Critically examine how massive IoT density and private 5G networks expand the cybersecurity threat landscape. What measures should CERT-In adopt to protect this critical infrastructure?

Massive IoT deployment and private 5G networks shift cyber risk from isolated device faults to large-scale, real-time disruption. Their scale, low cost and linkage to physical processes make them attractive targets for criminals, hacktivists and state-backed actors.

Expanded threat landscape

  • Huge attack surface: Billions of remotely reachable devices create countless entry points.
  • Weak device security: Default passwords, poor encryption, insecure updates and limited hardware protections leave many IoT devices exposed.
  • Botnets and DDoS: Compromised devices can be weaponised to disrupt banks, utilities and public services.
  • Cyber-physical impact: Private 5G connects sensors, machines and control systems, so breaches can alter operations, not just steal data.
  • Virtualisation risks: Cloud-native cores, software-defined functions and slicing increase misconfiguration, slice escape and lateral movement risks.
  • Supply-chain exposure: Multi-vendor ecosystems, imported modules and opaque code hide malicious insertions and flaws.

CERT-In measures

  • Issue sector-specific, real-time threat intelligence and attack signatures for telecom, manufacturing, health and smart-city networks.
  • Enforce rapid incident reporting, secure log retention and continuous anomaly detection in critical infrastructure.
  • Mandate security-by-design: secure boot, unique credentials, encrypted traffic, signed updates, rollback protection and MFA.
  • Require SBOM/HBOM disclosure, vendor audits and certification of critical devices and network functions.
  • Promote micro-segmentation, zero-trust access and strict isolation between slices and operational technology.
  • Run joint drills, red-team testing and training with telcos, device makers and operators.

Thus, CERT-In should shift from reactive response to anticipatory defence through enforceable standards, real-time intelligence and public-private coordination.

Originally written on September 13, 2026 and last modified on September 13, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *