Subscribe to newsletter
Industrial IoT security on 4G and 5G depends more on network design than on passwords. Keep devices off the public internet, reach them only through VPN tunnels, and connect them with IoT SIMs on a private APN.
Most online security advice focuses on passwords, cloud APIs or consumer IoT devices. In industrial deployments that use 4G and 5G routers and IoT SIMs, the biggest risks sit at the network layer, not the application layer.
This guide explains how to secure industrial cellular routers, IoT SIMs and the remote assets that rely on them, such as CCTV, building management systems (BMS), EV chargers, energy systems, kiosks and control equipment.
The Core Principle: Do Not Expose Devices to the Internet
The core principle of industrial IoT security is that devices should never be directly reachable from the public internet.
The biggest IoT security mistake is to give a device a public IP address and expose its services directly to the internet. Once anyone can reach a device, every other control is limiting harm rather than preventing it.
Industrial IoT deployments are most secure when devices are:
- Not publicly addressable
- Reachable only through controlled tunnels
- Isolated from the wider internet by design
How to Secure a 4G or 5G IoT Deployment
Millbeck recommends eight steps to secure a 4G or 5G IoT deployment, starting with the IoT SIM and ending with firmware and device lifecycles.
- Use Private APNs and SIM-Level SecurityPrivate APN, closed user groups and controlled routing
- Avoid Public IP SIMs Wherever PossibleUse a private IP SIM with VPN access in most deployments
- Use VPN-Only Remote AccessOutbound from the router, with no open inbound ports
- Harden the Gateway ConfigurationChange default passwords and disable WAN-side management
- Segment Networks and DevicesSeparate OT, CCTV and management traffic with VLANs
- Encrypt All Data in TransitVPN tunnels, TLS for telemetry and encrypted management
- Monitor Connectivity and BehaviourData usage, VPN status, uptime and unexpected traffic
- Manage Firmware and Device LifecyclesUpdate firmware, remove legacy protocols and replace unsupported hardware
1. Use Private APNs and SIM-Level Security
The IoT SIM is the first security layer in a cellular deployment, because it controls traffic before that traffic reaches the router firewall. IoT SIMs are not the same as consumer mobile SIMs.
An APN (Access Point Name) is the gateway a cellular device uses to reach a data network. A private APN is an APN dedicated to one customer, which routes SIM traffic to that customer's systems instead of the public internet. A closed user group limits a set of SIMs to communicating with each other and with approved destinations.
A well-designed IoT SIM service uses:
- Private APN connectivity
- Closed user groups
- Network-level isolation between customers
- Controlled routing to back-end systems
With these controls in place, devices:
- Cannot be reached from the public internet
- Can only communicate with approved destinations
- Are protected before traffic reaches the router firewall
2. Avoid Public IP SIMs Wherever Possible
Most IoT deployments should not use public IP SIMs, because a public IP makes the device reachable from the internet. A public IP SIM gives a device an internet address that anyone can reach. A private IP SIM gives it an address that is not routable on the public internet.
Public IP SIMs are widely sold but often misunderstood. They are sometimes necessary, but in most deployments they:
- Increase the attack surface
- Need constant firewall hardening
- Expose management interfaces if misconfigured
- Create long-term security and compliance risk
In most cases, a private IP SIM with VPN access is more secure and easier to scale.
If a deployment needs a public IP, the connection must be:
- Locked down with strict firewall rules
- Never combined with open port forwarding
- Monitored continuously
3. Use VPN-Only Remote Access
Remote access to an industrial router should always run outbound from the device through a VPN, never inbound from the internet. A VPN (Virtual Private Network) is an encrypted tunnel between two endpoints across an untrusted network.
Set up remote access so that there is:
- A VPN initiated from the router to a secure server
- No WAN-side management access
- No exposed web interfaces
- No open inbound ports
Industrial deployments commonly use IPsec, OpenVPN or WireGuard for the VPN tunnel.
The principle
If the VPN is down, the device is unreachable. That is the intended result, not a fault.
4. Harden the Gateway Configuration
Hardening a gateway means switching off everything the deployment does not need. Industrial routers ship with many features enabled to suit different uses, and not all of them should be active.
The minimum hardening steps are:
- Change default usernames and passwords
- Disable WAN-side management access
- Disable unused services and protocols
- Restrict management access to the LAN or VPN
- Apply strict firewall policies
Treat routers as infrastructure equipment, not consumer devices.
5. Segment Networks and Devices
Network segmentation separates devices and traffic types, so a compromised device has limited reach into the rest of the network. Never put everything on a single flat network.
Typical segmentation includes:
- LAN and WAN separation
- Operational technology (OT) devices isolated from IT systems
- CCTV isolated from corporate networks
- Management traffic separated from data traffic
VLANs (virtual LANs) and firewall zones give you:
- Less lateral movement if a device is compromised
- Safer multi-device deployments
- Easier compliance with security standards
6. Encrypt All Data in Transit
Every industrial IoT deployment should encrypt all data in transit, without exception.
Make sure that:
- VPN tunnels use current encryption
- Telemetry travels over TLS (Transport Layer Security)
- Management traffic is encrypted
- Legacy unencrypted protocols are not used
Encryption protects:
- Data confidentiality
- Credentials
- Control traffic
- The integrity of commands sent to devices
7. Monitor Connectivity and Behaviour
Monitoring gives you visibility of what devices are doing, and that matters as much as prevention.
Monitoring should cover:
- SIM data usage patterns
- VPN connection status
- Device uptime and connectivity
- Unexpected traffic
- Repeated reconnections or authentication failures
Abnormal behaviour often points to:
- Misconfiguration
- Failing hardware
- Network issues
- Security incidents
8. Manage Firmware and Device Lifecycles
Unpatched devices are vulnerable devices, so firmware and hardware need managing for the whole life of a deployment.
Lifecycle management includes:
- Keeping router firmware up to date
- Updating cellular modem firmware when required
- Removing legacy protocols
- Planning for the 2G and 3G network switch-off
- Replacing unsupported hardware
Security is an ongoing process, not a one-off set-up.
What Keeps Industrial IoT Secure?
Industrial IoT security rests on network design, not on passwords.
Secure industrial IoT deployments rely on:
- Network isolation
- Private SIM connectivity
- VPN-based access
- Strong firewall policies
- Controlled remote management
- Continuous monitoring
Passwords and multi-factor authentication (MFA) help, but they are secondary controls, not the foundation.
How Does Millbeck Approach IoT Security?
Millbeck builds security into the connectivity design from the start, rather than adding it afterwards.
Millbeck designs IoT connectivity around:
- Private and roaming IoT SIMs
- VPN-based remote access
- Industrial 4G and 5G routers
- Security designs that work in real deployments
If you are unsure whether your current deployment follows these principles, we are happy to review it.
Need Help Securing a Deployment?
Millbeck can help if you are deploying or managing:
- Industrial 4G or 5G routers
- CCTV or BMS over cellular
- EV charging infrastructure
- Remote monitoring or control systems
We can help you design a secure IoT connectivity architecture that scales and avoids common mistakes.
Speak to us about your deployment
Millbeck. IoT Connectivity




.avif)