The smart devices putting SMBs at risk

In 2026, an office is a web of connected devices. The office aquarium. The smart thermostat in the corner. The IP camera above the reception desk. The networked printer down the hall.

Most people do not view these devices as cybersecurity risks. According to security professionals, that is exactly what makes them dangerous. IoT sprawl in small offices has become one of the most overlooked security challenges facing SMBs.

IoT malware attacks increased 124 percent heading into 2026, with threat actors launching an average of 820,000 malicious IoT attack attempts every day, a 46 percent year-over-year increase.

These devices often join business networks, get forgotten, and remain unpatched while other security controls receive attention. For MSPs, they represent both a security challenge and an opportunity to expand client services.

Why IoT devices attract attackers

Roman Marszalek, CEO of Dr Logic, a London-based Apple-focused MSP, often uses smart thermostats as an example when talking to clients. He explains that attackers are not interested in controlling the thermostat itself. They target it because it is often one of the least-patched and least-monitored devices on the network. Once inside, they may be only one step away from a file server or administrator laptop.

Marszalek says this is where many businesses misunderstand the risk. MFA and antivirus protect accounts and endpoints, but they do little to determine whether a connected device can be trusted. Printers, cameras, and other IoT devices often lack those defenses entirely. He recently worked on a network segmentation project where printers, a building access system, and various IoT devices shared a VLAN with employee laptops and a database server. According to Marszalek, that setup is common when networks grow over time without regular review.

Omair Manzoor, founder and CEO of ioSENTRIX, a CREST-accredited offensive security firm, sees the issue regularly during penetration tests.

Some of the easiest network compromises his team has achieved began with unmanaged IoT devices connected to flat networks. Connected printers and IP cameras are common entry points because they often ship with default credentials, run outdated firmware, and advertise themselves through protocols such as UPnP and mDNS.

Once compromised, these devices can serve as launch points for broader attacks. Manzoor says an attacker who gains control of an unpatched smart thermostat can spoof traffic, capture credentials, and move laterally to file servers, POS systems, or domain controllers. The thermostat is not the target. It is the path to more valuable systems.

The printer security blind spot

Shankar Somasundaram, CEO of Asimily, an IoT and medical device security firm, points to connected printers as one of the most underestimated risks in small offices.

Many printers store scan-to-email and scan-to-folder credentials, along with copies of documents that pass through them. Because these devices are rarely monitored closely, attackers who gain access can collect credentials and use them to reach more critical systems. The problem is difficult to detect because endpoint security tools generally cannot be installed on printers and many other IoT devices. As a result, attackers can remain hidden for extended periods.

Corey Ercanbrack, CTO of Vasion, sees the same challenge from a print management perspective. He says print infrastructure is often treated separately from the broader security environment, despite being connected to the same business systems and introducing many of the same risks.

Research from Vasion found that 92 percent of U.S. CIOs and senior technology leaders experience print or document workflow failures an average of three times per week, highlighting how much business activity depends on infrastructure that receives little security scrutiny. Ercanbrack recommends starting with visibility. MSPs should know which printers are on a client’s network, who manages them, what firmware they run, and which systems they can communicate with.

Discovery before segmentation

The path to securing IoT devices starts with visibility and segmentation.

Marszalek recommends beginning with a complete inventory of connected devices. Organizations cannot segment devices they have not identified. Once every device is accounted for, IoT and building systems should be separated from business-critical assets using VLANs and default-deny firewall policies.

According to Marszalek, attackers often assume everything becomes reachable once they get past the perimeter. Segmentation breaks that assumption.

Somasundaram cautions against aggressive active scans, which can disrupt older IoT devices. Instead, he recommends passive monitoring. By observing the traffic devices already generate, MSPs can identify devices and understand how they communicate without interacting with them directly.

Once device behavior is understood, segmentation becomes much easier. Somasundaram recommends placing IoT devices on dedicated network segments and allowing them to communicate only with the destinations they require. For example, a thermostat may need access to its vendor’s cloud platform, but it has no reason to communicate with a file server.

Manzoor says SMBs do not need enterprise-level complexity to improve security. A properly configured VLAN strategy that separates IoT devices from business-critical systems can eliminate much of the lateral movement risk. The bigger issue, he says, is that many SMBs never implement segmentation because no one advises them to do so.

A simple checklist for MSPs

Manzoor recommends three core actions:

  • Inventory all network-connected devices at least quarterly.
  • Place IoT devices on a dedicated VLAN with no access to business-critical systems unless explicitly required.
  • Include IoT devices in the patch management lifecycle.

As he notes, connected devices do not update themselves. In many cases, firmware updates released years earlier may already address vulnerabilities attackers are targeting today.

For clients who dismiss smart devices as harmless, Marszalek offers a simple reminder: attackers are not interested in controlling the thermostat. They are interested in what the thermostat can reach.

Photo: Pressmaster/ Shutterstock

This post originally appeared on Smarter MSP.