The number of connected devices worldwide has continued to climb every year since the term “Internet of Things” was coined, and 2026 is no exception. Smart thermostats, wearables, factory sensors, and connected cars now sit on the same networks as laptops and phones, and that IoT growth brings a real security cost. Every new device is another potential way into a network, and most of them were designed for convenience rather than defence.

This article looks at where IoT growth stands in 2026, the security risks it brings, and what UK businesses specifically need to know about the Product Security and Telecommunications Infrastructure Act. It also covers how artificial intelligence is changing both sides of the fight, what the industrial sector is facing, and where IoT growth is heading over the rest of the decade. Wherever a statistic appears below, it is attributed to the research firm or government body that produced it, so you can check the original source yourself.

Global IoT Growth: How Many Connected Devices Are There in 2026?

Global IoT Growth

Working out exactly how many IoT devices exist is harder than it sounds, since research firms count different things and publish forecasts at different points in the year. IoT Analytics, a specialist research firm that tracks IoT connections on an ongoing basis, gives one of the more consistent pictures of IoT growth over time.

IoT Device Numbers, 2024 to 2030

According to IoT Analytics, the number of connected IoT devices reached 18.5 billion in 2024, up 12% on the year before. The firm’s most recent forecast puts 2025 growth at 14%, taking the total to around 21.1 billion connected devices by the end of that year. Looking further out, IoT Analytics projects that IoT growth will continue at a compound annual growth rate of roughly 13% from 2025, reaching 39 billion connected devices by 2030 and more than 50 billion by 2035.

That pace of IoT growth is not evenly spread across the world. Asia-Pacific continues to add the highest number of new connections each year, driven by manufacturing and smart city projects in China, Japan and South Korea, while North America and Europe grow more slowly but from a larger base of existing enterprise and industrial deployments. The connectivity behind these devices is shifting too: cellular IoT connections, covering everything from 4G asset trackers to 5G industrial gateways, have been growing faster than the wider IoT market as networks expand into rural and industrial areas that older technology could not reach.

Healthcare has also become one of the fastest-growing areas of IoT growth, with wearables and remote monitoring tools increasingly used to track patients outside hospital settings. Our guide to cyber security in the healthcare system looks at the data protection side of that shift in more detail.

Which Sectors Are Driving IoT Growth

Manufacturing remains the single largest adopter of connected devices, using them for predictive maintenance and real-time tracking of stock and equipment. Retailers use IoT growth to their advantage too, fitting sensors to shelves and supply chains to cut down on manual stock checks. Energy providers are rolling out smart meters and grid sensors at scale, while transport and logistics firms use GPS-linked devices to track vehicles and cargo in real time.

Agriculture is a smaller but fast-growing category, with soil and weather sensors helping farmers manage irrigation and crop health more precisely. Every one of these sectors adds new endpoints to defend, which is exactly why IoT growth and IoT security have to be discussed together rather than as separate topics.

IoT Security Risks in 2026

More connected devices mean more places for something to go wrong, and the security side of IoT growth has not kept pace with the hardware side. Many IoT devices still ship with weak or reused default settings, and a large number never receive a single security update after they leave the factory.

Common Attack Vectors and Shadow IoT

One of the biggest problems enterprises face is devices they don’t even know are on their network. Security firm ORDR’s Rise of the Machines research found that 42% of enterprise assets are agentless, meaning they cannot run standard security software, and that the average enterprise network contains more than 50 high-risk or outright banned devices. These unmanaged, or “shadow”, IoT devices often lack basic protections such as encryption or network segmentation, which makes them an easy way in for attackers looking to move sideways into more sensitive parts of a network.

Consumer devices such as routers and IP cameras are common entry points, and our breakdown of hostile types of malware covers how attackers use compromised devices like these to build botnets and launch further attacks. Nation-state groups have also been reported using unmanaged consumer-grade devices as a way into larger targets, a tactic covered in our overview of state-sponsored cyber attacks.

The Cost of an IoT Security Failure

Once a device is compromised, the damage rarely stays contained to that one device. A weak IoT endpoint can give an attacker a foothold to reach servers, staff accounts or customer data stored elsewhere on the same network. Breaches that start with an unmanaged device also tend to take longer to detect and contain, since these devices generate little or no log data for security teams to review. For a business already managing GDPR obligations, an IoT-linked breach can mean the same reporting duties and ICO scrutiny as any other data breach, which is worth factoring into any risk assessment involving connected devices.

Password reuse remains one of the simplest and most common ways attackers get in. Many consumer and small business IoT devices still ship with a single default password shared across an entire product line, and unless the owner changes it during setup, that password is often searchable online.

Firmware that never gets updated compounds the problem: a publicly disclosed vulnerability on one device model can remain exploitable on thousands of units sold years earlier and never patched. This is why the PSTI Act, covered in the next section, focuses so heavily on passwords and update transparency rather than trying to regulate every aspect of device security at once.

UK IoT Regulation: The PSTI Act Explained

Most guides to IoT growth are written from a US perspective and skip over regulation entirely, which is a gap for UK readers. The Product Security and Telecommunications Infrastructure Act, or PSTI Act, is the UK’s answer to weak IoT security, and it has been in force since April 2024.

What the PSTI Act Requires

According to the National Cyber Security Centre, the PSTI Act applies to manufacturers, importers and distributors of consumer smart devices sold in the UK, covering everything from smart TVs and speakers to connected kettles, doorbells and children’s toys. From 29 April 2024, manufacturers have had to meet three core requirements: devices cannot ship with easily guessed default passwords, manufacturers must publish a way for security researchers to report vulnerabilities, and they must state clearly how long a device will keep receiving security updates.

The Office for Product Safety and Standards enforces the Act, and non-compliance can carry fines of up to £10 million or 4% of a company’s worldwide revenue, whichever is higher.

What This Means for Buyers and Businesses

For UK businesses buying IoT equipment, whether that’s a fleet of smart sensors for a warehouse or a batch of connected devices for an office refit, the PSTI Act gives a legal baseline to check suppliers against rather than relying on marketing claims. For manufacturers and importers, it turns security from a discretionary extra into a legal requirement with real financial consequences for getting it wrong.

The Act sits alongside the EU’s Cyber Resilience Act, which imposes broadly similar security-by-design duties on products sold into the European Union, so UK manufacturers selling into both markets increasingly need to design for both regimes from the outset rather than treating them as separate compliance exercises.

Our roundup of the latest trends of cybersecurity covers how the PSTI Act sits alongside other UK data protection obligations, including GDPR and ICO enforcement, and our guide to UK cyber security facts and statistics has more detail on how ICO fines and reporting duties work in practice.

AI and IoT: New Risks, New Defences

IoT Growth, AI and IoT

Artificial intelligence has become part of the IoT security conversation on both sides of the fence. Attackers use AI to write more convincing phishing messages and to speed up scanning for vulnerable IoT endpoints, while defenders use AI to spot unusual device behaviour faster than manual monitoring ever could.

How Attackers Are Using AI Against IoT Devices

AI tools make it easier for attackers to scan large numbers of devices for known weaknesses, generate convincing phishing content aimed at the staff who manage IoT infrastructure, and automatically adapt malware to avoid detection once it is on a network.

None of this replaces the underlying problem of weak passwords and unpatched firmware, but it does mean attacks can be planned and launched faster than before, leaving less time for defenders to react. Our article on AI in cybersecurity looks at this dynamic in more detail, including how the same automation that helps attackers is being used to build faster defences.

AI-Driven IoT Security Tools

On the defensive side, AI-based monitoring tools are increasingly used to build a baseline of what “normal” device behaviour looks like on a network, so that anything unusual, a smart camera suddenly sending large volumes of data out, for example, gets flagged automatically rather than going unnoticed.

This kind of behaviour-based detection matters more as IoT growth continues, since it is no longer realistic for security teams to manually monitor every device on a large network. Automated device discovery tools are also being used to solve the shadow IoT problem described earlier, giving IT teams a clearer picture of exactly what is connected before they can secure it properly.

None of this makes AI a complete answer on its own. Behaviour-based detection still needs to be tuned to a specific network to avoid flooding security teams with false alerts, and attackers are already testing ways to make malicious device activity look ordinary enough to slip past automated baselines.

The practical takeaway for most organisations is that AI-driven tools are becoming a useful layer of IoT defence rather than a replacement for the basics: changing default passwords, keeping firmware updated, and knowing what is actually connected to the network in the first place.

Industrial IoT (IIoT) and Critical Infrastructure

Industrial IoT, sometimes shortened to IIoT, covers the sensors and connected equipment used in factories, energy grids and other critical infrastructure. It carries a different set of risks to consumer IoT growth, since a compromised industrial device can disrupt physical operations rather than just leak data.

Ransomware and Critical National Infrastructure

Manufacturing and energy remain two of the most targeted sectors for ransomware groups, in part because operational downtime is so costly that victims are seen as more likely to pay. Older industrial equipment was often designed without security in mind, since it was never meant to be connected to the internet in the first place, which leaves a long tail of legacy devices that are difficult or impossible to patch.

Businesses operating in these sectors need a different approach to risk management than a typical office environment, and our guide on how to protect your business from cyber threats covers the basics of building that kind of defence, from network segmentation through to incident response planning.

IoT Growth Predictions for 2027 to 2030

Looking ahead, a few trends stand out for where IoT growth and IoT security are heading over the rest of the decade.

  • Connected device numbers will keep climbing steadily rather than exploding, with IoT Analytics forecasting 39 billion devices by 2030 at the current growth rate.
  • Regulation will spread beyond the UK and EU, with more countries expected to introduce their own device security rules similar to the PSTI Act and the EU Cyber Resilience Act.
  • Industrial and healthcare IoT will grow faster than consumer IoT, as sectors with the most to lose from downtime invest more heavily in connected monitoring.
  • Shadow IoT will remain a live problem for enterprises until automated device discovery becomes standard practice rather than an add-on.
  • AI-driven defence tools will become a standard part of IoT security stacks, particularly for detecting unusual device behaviour at a scale that humans cannot monitor manually.
  • Security-by-design will become a genuine buying criterion, as PSTI-style compliance labelling starts to influence purchasing decisions rather than just legal risk.

IoT growth shows no sign of slowing, and neither does the gap between the number of connected devices and the security built into them. Whether you’re buying IoT equipment for a business or simply want to understand what’s changing, the PSTI Act and the broader security landscape covered here are worth revisiting as new rules and threats emerge. If you have questions about a specific device or sector, drop them in the comments below, and we’ll do our best to cover them in future updates.

Frequently Asked Questions

How many IoT devices will there be by 2030?

IoT Analytics forecasts around 39 billion connected IoT devices worldwide by 2030, growing at a compound annual growth rate of roughly 13% from 2025’s total of 21.1 billion.

What is the UK PSTI Act and does it affect me?

The PSTI Act is UK law that applies to manufacturers, importers and distributors of consumer smart devices sold in the UK. It has applied since April 2024 and bans default passwords, requires a vulnerability reporting contact, and requires clear information on security update periods. If you buy or sell connected devices in the UK, it affects you directly.

What are the top IoT security risks in 2026?

The most pressing risks are unmanaged “shadow” IoT devices that sit outside normal IT oversight, weak or default passwords that were never changed, and legacy industrial devices that cannot be patched. AI is now being used by attackers to scan for these weaknesses faster than before.

Why is IoT security harder than IT security?

IoT devices typically have limited processing power, no user interface for applying updates, and lifespans of ten years or more, compared with a few years for a typical laptop. That combination makes patching and monitoring far harder than on standard IT equipment.

Which industries are adopting IoT fastest in the UK?

Manufacturing, energy and healthcare are leading UK IoT growth, driven by predictive maintenance, smart grid rollouts and remote patient monitoring, respectively.

Is the IoT security market growing?

Yes. Mordor Intelligence values the global IoT security market at $11.66 billion in 2026, projecting growth to $47.33 billion by 2031, partly driven by compliance spending linked to the PSTI Act and the EU Cyber Resilience Act.