-vendor ecosystems, imported modules and opaque code hide malicious insertions and flaws.
CERT-In measures
- Issue sector-specific, real-time threat intelligence and attack signatures for telecom, manufacturing, health and smart-city networks.
- Enforce rapid incident reporting, secure log retention and continuous anomaly detection in critical infrastructure.
- Mandate security-by-design: secure boot, unique credentials, encrypted traffic, signed updates, rollback protection and MFA.
- Require SBOM/HBOM disclosure, vendor audits and certification of critical devices and network functions.
- Promote micro-segmentation, zero-trust access and strict isolation between slices and operational technology.
- Run joint drills, red-team testing and training with telcos, device makers and operators.
Thus, CERT-In should shift from reactive response to anticipatory defence through enforceable standards, real-time intelligence and public-private coordination.
Originally written on
September 13, 2026
and last modified on
September 13, 2026.