CYBERSECURITY OF IoT DEVICES IN THE INTERNAL NETWORKS OF MILITARY UNITS AND ORGANIZATIONS
DOI:
https://doi.org/10.31435/ijitss.3(51).2026.6692Keywords:
Internet of Things, IoT Device, Military Internal Network, Cybersecurity, Attack Surface, Zero Trust, Microsegmentation, Residual RiskAbstract
The digital transformation of the defense sector has expanded the use of Internet of Things devices in the internal networks of military units and organizations. These devices include IP cameras, access-control systems, biometric equipment, smart displays, multifunction printers, conferencing systems, building-management systems, environmental sensors, and smart meters. They improve operational efficiency, monitoring, and automation, but they also enlarge the cyberattack surface because of weak credentials, outdated software, vendor-managed cloud services, automatic device-discovery protocols, limited logging, and long service lifecycles. In a military organization, the consequences extend beyond the loss of information confidentiality. A compromised device may disclose the location and layout of facilities, security routines, personnel movements, and logistics patterns; provide a foothold for lateral movement within the internal network; and ultimately disrupt mission continuity.
This study identifies the principal attack surfaces, threats, and vulnerabilities associated with IoT devices in military internal networks and develops a mission-oriented risk-assessment method and a security model based on zero-trust principles. The research comparatively examines Mongolian cybersecurity legislation and authoritative sources, including NIST CSF 2.0, NISTIR 8259A, NIST SP 800-213, NIST SP 800-207, NIST SP 800-82 Rev. 3, ETSI EN 303 645, and MITRE ATT&CK. The findings show that military IoT risk is not confined to technical vulnerabilities at the device level. It also arises from incomplete asset inventories, flat network architectures, uncontrolled vendor remote access, cloud dependency, and weak lifecycle governance. The study proposes a five-zone network architecture, evidence-based risk assessment, and integrated security measures covering the entire lifecycle from procurement to disposal.
References
Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., & Zhou, Y. (2017). Understanding the mirai botnet. 26th USENIX Security Symposium, 1093-1110. https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-antonakakis.pdf.
Cybersecurity and Infrastructure Security Agency, & National Security Agency. (2023). NSA and CISA red and blue teams share top ten cybersecurity misconfigurations. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a
Department of Defense Chief Information Officer. (2022). Department of Defense zero trust strategy. https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf
European Telecommunications Standards Institute. (2024). ETSI EN 303 645 V3.1.3: Cyber security for consumer Internet of Things: Baseline requirements. https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf
Fagan, M., Megas, K. N., Scarfone, K., & Smith, M. (2020). IoT device cybersecurity capability core baseline (NISTIR 8259A). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8259A
Fagan, M., Marron, J., Brady, K. G., Jr., Cuthill, B. B., Megas, K. N., & Herold, R. (2021). IoT device cybersecurity guidance for the federal government: Establishing IoT device cybersecurity requirements (NIST SP 800-213). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-213
Internet Engineering Task Force. (2013). Multicast DNS (RFC 6762). RFC Editor. https://doi.org/10.17487/RFC6762
Internet Engineering Task Force. (2014). The constrained application protocol CoAP (RFC 7252). RFC Editor. https://doi.org/10.17487/RFC7252
MITRE. (2026). MITRE ATT&CK knowledge base. https://attack.mitre.org/
State Great Khural of Mongolia. (2016). Law on State and Official Secrets [In Mongolian]. https://legalinfo.mn/mn/detail/12408
State Great Khural of Mongolia. (2021a). Law on Cybersecurity [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16390365491061
State Great Khural of Mongolia. (2021b). Law on the Protection of Personal Information [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16390288615991
Government of Mongolia. (2022). National Cybersecurity Strategy, Government Resolution No. 493 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16532522791411
Government of Mongolia. (2023). General Procedure for Ensuring Cybersecurity, Government Resolution No. 224 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=16759862495731
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework 2.0. https://doi.org/10.6028/NIST.CSWP.29
OASIS Open. (2019). MQTT version 5.0. https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html
ONVIF. (2020). ONVIF core specification. https://www.onvif.org/specs/core/ONVIF-Core-Specification-v2006.pdf
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Stouffer, K., Pease, M., Tang, C., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M. (2023). Guide to operational technology security (NIST SP 800-82 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-82r3
Minister of Digital Development, Innovation and Communications, & Director General of the General Intelligence Agency. (2024). Procedure and methodology for cybersecurity risk assessment, Joint Orders Nos. A/30 and A/148 [In Mongolian]. https://legalinfo.mn/mn/detail?lawId=17141973551921
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Unenbat Erdenesuvd, Nergui Bayartogtokh, Batbayar Densmaa

This work is licensed under a Creative Commons Attribution 4.0 International License.
All articles are published in open-access and licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0). Hence, authors retain copyright to the content of the articles.
CC BY 4.0 License allows content to be copied, adapted, displayed, distributed, re-published or otherwise re-used for any purpose including for adaptation and commercial use provided the content is attributed.

