Wednesday, August 26, 2026 | Trusted IoT intelligence since 2016
General IoT Hardware & Devices India IT & Telecom Industrial IoT Agriculture Defence Energy Healthcare Logistics Smart Cities Networks Platforms & Cloud Smart Home
2 min read

The Internet That’s Designed to Be Attacked

Every consumer IoT device you’ve ever set up assumes the network around it is basically friendly — it expects Wi-Fi to be there, a firmware server to answer, GPS to be honest. This September, in the waters off Portugal, NATO is testing a version of the Internet of Things built on the opposite assumption: that […]

Every consumer IoT device you’ve ever set up assumes the network around it is basically friendly — it expects Wi-Fi to be there, a firmware server to answer, GPS to be honest. This September, in the waters off Portugal, NATO is testing a version of the Internet of Things built on the opposite assumption: that the network is actively hostile from the moment it switches on.

The project is called Mangrove, a Saab-led consortium of industry, small firms and academic researchers tasked with designing the reference architecture for what NATO calls the Allied Underwater Battlespace Mission Network. Its job is to give unmanned submarines, sensors and surface vehicles a shared digital backbone so they can exchange data and coordinate command and control across a wide stretch of ocean — trade press has already started calling it, simply, an “internet of things” for undersea warfare. Mangrove gets its real-world test at REPMUS 2026, NATO’s flagship maritime unmanned systems exercise, running this September off Sesimbra and Tróia — the same exercise that has grown from a small Portuguese research effort in 2010 into a gathering of thousands of participants and well over a hundred unmanned systems from more than twenty nations.

The underlying design philosophy has a name and a decade-old paper behind it: the Internet of Battlefield Things, a term U.S. Army Research Laboratory scientists coined in 2016 to describe a network built for a battlefield rather than a living room. Civilian IoT architecture starts from an assumption of a benign environment and bolts security on afterward. IoBT architecture starts from the opposite premise — that an adversary will actively try to jam the radio spectrum, spoof sensor readings, and physically destroy nodes — and builds resilience in as a first requirement, not a patch. Under the ocean, where GPS doesn’t work and acoustic links are slow, unreliable and easy to jam, that assumption isn’t theoretical. It’s the baseline condition every node has to survive.

That gap between the two design philosophies is closing faster than most people building civilian IoT realize. Power-grid sensors, port logistics systems and pipeline monitoring networks are now sitting in exactly the contested, adversarial conditions the IoBT framework was built for, as state-linked jamming and spoofing incidents against civilian infrastructure have moved from rare events to a recurring feature of the threat landscape. The engineering conversation happening around REPMUS this month — how do you build a network that keeps functioning when someone is actively trying to break it — is no longer a purely military question. It’s the direction every operator of critical-infrastructure IoT is going to be pushed toward, whether they’ve budgeted for it or not.

IoBT vs Consumer IoT infographic - REPMUS 2026