The summary.
UNIQUE CREDENTIALS PER DEVICE, ALWAYS
A shared credential means compromising one device compromises the fleet.
And an unrecorded device cannot be managed, secured or recovered — record every one, its owner, location and status.
NEVER HARD-CODE SERVER ADDRESSES
Changing infrastructure would otherwise require a firmware update to every device in the field.
VALIDATE CONFIGURATION ON THE DEVICE AND REVERT TO LAST KNOWN GOOD
It is the only defence against remotely disabling your own fleet with a bad setting.
STAGE EVERY UPDATE AND VERIFY SIGNATURES BEFORE APPLYING
A defective update applied everywhere at once can end a deployment, and anyone able to deliver an unsigned image controls the fleet.
Require the new version to prove it can connect, or revert automatically.
ALERT ON PROPORTIONS AND GROUPS, NOT INDIVIDUAL DEVICES
Correlated failure indicates a common cause. Per-device alerting in a large fleet is unmanageable and buries real problems.
VISIT COST FREQUENTLY EXCEEDS DEVICE VALUE
Design for swap rather than repair, and hold spares against import lead times.
REVOKE CREDENTIALS ON DECOMMISSIONING, AND DESIGN FOR SURVIVING YOUR SERVICE ENDING