MQTT is the backbone of most IoT deployments, but its defaults are built for convenience, not security. Before you connect thousands of devices, every layer of the stack needs hardening.
Encrypt everything with TLS
Never run production MQTT over plaintext port 1883. Enforce TLS on port 8883 so telemetry and credentials can't be sniffed on the wire.
- Use certificates from a trusted CA, not self-signed in production
- Rotate certificates before they expire with automated tooling
- Pin the broker certificate on constrained devices where possible
Authenticate every client
Anonymous access is the single most common MQTT misconfiguration we find during audits.
- Give each device a unique client ID and credential
- Prefer mutual TLS (client certificates) over username/password
- Revoke credentials instantly when a device is decommissioned
Control access at the topic level
A device should only publish and subscribe to the topics it actually needs.
- Scope each device to its own topic namespace
- Deny wildcard subscriptions for device-role clients
- Keep command and telemetry topics separated
The pre-launch checklist
Before any fleet goes live, our engineers confirm TLS is enforced, every client authenticates, topic ACLs are locked down, and broker logs are shipped to monitoring. Skipping any one of these is how breaches happen.