# Steps to Implementing Security by Design for IoT

By Shelby Skrhak · Published 2020-03-24 · Updated 2026-07-23 · Industrial IoT on MarketScale
Canonical: https://www.marketscale.com/industries/industrial-iot/steps-to-implementing-security-by-design-for-iot

> IoT security by design might seem like a buzzword in that it’s not well-defined in the consumer landscape, but KORE Wireless’s Chris Francosky said the most effective security measures are put in place well before production even begins. Host Shelby Skrhak sat down with Francosky on this episode of the Industrial IoT podcast, brought…

## Key points

- Implement IoT security measures early in the product development process.
- Use threat modeling as a core strategy with steps like defining assets, identifying threats, and prioritizing them.
- STRIDE is a useful acronym for identifying types of security threats in IoT systems.

IoT security by design might seem like a buzzword in that it’s not well-defined in the consumer landscape, but [KORE Wireless’s](https://www.korewireless.com/) [Chris Francosky](https://marketscale.com/industries/contributors/chris-francosky/) said the most effective security measures are put in place well before production even begins.

Host Shelby Skrhak sat down with Francosky on this episode of the Industrial IoT podcast, brought to you by MarketScale.

“I’m evangelizing this idea of a five-step process centered around threat modeling, which is at the heart of security by design,” Francosky said.

**5 Step Process for Threat Modeling**

1. Define your assets – not only devices, but the data, as well.
2. Decompose that application through an architecture diagram so you can see clearly how the application is broken up.
3. Look at each area of the decomposed application and identify threats.
4. Document threats.
5. Rate and prioritize threats

How do you recognize threats? In the late 1990s, Microsoft devised an acronym that summarizes the kinds of threats to look for, and it’s still useful today, Francosky said.

The acronym STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Escalation of Privilege. These aspects serve as guideposts to help you identify the types of threats you’re looking for.

KORE Wireless offers tool suites to help make IoT security a part of a consistent process.

For the latest news, videos, and podcasts in the **IoT Industry**, be sure to subscribe to our industry publication.

**Follow us on social media for the latest updates in B2B!**

Twitter – [@MarketScale](https://twitter.com/MarketScale)

Facebook – [facebook.com/marketscale](http://facebook.com/marketscale)

LinkedIn – [linkedin.com/company/marketscale](http://linkedin.com/company/marketscale)

Tags: Chris Francosky Podcast, IoT security, IoT security by design, IoT threat modeling, KORE Wireless, Promoted Content

---
Source: MarketScale, https://www.marketscale.com/industries/industrial-iot/steps-to-implementing-security-by-design-for-iot. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
