We live in a world of connections, far more than most individuals and companies take time to appreciate. Historically, the companies with the most durable value in this ecosystem owned what couldn’t be replicated: spectrum and network footprint. That’s no longer the whole story.
Satellite is redrawing the map of device connectivity. AI is being applied, rapidly and carefully, across device estates of every kind. eSIM adoption is about to bring tens of billions of new devices online. That footprint is being redrawn not just technically, but by customer demand for control and elevated security. Defensibility, and the real opportunity, sit in the connectivity layer and edge networking. AI sits atop that estate and will materially change the networks and the device-level controls beneath them. The largest enterprises and public sector leaders no longer treat connectivity as an expense line; device productivity and security are the actual focus.
The requirements coming out of utilities, automotive and public safety say the same thing in different words: legacy approaches have run out of road. Without full control, is there full security for a device landscape this distributed? The biggest names in enterprise security are buying their way toward complete coverage, and they’re right to. But one blind spot survives every deal, beneath the device, at the connectivity layer, where no M&A has reached yet.
2024-2026 have been landmark years for security acquisitions, and momentum has only sharpened.
- ServiceNow acquired Moveworks and Veza, then agreed to acquire Armis for $7.75 billion, a push into asset visibility opening the door to IoT. (Their CRM focus could create an entire IT-OT/IoT profile for customers and downstream alignment)
- Palo Alto Networks moved on CyberArk for roughly $25 billion, folding in Chronosphere and Onyxia for observability.
- Cisco continues building around its $28 billion Splunk acquisition, adding Galileo Technologies for AI agent observability, plus has ThousandEyes and Control Centre positions.
These consolidations signal a market conclusion: security is increasingly won at the platform level, not through point products. Enterprise risk is concentrating around identity, observability, IT/OT convergence, and the autonomous workflows AI now drives. These are formidable, tier-1 IT companies, and their strategy is unmistakable: build integrated, AI-enabled control planes for security, networking, and operations to deliver greater operational visibility, tighter security postures, and agentic resiliency.
Unaddressed blindspots
Put yourself in the CISO’s chair, or the CIO’s, or the COO’s, after all this investment, where is the blind spot still?
Imagine you’ve done everything right. Asset intelligence discovers and profiles every device on your network. A SIEM correlates events across your estate. Identity governance covers human and non-human accounts. OT and IoT discovery feed the same workflows as your IT.
Now picture the part of your estate that never touches your network at all: routers in the field, meters on the grid, GPS trackers on the fleet, first-responder field devices, point-of-sale terminals in the stores. Tens of thousands, sometimes millions, of devices connected over cellular and satellite, some of your most exposed assets, reachable only through networks you don’t operate and must simply trust.
Almost everything the consolidation wave is buying lives above or beside those devices. Almost none of it reaches underneath, to the connectivity itself, where an entire class of risk sits untouched.
Is that SIM or eSIM even active, or is the device silently dead? Has its profile been swapped without authorization? Is it roaming somewhere it has no business being? Today’s platforms can tell you a device is talking a great deal. They cannot tell you whether that traffic is benign or malicious, because they have no visibility into the network the device doesn’t control. IT and security leaders have defined this vulnerability with precision. Their behavior on who to turn to is the opportunity.
However, the scale of the need is larger than most enterprises realise. Across Simetric‘s customer base, we consistently find 10-15% of an enterprise’s deployed IoT devices inoperable at any given time: silently offline, misprovisioned, or otherwise unreachable. One inoperable device is an inconvenience. Thousands are a fleet-wide blind spot, a compliance exposure (i.e. EU Cyber Resiliency Act), and in cases, lost revenue, all at once. Every device represents compute the enterprise already paid for. If it isn’t connected, secured and operated as a fleet, it isn’t an asset. It’s stranded capital, sitting idle on the balance sheet.
This isn’t a knock on any one platform; it’s a structural gap. The connectivity layer is fragmented across hundreds of operators, each with its own portal, data model and management plane. Even as these players expand their value, none of their acquisitions closes this gap, because it lives in the seams between carriers, and in the SIM and eSIM identities that are the real control plane for distributed devices.
What closing the gap looks like
This is the layer Simetric was purpose-built for. We don’t replace the connectivity management platforms operators run, and we don’t compete with the security platforms enterprises are consolidating around. We sit above the carrier layer, in what analysts call Connectivity Management Orchestration (Counterpoint Research) or Distributed Workflow Management (Transforma Insights), normalising hundreds of operator connections, plus satellite, into a single enterprise control plane. The SIM and eSIM become first-class security identities: discoverable, attributable, actionable.
Practically, that gives a CISO what the rest of the stack cannot supply: unified visibility across every carrier and modality, including the satellite and eSIM estate traditional tooling never sees; a genuine control plane, able to quarantine a device, swap a profile, or change a rate plan at the SIM level instantly; and destination intelligence, so “this device is talking a lot” finally becomes “this device is talking to something it shouldn’t.” That governance extends natively into platforms like ServiceNow.
eSIM adoption and AI, in tandem, are forcing every enterprise and public sector organisation to rethink how the business runs, not just how it’s provisioned. That synergy deserves to be defined deliberately, not discovered by accident. As AI agents take on more reasoning and decision-making across IoT fleets, the changes won’t stop at the network layer. They will reach into how enterprises staff, budget, and run operations, moving device management from a periodic IT chore into a continuously governed, AI-assisted discipline.
The instinct is right; the map has one more layer
The acquisition wave is closing valuable gaps, and enterprises buying into these platforms are better protected for it. My only argument: the map has one more layer than most of these deals account for. For connected devices at scale, security does not start at the network edge or the enterprise IT boundary. It starts at the SIM. Observability and segmentation must exist there for data and security continuity.
Closing that last gap doesn’t mean unwinding platform decisions already made. It means extending them one layer further, to where the most distributed, least visible, and most expensive-to-strand assets live. Enterprise requirements have hardened around asset management and security posture; connected devices are vital to organisations of every size. No one disputes that connectivity matters. What enterprises are asking for now is an IT ecosystem that finally treats it that way: infrastructure worth building on, not a disconnected networking landscape.
Comment on this article via X: @IoTNow_ and visit our homepage IoT Now
