Cybersecurity at the Far Edge: The Overlooked Risk in Physical Security
It’s Cybersecurity Awareness Month! As the month kicks off, the Security Industry Association (SIA) is spotlighting the urgent challenges reshaping the security landscape. In this article, SIA Utilities Advisory Board member Bobbie Ferraro examines zero trust at the edge, why it matters for artificial intelligence and automation and what utilities can do now to enhance cybersecurity at the edge.

Utilities have invested heavily in cybersecurity—protecting networks, applications, identities, control systems and data. But as physical security systems become increasingly connected, automated and intelligent, another trust boundary deserves greater attention: the device at the far edge.
Door contacts, intrusion sensors, readers, locks, alarms and other field devices sit at the beginning of the physical security data chain. They generate the signals that ultimately become alarms, alerts and operational decisions, yet many were designed and deployed long before today’s cyber threats or zero trust principles were part of the conversation.
That raises a fundamental question: If we cannot verify the device generating a security event, how much should we trust the data it produces?
Extending Zero Trust to the Far Edge
Zero Trust is often discussed in the context of users, identities, applications, networks and data. But as physical and cyber systems converge, those same principles of explicit verification need to extend deeper into the physical security environment—all the way to the devices generating security events at the far edge.
An established concept that helps frame this challenge is device identity and authentication, sometimes described as Identity of Things (IDoT). Just as identity and access management establishes who a person or application is and what it is permitted to access, IDoT applies identity and permissions to connected devices. The question becomes not only “Who is the user?”, but also “What is the device, can we verify its identity and what should it be permitted to communicate with?”
This is not a new regulatory requirement—it is a longstanding cybersecurity principle that is increasingly important as more physical security devices become connected and their data is consumed by other systems.
The challenge is particularly significant in legacy environments. Many traditional analog sensors communicate through changes in electrical state. End-of-line resistance can help supervise a circuit for conditions such as an open or short, but it was not designed to provide a cryptographic identity for the device or authenticate the event being generated.
“Recent attacks against water and energy infrastructure are a reminder that adversaries are looking for weaknesses well beyond the traditional network perimeter. As these environments become more connected and automated, we need to think about trust all the way down to the devices generating the data.”
Pierre Bourgeix, CEO and Founder, ESI Convergent
Digital devices and protocols can provide a stronger cybersecurity foundation, but digital does not automatically mean zero trust. What matters is whether the architecture can establish device identity, authenticate communications, protect data integrity and control which devices and systems are permitted to communicate.
Importantly, modernization does not require replacing every analog sensor or wiring. Technologies are available that can add a digital security layer to existing analog infrastructure, providing stronger device identity, authentication and data integrity at or near the source while preserving existing field devices and wiring.
Why It Matters for AI and Automation
As utilities adopt artificial intelligence (AI), advanced analytics and automation, trusted data becomes even more critical. AI can correlate signals, identify anomalies and help operators make faster decisions, while machine-to-machine communications can trigger actions with limited human intervention. Both depend on the integrity of the underlying data.
AI does not inherently know whether a physical security signal came from an authentic source, and automation can magnify the consequences of untrusted data by acting on it faster.
Before AI or an automated system acts on a physical security event, organizations should be able to answer: Where did this data originate, and can we trust it?
What Utilities Can Do Now
Addressing far-edge cybersecurity does not require replacing physical security infrastructure overnight. Start by identifying where trust is assumed rather than verified.
Inventory critical field devices and understand how they communicate and generate events. Assess where device identity, authenticated communications and event data integrity are already supported, and identify gaps where additional technology is needed to establish trust at the source.
For legacy analog environments, evaluate technologies that add digital identity, authentication and data integrity at the far edge without wholesale rip and replace. For digital systems, don’t assume the device or protocol is inherently secure—verify that these protections are actually implemented.
Finally, prioritize data feeding AI, analytics and automated actions. The greater the consequence of acting on a signal, the more important it is to verify that signal at its source.
Can We Trust the Source?
As physical and cyber systems converge, trust must extend beyond users and credentials to include devices, communications, events and data.
The security operation of the future will not simply collect more data. It will increasingly act on that data.
Before we ask an operator, AI or automation to make a critical decision, we should be able to answer one fundamental question: Can we trust the source?
Access more SIA cybersecurity resources and content here.
The views and opinions expressed in guest posts and/or profiles are those of the authors or sources and do not necessarily reflect the official policy or position of the Security Industry Association.
