Everyone's chasing the 'zero trust for IoT' hype. Banyan's appliance model and NetFoundry's cloud-native ZTNA both claim to solve it.
But what if the real lock-in is assuming you need their platform at all? Banyan wants you on their hardware. NetFoundry wants you in their cloud fabric. Both create a nice, tidy bill.
For a bunch of headless sensors, is the overhead worth it? Or are we just securing the management tunnel while the device firmware itself is a 2019 CVE waiting to happen? Open source tools can handle the network part. The real cost is auditing what's actually running on the endpoints—something neither vendor touches.
Doubt everything
You're right about the core problem being endpoint hygiene. Too many companies think buying a ZTNA platform checks the "IoT security" box. They'll spend six figures on a fancy tunnel while the devices inside it are running decade-old kernels with default credentials.
I've seen it in audits. The network perimeter is Fort Knox, but the actual device images are untouchable black boxes from the OEM. Vendors love this because it makes their solution sticky. You can't leave their platform without a full device firmware refresh, and that's a multi-year project no one budgets for.
Focus on getting control of your bill of materials first. If you don't own the software stack, you're just renting a safer room for your ticking time bombs.
That point about vendor lock-in is really eye-opening. I hadn't thought about it that way, but you're completely right. If you don't own the software stack, you're just stuck paying for the room.
It makes me wonder, how do you even start to audit a bill of materials for something like an industrial sensor from an OEM? Is there a realistic first step for a team that's already bought the hardware but wants to get some control back, or is it just a total reset from scratch?
That's such a good question. I've been wondering the same thing.
I'm in a similar spot with some environmental monitors we bought. The first step I'm being told to take isn't about the firmware itself, but the contract. Our legal team is trying to push for a software bill of materials (SBOM) clause in the purchase orders for any new devices. For the ones we already have, they're asking the OEM for disclosure as part of our support agreement.
It feels super slow and not very technical, but apparently without that paperwork, you can't even start to audit what's on there. It's all about getting permission first, which is kind of frustrating.
Is your team trying to get an SBOM from your vendor, or are you looking at more technical ways to figure it out yourselves?