Skip to main content ITCSAU - Advising Sovereignty in a Digital Age
Cybersecurity | Enterprise | 6 MIN READ

The cheap device in the expensive system

New smart-device security rules cover some products sold from now on. The cameras and controllers already on company networks may have no owner until the board insists on one.

By Marc Mendis •

In Brief

Contractors install controllers, cameras and sensors that no executive owns. Many run software the maker no longer supports, and some connect only through their own mobile links, where no scan of the company's network will find them. Australia's smart-device security rules, in force since 4 March 2026, are unlikely to reach most of this equipment. Boards should name one owner for every connected device, count devices from contracts and site surveys, and write a support end date into every contract.

The devices nobody knew were on site

Somewhere in the company’s buildings there may be a controller a contractor installed years ago. It runs the chillers, the lifts or the car park gates. It may report back to its maintainer over its own mobile connection, and it may appear on no list the company keeps.

If it connects only through that mobile link, it will not appear in a scan of the company’s network. Contract records, a physical inspection and a radio survey, a sweep of the site for devices transmitting on mobile or wireless networks, can help find it. The connection may bypass the company’s network monitoring and controls.

Across property and industrial reviews, we keep finding the same pattern. Contractors installed the controllers, cameras and sensors. No executive owns them. Many run firmware the maker no longer supports. Firmware is the software built into a device; once support ends, the maker stops fixing the security flaws found in it.

Some of those devices share a network with staff computers, with no barrier between a camera and a finance system. Cameras and door-access readers record personal information, which brings duties under the Privacy Act. Often nobody can show those duties are being met.

The law has moved, though not far enough to reach that controller. Mandatory security rules for smart devices took effect on 4 March 2026 under the Cyber Security Act 2024.

On covered products, they ban manufacturer-set passwords shared across devices, with a narrow exception for the factory default state. They require makers to say how flaws can be reported, and to publish when security fixes will end.

Those rules apply to consumer-grade products made from that date, whoever buys them. The rules cover products a consumer could reasonably buy for the home, and many building controllers are unlikely to qualify. Products made before that date are outside the rules, so a controller installed in 2019 is not covered. Nor do the rules make any owner manage the devices it already runs.

The cheap device, which a facilities line item or fit-out contractor bought a decade ago, remains the expensive problem the new law does not reach.

$97,166

average loss per cybercrime report from a medium business in 2024–25, up by more than half on $62,870 a year earlier. The figures cover all cybercrime, not device attacks alone.

Australian Signals Directorate, Annual Cyber Threat Reports 2024–25 (14 October 2025) and 2023–24

So the board’s question is not whether the new rules apply. It is who owns what is already on the network.

The support date is the lever a board can use today

Of the three requirements, the support period deserves a director’s attention. The maker of a covered product must publish the date its security fixes end, and cannot bring that date forward once published. The law sets no minimum length. A contract can.

The rules make that date public only for covered consumer-grade products. A purchasing contract can demand the same date from every supplier, including the maker of a building controller the rules do not cover.

That turns a hidden risk, security end-of-life that can arrive years before physical end-of-life, into a contractual specification a board can mandate today.

The support end date sets the exposure windowThe support end date sets the exposure windowIllustrative: the same device, bought two waysReceives security fixesOn the network, no fixesRetired or isolatedBought with no support date in the contractExposure window: length unknown at purchaseBought with a support end date required and a retirement date setSupport period set in the contractReplaced04812Years in service (illustrative)Illustrative only, not measured averages. Support periods vary by product and maker.Covered products must publish a support end date; the law sets no minimum length.
What the law says

The law. Cyber Security (Security Standards for Smart Devices) Rules 2025, made under the Cyber Security Act 2024.

Commencement. 4 March 2026, for in-scope products manufactured on or after that date. Products made earlier do not have to comply.

What is covered. Internet- or network-connectable products that a consumer could reasonably be expected to acquire in Australia. Some, such as smartphones and laptops, are exempt.

Who is bound. Manufacturers must meet the product and disclosure requirements. Suppliers must supply only compliant products, with a statement of compliance. An importer’s duties depend on the role it plays.

The three requirements. Passwords, where used, must be unique to each device or set by the user. A manufacturer-set password shared across devices is allowed only in the factory default state of the hardware and pre-installed software, not in separately installed software the product needs. The manufacturer must publish how to report security issues and when it will acknowledge a report and give status updates. It must publish a support period with an end date, which can be extended but not shortened; no minimum length is set.

Out of scope. Products made before 4 March 2026. The rules impose no programme for managing devices already installed.

Critical infrastructure. Under the Security of Critical Infrastructure Act 2018, responsible entities for the asset classes the risk management rules specify must keep a risk management programme. Enhanced rules from 10 June 2026 expressly address unsupported components, patching failures and legacy systems, with transition periods running to June 2027 and June 2028.

Financial services. CPS 234, the information security standard of the prudential regulator APRA, applies to specified APRA-regulated entities and extends to information assets that third parties manage for them.

Privacy. Entities covered by the Privacy Act 1988 must take reasonable steps to protect personal information they hold, including through technical and organisational measures (APP 11, as amended from 11 December 2024).

A compliant device is only as safe as the way it is run. The rules govern what the maker must do. They do not require the owner to know the device exists, keep it apart from business systems, install its fixes or remove it when support ends.

A published fix is no guarantee of an installed one. A peer-reviewed 2023 study by Frank Ebbers examined 1.06 million smart devices reachable from the internet. Only 2.45 per cent, about one in 40, ran their maker’s latest firmware. The study did not look at Australian companies.

Several duties many boards already carry cannot be met without a device list: critical infrastructure risk programmes, APRA’s information security standard and the Privacy Act among them. For the entities they cover, the critical infrastructure rules have named unsupported components and legacy systems directly since 10 June 2026.

Every one of those duties starts with a list. A list starts with an owner.

Name the owner, then count from the contracts

Order matters. Ownership precedes inventory; inventory precedes segmentation; segmentation precedes a credible patching and retirement policy. Segmentation means dividing the network so that a compromised camera cannot reach the systems that run the business.

Name one owner. The CEO should name one executive accountable for every connected device on the company’s premises, including those bought by facilities, security and project teams. One named owner makes it clear who answers for each step below.

Count from the contracts, then check the site. Management should ask facilities, security and project teams to list every kind of networked device they have specified, installed or accepted from a contractor. An automated scan then shows what is connected to the company’s network. At critical sites, a physical inspection and a radio survey can help identify what a scan cannot: equipment connected only by its own mobile link. The gaps between those lists may reveal equipment nobody knew about.

Put a support end date in every contract. Every tender, fit-out contract and managed-service agreement should require each device’s support end date, a contact for reporting security flaws, and a register of what was installed. That applies whether or not the law covers the product. No contractor should connect equipment without the owner’s approval.

Isolate or retire what is past its date. The board should approve a policy for devices that no longer receive security fixes. Each should be replaced, moved to a separate part of the network, or kept by written decision with a named owner and a review date.

None of this is free. Replacing devices that still work, and separating the rest from business systems, takes budget and disrupts buildings. The alternative is to keep a way into the network that no executive answers for.

Recommended board actions (not legal requirements)

Action Owner Timeline Priority
Name one executive accountable for every connected device, including those installed by facilities teams and contractors CEO Before the next board meeting critical
Build a first inventory from procurement and contractor records, check it against a network scan and, at critical sites, a physical and radio survey; list the gaps Accountable executive, with the CIO and head of facilities Within 90 days critical
Require a support end date, a security reporting contact, an installed-device register and approval before connection in every new specification and contract Chief procurement officer, with general counsel Within 120 days high
Approve a policy to replace, isolate or formally accept every device past its support end date Audit and risk committee, on the accountable executive's proposal Within six months high
Report the second inventory: coverage, owners, and unsupported devices isolated or retired Accountable executive, to the audit and risk committee 90 days after the first report high

The board should expect the first answer to come back incomplete, and require the second 90 days later. That report should show how many devices have been counted, how many have an owner, and how many past their support date have been isolated or retired.

The first decision is the CEO’s: name the owner before the next board meeting.

The number to ask management for this quarter: how many devices on our network no longer receive security fixes?

Updated September 2026: figures refreshed and the argument sharpened since first publication on 21 May 2026.

Questions for Leadership

Which executive is accountable for every connected device on our premises, including those installed by contractors?

Split ownership can leave patching and retirement with no one answerable to the board.

How did management establish that the device inventory is complete, including equipment with its own mobile connection?

A device connected only by its own 4G link will not appear on a scan of the company's network.

Which of our cameras and door-access readers record personal information, and can management show how it is protected?

The duty to protect personal information applies whichever team bought the camera.

Does every purchase that connects to our network now require a published support end date, including fit-out and building contracts?

It is the one security term the board can require of every supplier at the next tender.

What would it cost to replace or isolate every device past its support date, and what does waiting cost?

A costed plan turns a standing risk into a budget decision the board can make.

The Bottom Line

Treat the installed base of connected devices as a governance gap the smart-device rules do not close. Name one executive owner, require an inventory built from procurement records and network discovery, and make a support end date a condition of every purchase.

Frequently Asked Questions

Does a consumer-grade device bought by a business fall under the rules?

It can. The rules apply to classes of product, not to individual purchases. If a consumer could reasonably be expected to buy a product for personal, domestic or household use, every unit must comply unless the product class is expressly exempt, as smartphones and laptops are. That includes units a business buys for an office or a building, provided they were manufactured on or after 4 March 2026. Apart from those exemptions, a product falls outside the rules only if a consumer could not reasonably be expected to acquire it that way. The Department of Home Affairs publishes frequently asked questions on scope, and legal advice is the safe course for a specific product.

What should management do with a device that cannot be updated?

Make it a recorded decision. There are three honest options. Replace it, ideally with a product whose support end date is published and far enough away to cover its expected service life. Isolate it on a separate part of the network, so it can reach only the systems it needs and nothing that holds financial or personal data. Or accept the risk in writing, with a named owner, a reason and a review date. The one outcome the board should not accept is the option nobody chose: a device left in place because no one decided.

What if a contractor cannot or will not say what it installed?

Treat the gap as a finding in itself, and do not let the inventory wait for the contractor. An automated network scan can find what is connected to the company's network, a site walk-through can confirm what each device is, and a radio survey can help identify equipment using its own mobile connection. For existing contracts, check what rights the company already holds to handover records, and use them. For renewals and new work, make a device register, with models, locations, software versions and support end dates, a condition of handover and final payment. A contractor that still cannot disclose is telling the board something about the risk it carries.

Does the Essential Eight apply to building systems?

Not directly. The Essential Eight is the Australian Signals Directorate's set of eight baseline strategies against cyber attacks, designed for internet-connected IT networks rather than building or industrial control systems. Whether a company must meet it depends on the policy, regulation or contract that applies to it. Its logic still helps here: at maturity levels one to three it expects an automated method of discovering assets at least fortnightly. ASD consulted from 15 June to 12 July 2026 on how the Essential Eight should evolve, including proposed Essentials for enterprise IT. It has not been replaced.

Should IT or facilities own connected devices?

Either can. The authority that comes with the role matters more than the team it sits in. Facilities teams know the buildings, the contractors and the replacement cycles; IT teams know networks, patching and monitoring. The owner needs a say over what gets bought and on what terms, a budget for replacement, and the power to stop a contractor connecting equipment without approval. One workable arrangement is a chief operating officer as owner, with the chief information officer setting the technical standard and facilities running the devices day to day. Whatever the split, one executive answers to the board.

Engage the Advisors

If your organisation is approaching a significant strategic decision, or questioning the value of current investments, we should talk. Strategic counsel at the right moment can redirect significant capital toward genuine business value.

ENGAGE THE ADVISORS