Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Internet and Other Technologies
Internet of Things (IoT): Architecture, Applications and Security Risks
Updated 11 October 2026 · Fact-checked
The **Internet of Things (IoT)** is a network of physical devices fitted with sensors, software and connectivity that collect and exchange data over the internet with little human input. To answer exam questions, explain the architecture layers, give applications, state the security and privacy risks, then link them to Indian law.
Understand Internet of Things (IoT)
The Internet of Things (IoT) means everyday objects that can sense, connect and share data. A smart meter, a fitness band, a connected CCTV camera and a sensor in a factory machine are all IoT devices. Each has a sensor or actuator, a small processor, and a way to connect to a network.
Here is how IoT works. A sensor captures data, such as temperature. The device sends it through a network (Wi-Fi, Bluetooth, cellular or a low-power network) to a gateway or cloud platform. Software processes the data, often with analytics or AI. The result is shown to a user or triggers an action, such as switching off a pump. Data flows up and commands flow down.
A common way to describe the architecture is in layers. Many textbooks use three layers: perception (sensors and actuators), network (connectivity and gateways) and application (services the user sees). Some use four or five layers by adding a processing or middleware layer (storage, analytics) and a business layer (management and decisions). State which model you use and stay consistent.
Enabling technologies include sensors, wireless connectivity, cloud computing, edge computing, big data analytics, and AI and machine learning. Edge computing processes data near the device to cut delay. Applications include smart homes, smart cities, connected vehicles, healthcare monitoring, precision agriculture, industrial IoT and smart grids.
IoT raises serious security and privacy concerns. Devices are small, numerous and often shipped with weak passwords and no updates. They collect personal data, such as location and health readings. For a CS, the key link is to Indian law: the Information Technology Act, 2000 (data protection, reasonable security practices, cyber offences, CERT-In) and the data protection law in force. Always answer with the technical point, the risk, and the legal or compliance response.
Key rules to remember
- Three-layer IoT architecture
- Perception layer → Network layer → Application layer
- Perception senses and acts; network transmits data; application delivers the service to the user.
- Five-layer IoT architecture
- Perception → Transport/Network → Processing (Middleware) → Application → Business
- Use when the question asks for a detailed model. Say that layer names vary between sources.
- IoT data flow
- Sense → Connect → Process → Act/Inform
- A simple answer to 'how does IoT work' that fits any example.
- Security triad applied to IoT
- Confidentiality, Integrity, Availability (CIA)
- Use to structure risks: data leaks hit confidentiality, tampering hits integrity, DDoS or device failure hits availability.
- Answer structure for IoT questions
- Meaning → Architecture → Application → Risk → Legal/Compliance response
- Keeps a descriptive answer complete and in a logical order.
How to solve Internet of Things (IoT) questions
Use this method for any descriptive or case-based question on IoT.
- 1Read the question and mark the command word: define, explain, discuss, advise or analyse.
- 2Define IoT in one or two lines: connected devices that sense, collect and exchange data.
- 3Name the architecture you will use (three-layer or five-layer) and explain each layer with a one-line example from the case.
- 4Link the facts of the case to the layers and enabling technologies, such as cloud, edge or analytics.
- 5Identify the risks: weak authentication, unpatched firmware, insecure communication, data privacy, botnets, lack of standards.
- 6Map each risk to a control and to the legal position under the Information Technology Act, 2000 and the data protection law, stating only what you are sure of.
- 7Give a practical recommendation as a company secretary would: policy, vendor due diligence, encryption, update process, incident reporting.
- 8Close with a short conclusion that answers the exact question asked.
Quickest way: Layer, risk, response in three lines
When to use it: Use when time is short or the question carries few marks.
- Write a one-line definition of IoT.
- List the layers with one example each: perception (sensor), network (gateway), application (app).
- Write three risks and one control for each, then add one line on legal compliance.
Common mistakes in Internet of Things (IoT)
Listing layers without explaining what each does
Students memorise names but not functions.
Fix: Add one line and one example for every layer, such as a temperature sensor in the perception layer.
Mixing three-layer and five-layer models in one answer
Different books use different layer names.
Fix: Choose one model at the start and say that other sources may name the layers differently.
Treating IoT security as only a technology issue
Students focus on hacking and ignore compliance.
Fix: Always add the legal and governance response: reasonable security practices, data protection, incident reporting and vendor contracts.
Quoting section numbers or rules from memory without certainty
Students try to look more precise.
Fix: State the rule in plain words and give a section number only when you are sure of it.
Giving generic examples unrelated to the case
Students write a prepared answer instead of reading the facts.
Fix: Use the device, industry and data in the question for every example.
Confusing IoT with the internet or cloud computing
The terms appear together in the chapter.
Fix: Remember that the internet and cloud are enablers; IoT is the network of sensing and acting devices that uses them.
Worked examples
Example 1
Explain the architecture of the Internet of Things and how it works, using the example of a smart water-metering system run by a municipal corporation.
Show the solution
- Define: IoT is a network of devices with sensors and connectivity that collect and exchange data with little human input.
- Perception layer: smart meters on each connection measure water flow and may detect leakage.
- Network layer: meters send readings through a gateway over a cellular or low-power network to a central server.
- Processing layer: the cloud platform stores readings and analytics identifies abnormal usage or leaks.
- Application layer: the corporation's dashboard and citizens' app show usage and bills; alerts go to field staff.
- Business layer: management uses the data for tariff planning and reducing water loss.
- Data flow: sense, connect, process, then act or inform.
Answer: IoT architecture is commonly described in layers: perception, network, processing, application and business. In the smart water-metering system, meters sense flow, the network carries readings, the cloud analyses them, the app presents bills and alerts, and the corporation uses the insights for decisions. Layer names may differ between sources, but the data flow is the same.
Example 2
A company in Pune sells connected CCTV cameras to homes. Several cameras are found to use a default password and never receive updates, and footage of customers is exposed online. Discuss the security and privacy risks and advise the company on compliance.
Show the solution
- Identify the risks: default credentials allow unauthorised access (confidentiality); lack of updates leaves known vulnerabilities open (integrity); compromised cameras can be used in botnets for attacks (availability).
- Privacy risk: footage of people at home is personal data, and its exposure harms customers and may lead to claims.
- Legal position in plain words: the Information Technology Act, 2000 requires a body corporate handling sensitive personal data to maintain reasonable security practices and makes it liable to pay compensation for negligence causing wrongful loss. Unauthorised access to a computer system is an offence. Apply the data protection law in force to consent, purpose and safeguards.
- Incident reporting: serious cyber incidents must be reported to CERT-In in the manner and time prescribed by its directions.
- Recommend controls: force a unique password at set-up, provide secure and signed firmware updates, encrypt footage in transit and storage, minimise data collected, and publish a clear privacy notice.
- Recommend governance: security-by-design in product development, vendor and supplier due diligence, a vulnerability disclosure process, an incident response plan and board-level oversight.
Answer: The company faces confidentiality, integrity and availability risks from default passwords and missing updates, plus privacy exposure from leaked footage. It should fix the product with unique credentials, updates and encryption, adopt reasonable security practices, follow data protection and CERT-In reporting requirements, and put governance in place. Failure to do so can lead to compensation claims and regulatory consequences.
Exam tips
- Draw or describe the layers in order, and give one example from the case at each layer.
- Pair every risk with a control and a legal or compliance point; examiners reward this three-part structure.
- Use plain-word statements of the IT Act and data protection obligations; avoid section numbers you are not sure of.
- In case questions, advise as a company secretary: policy, due diligence, contracts, training and incident response.
- Keep a short list of applications (smart city, health, agriculture, industry, vehicles) ready for 'discuss' questions.
Practice questions from Internet and Other Technologies
- A logistics firm in Pune records shipment events on a blockchain. An employee wants to secretly change the temperature entry in an old block…
- A start-up proposes a smart contract that automatically releases payment to a supplier once an IoT sensor confirms delivery. Under the Infor…
- A Hyderabad company stores customers' personal data on a cloud provider's servers located abroad. A data breach occurs at the provider. Whic…
- A company wishes to record shareholder register entries on a blockchain. Considering the immutability feature and the right of a data princi…
- A logistics company fits temperature sensors in its refrigerated trucks. Each sensor collects readings and transmits them over a network to …
Internet of Things (IoT) in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internet of Things (IoT): frequently asked questions
What are the layers of IoT architecture?
A common three-layer model has the perception, network and application layers. A five-layer model adds a processing (middleware) layer and a business layer. Names vary between sources, so state the model you use.
What are the main security challenges in IoT?
Common challenges are weak or default passwords, outdated firmware, unencrypted communication, large numbers of poorly managed devices, and botnet misuse. Devices also collect personal data, so privacy is a concern. Resource-limited devices often cannot support strong security.
How does IoT work with an example?
A sensor collects data, a network sends it to a gateway or cloud, software processes it, and the result is shown to a user or triggers an action. In a smart home, a temperature sensor can send readings to an app and switch the air conditioner on or off.
Which Indian laws matter for IoT in the CS Professional paper?
Focus on the Information Technology Act, 2000, covering reasonable security practices, cyber offences and CERT-In, and on the data protection law in force. Explain the rules in plain words and link them to the facts in the question.