Skip to content
All industries
Connected IoT / Smart Buildings

One compromised node is a bridge into the corporate network. We watch every node.

Connected lighting, smart-building sensors, surveillance cameras, and consumer IoT in enterprise settings create unmonitored bridges into corporate networks. Blacklight monitors connected fleets at scale on Zigbee, Wi-Fi, and BLE, with no endpoint agent required.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • Verkada
    Surveillance cameras accessed across hospitals, prisons, factories
    150,000 cameras, 2021
  • Johnson Controls
    Ransomware, floor plans and physical security layouts exfiltrated
    27TB stolen / $27M, 2023
  • Schneider Electric
    Cactus ransomware, sustainability business unit
    1.5TB stolen, 2024
  • ABB
    Black Basta ransomware, engineering data exfil
    2023
Case in point

Verkada, 2021: 150,000 surveillance cameras accessed in hospitals, prisons, and factories

A single compromised IoT node propagates laterally into everything it touches. Check Point demonstrated how one compromised smart bulb could spread malware across an entire Zigbee network. Verkada lost 150,000 surveillance feeds across hospitals, prisons, and factories in 2021. Johnson Controls: 27TB stolen and a $27M remediation, including floor plans and physical security layouts. Schneider Electric: 1.5TB. ABB: hit by Black Basta. These are not edge-cases, they are the new norm. Blacklight watches connected fleets at scale across Zigbee, Wi-Fi, BLE, and IP backhaul, agentless, end-to-end. Abnormal mesh traffic flagged in real time. Firmware tampering detected before exploitation. Physical-security telemetry cross-correlated with corporate network telemetry, so smart-building compromises do not become data breaches.

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Fleet-scale IoT and smart-building monitoring, agentless, across Zigbee, Wi-Fi, and BLE
  • Lateral-movement detection from IoT into corporate IT before exfil starts
  • Firmware integrity and supply-chain tampering alerts for device fleets
  • NIS2 and GDPR evidence bundled per-incident, per-jurisdiction
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.