The summary.
A COMPROMISED SENSOR LEAKS INFORMATION; A COMPROMISED ACTUATOR CAUSES EVENTS
Which is why enforcing limits on the device, and authenticating commands at the message level rather than only the transport, matters more here than elsewhere.
YOUR DEVICES ARE A RISK TO OTHERS, NOT ONLY TO YOU
Default credentials and unpatched software have produced enormous attack networks. Unique credentials per device, no exceptions.
Never derive credentials from serial numbers — once the derivation is known, every device is compromised.
PLAN CERTIFICATE EXPIRY BEFORE THE FIRST ONE ARRIVES
Expired certificates disconnect a fleet permanently if renewal was not built in.
DISABLE DEBUG INTERFACES BEFORE SHIPPING
They usually give complete access and are routinely left enabled.
DEVICES SHOULD INITIATE OUTWARD AND NEVER ACCEPT INBOUND CONNECTIONS
And a compromised device contacting an unknown destination is the clearest signal you will get.
EVEN SIMPLE SENSORS REVEAL PATTERNS OF LIFE
Process locally where possible — data that never leaves cannot be breached.