IoT SIM Security Built for Infrastructure Operators
IoT SIM security is the set of network and SIM controls that stop connected devices being reached, misused or intercepted over the mobile network. It is built in layers. A private APN keeps devices off the public internet, fixed private IP addresses give your team a controlled route in, VPN tunnels encrypt the traffic, and SIM-level controls and central management close off misuse across the SIM estate.
A device with a public IP address can be reached by anyone on the internet. Search engines index internet-facing devices by the services they expose, and botnets try known passwords on any login they find. The Mirai botnet, for example, took control of large numbers of IoT devices by logging in with default usernames and passwords. For operational technology and critical infrastructure, an exposed device is a risk to the service itself.
The controls below apply to all Millbeck IoT SIMs, whether UK roaming, global roaming or eSIM.
| Control | What It Does | Risk It Reduces |
| Private APN | Sends device traffic over an isolated path to your network, not the public internet | Internet scanning and opportunistic attack |
| Fixed private IP address | Gives a SIM the same private address every time it connects (optional; required for VPN) | Uncontrolled or inconsistent remote access |
| VPN tunnel (IPsec, OpenVPN, WireGuard) | Encrypts traffic between the router and your systems | Interception and tampering in transit |
| IMEI lock | Stops a SIM working in any device other than the one it is assigned to | SIM theft and use in other devices |
| SMS and voice barring | Removes services the device does not need | Rogue SMS commands and premium-rate fraud |
| Central SIM management | Suspends SIMs automatically on thresholds you set | Runaway data use from a faulty or misused device |
Private APN: Take Devices Off the Public Internet
A private APN is usually the first control we recommend, because devices on a private APN without internet breakout cannot be reached from the internet. An APN (Access Point Name) is the setting that tells the mobile network where to send a device's data. A standard APN, or private APN with internet breakout sends traffic out to the public internet. A private APN sends it over a dedicated, isolated path to your own network, and we connect that path to your network over an IPsec link.
Devices on a private APN have no public presence. Internet scanners cannot find them and opportunistic attacks cannot reach them. The exposure shrinks to the path between the SIM and your systems, which you secure with your existing firewall and access controls.
We recommend a private APN for operational technology, critical infrastructure, regulated environments and any deployment where a compromise would disrupt service.
Fixed Private IP Addresses for Controlled Remote Access
A fixed private IP address gives an IoT SIM the same private address every time it connects, so your team can reach each device for diagnostics, configuration and firmware updates without exposing it to the internet. Without a fixed address, a device can receive a different IP address each time it attaches to the network, and consistent remote access breaks.
We offer fixed private IP addresses as an option on our IoT SIMs, and every SIM that runs a VPN over our network needs one. Combined with a private APN, a fixed private IP address gives you a secure, addressable route to every device.
Fixed addresses also make firewall rules precise. Your team can allow named device addresses rather than whole ranges, and audit logs tie each event to one device. Where a deployment needs devices reachable from the internet, we also offer fixed public IP addresses, and will help you weigh the trade-offs at the design stage.
Encrypted Transport With VPN
A VPN (virtual private network) tunnel encrypts traffic between the router on site and your core systems, so intercepted data cannot be read. A private APN and a VPN do different jobs. The private APN controls who can reach the device, and the VPN protects the data as it travels. Most secure deployments use both.
We encrypt traffic at two points. On the network side, we connect the network core to yours over an IPsec link. IPsec is a standard set of protocols that encrypts and authenticates IP traffic. On the device side, our IoT SIMs carry IPsec and OpenVPN tunnels from the router on site to your environment. OpenVPN is an open-source VPN that runs over TLS. Teltonika routers also support WireGuard, a newer VPN protocol with a smaller code base and simpler configuration.
The router builds a device-side tunnel, and the SIM and private APN carry it. Each SIM that runs a VPN needs a fixed private IP address.
With a VPN in place, payment transactions, telemetry, meter readings and control messages stay encrypted on the cellular path and are authenticated before they enter your network. Sectors that handle sensitive data (retail payments, operational technology, healthcare and critical national infrastructure) often have to encrypt data in transit to meet regulatory or contractual obligations.
SIM-Level Security Controls
SIM-level controls restrict what each IoT SIM can do, which closes off common routes to fraud, theft and misuse across the SIM estate.
- IMEI lock: an IMEI (International Mobile Equipment Identity) is the unique number that identifies a device's cellular hardware. IMEI lock stops a SIM working in any device other than the one it is assigned to, so a stolen SIM cannot be used or resold.
- SMS and voice barring: we remove SMS and voice from SIMs that do not need them. Barring closes SMS as a route for rogue commands, removes exposure to premium-rate fraud and simplifies your security documentation.
- SIM authentication: before any data flows, the SIM and the mobile network authenticate each other using a secret key stored on the SIM. The key never leaves the SIM, so it is much harder to copy than a password or software certificate.
We also tell customers when Teltonika publishes a security advisory that affects their devices. For hardening the router itself, see our guide to IoT security for 4G and 5G routers and IoT SIMs.
Central SIM Management and Lifecycle Controls
The SIM management platform lets you control every IoT SIM in the estate, so your team can stop a problem as well as spot it.
- Automatic suspension: thresholds suspend a SIM automatically when its usage passes them, which stops runaway charges from a faulty or misused device before they grow.
- Lifecycle control: SIMs can be activated, suspended, cancelled or reactivated, so a SIM in a decommissioned or stolen device stops working straight away.
- Group policies: IMEI lock and SMS and voice barring to groups of SIMs rather than one at a time, so every SIM in a group gets the same change.
- API access: API lets you build controls into your own systems.
Regulatory and Compliance Context
IoT connectivity security is increasingly a regulatory requirement for UK operators, and four sets of rules are the most likely to apply.
- NIS Regulations 2018: the Network and Information Systems Regulations 2018 apply to operators of essential services in energy, transport, health, drinking water and digital infrastructure, and to some digital service providers. Where connected devices support an essential service, the security of their connectivity forms part of compliance.
- Cyber Security and Resilience Bill: the Cyber Security and Resilience (Network and Information Systems) Bill would extend the NIS Regulations to data centres, managed service providers, large load controllers and critical suppliers. Large load controllers are organisations that can control the energy use of smart appliances such as batteries and electric vehicles. The Bill is still going through Parliament and is not yet law.
- PCI DSS: the Payment Card Industry Data Security Standard (PCI DSS) is the security standard for any organisation that stores, processes or transmits card data. PCI DSS requires strong cryptography for card data sent over open, public networks, and lists cellular technologies among its examples of those networks. Network segmentation is not itself a PCI DSS requirement, but it can reduce the scope of an assessment. A private APN, fixed private IP addresses and VPN encryption support both.
- Sector frameworks: financial services, healthcare and critical national infrastructure have their own security standards, which connectivity must also support.
Our security controls support compliance with these frameworks. Where you need a specific certification or architecture assessment, we work with you at the design stage to match the controls to the requirement. If you sell connected products into the EU, see EU Cyber Resilience Act: What It Means for UK IoT.
Frequently Asked Questions
What Makes an IoT SIM More Secure Than a Consumer SIM?
An IoT SIM is more secure than a consumer SIM because it comes with network controls that consumer SIMs do not offer. Millbeck IoT SIMs support a private APN that keeps devices off the public internet, fixed private IP addresses for controlled access and VPNs, IMEI lock, SMS and voice barring, and a platform that suspends SIMs automatically on thresholds you set.
Is a Public Static IP SIM Safe for IoT Devices?
A public static IP SIM makes a device reachable from anywhere on the internet, so the device is only as safe as its own firewall, passwords and firmware. Internet scanners index public addresses continuously and botnets try known weaknesses. For remote access, we recommend a fixed private IP address on a private APN, reached over a VPN, so the device has no public exposure.
Do I Need a VPN If I Already Use a Private APN?
A VPN is worth adding in most deployments, even on a private APN. A private APN stops anyone on the internet reaching your devices, but it does not encrypt traffic end to end between the device and your systems. A VPN tunnel, such as IPsec or OpenVPN, adds that encryption and authenticates traffic before it enters your network. Regulated deployments, such as those carrying card payments, usually need both.
How Do I Manage Devices on a Private APN Remotely?
You manage devices on a private APN by giving each IoT SIM a fixed private IP address and connecting to it from inside your own network, usually over a VPN. Because each SIM keeps the same address, your team can reach any router for configuration, diagnostics and firmware updates whenever it needs to, without opening any device to the public internet.
Does the Cyber Security and Resilience Bill Affect IoT Connectivity?
The Cyber Security and Resilience Bill could affect IoT connectivity where connected devices support a regulated service. The Bill would extend the NIS Regulations 2018 to data centres, managed service providers, large load controllers and critical suppliers. The Bill is still going through Parliament, so operators should review their connected estates and suppliers now.
Does PCI DSS Apply to Card Payments Sent Over 4G or 5G?
PCI DSS applies to card payments sent over 4G or 5G, because it lists cellular technologies as open, public networks. Card data sent over a mobile network must be protected with strong cryptography. For card terminals, EV chargers and kiosks on IoT SIMs, a VPN tunnel provides that encryption, and a private APN with fixed private IP addresses keeps payment traffic separate from the public internet.
This is some text inside of a div block.