Why the Riskiest Day of a Device's Life Is Day One

Part one of a three-part series on the cyber security implications of device lifecycle management.

There's a particular kind of optimism in the air when new equipment arrives. The boxes are stacked in the server room, still smelling of cardboard and the factory floor. Someone's taking photos for the company Slack. The IT manager is quietly relieved that the budget finally came through, and everyone else is just glad the ancient laptops are going in the bin. New gear feels like a fresh start. Clean. Safe. Yours.

It is, statistically, one of the most dangerous days that hardware will ever have.

Let me tell you how it usually goes wrong…

The welcome email that arrived too late

Picture a mid-sized regional organisation — we'll call them Kōwhai Regional Services, because the specifics don't matter and the pattern is depressingly universal. Kōwhai has just taken delivery of forty laptops and a rack of new network switches. The rollout is on a tight timeline, so the team does what stretched teams everywhere do: they plug things in and get people working.

The laptops come up fine. The switches come up fine. Everything works, which is the trap, because "works" and "secure" are not the same word.

What nobody checks is that the switches are still carrying the manufacturer's default admin credentials — the ones printed in a PDF anyone can download. What nobody checks is that the laptops shipped with a handful of services running that Kōwhai will never use, each one a small open window. What nobody checks is the firmware, which is three versions behind and has a known, published vulnerability with a tidy exploit already circulating.

The devices are, in the language of security, unhardened. They were exposed the moment they powered on. And an attacker doesn't need to be sophisticated to walk through a door that was never locked — they just need to try the handle.

By the time the "welcome to your new laptop" email goes out to staff, the environment has already been mapped by someone who was not invited.

This is not hypothetical - it happened down the road

If that sounds like scaremongering, consider what is arguably New Zealand's most instructive breach — and one of its most avoidable.

In 2012, the Ministry of Social Development ran self-service kiosks in Work and Income offices so job seekers could search and print listings. Reasonable idea. The problem was in how the hardware was commissioned and connected. Blogger Keith Ng, acting on a tip, walked into an office, sat down at a public kiosk, and discovered he had unauthenticated access straight into the Ministry's corporate network. From a machine bolted to the floor of a public waiting room, he could reach invoices, contractor details, and sensitive records — including information about vulnerable children in the Ministry's care.

No malware. No password cracking. No clever social engineering. The kiosks had simply been deployed without being locked down, and they were wired into places they should never have been able to reach. A subsequent Deloitte investigation was, by the assessment of those who read it, brutal.

The lesson isn't "kiosks are bad." The lesson is that a device is only as safe as the day it was set up — and setup is exactly the step everyone is tempted to rush. The Ministry didn't get breached because its technology was old or its attackers were brilliant. It got breached because commissioning was treated as a plug-in-and-go formality rather than a security event.

Device Security in New Zealand


What "doing Day One properly" actually means

New Zealand's National Cyber Security Centre is refreshingly unglamorous on this point. Its asset lifecycle guidance starts not with firewalls or threat intelligence, but with something far more mundane: writing down what you own.

You cannot protect what you cannot see. So the first act of commissioning is building a real asset register — for every laptop, switch, router, printer, server, and licence. Not a spreadsheet someone started in 2019 and abandoned, but a living record that captures, for each asset: what it is, who owns it, who supplies its patches, where it sits physically and on the network, its serial number, the system it supports, and — crucially — its end-of-support date.

That last field is a time bomb you get to defuse in advance. But that's a story for part two.

Once an asset is recorded, the NCSC's next instruction is equally plain: harden it before use. In practice that means three things done consistently, every time:

  • Remove or change default accounts and passwords. The credentials that shipped with the device are not a secret; treat them as already compromised.

  • Disable unused services and close open ports. Every service you're not using is an attack surface you're maintaining for free — on the attacker's behalf.

  • Update to the latest supported software and firmware. New in the box does not mean current. Plenty of "new" hardware has been sitting in a distributor's warehouse for months.

None of this is exotic. That's the uncomfortable part. The MSD breach, and thousands of quieter incidents like it, didn't require a failure of sophisticated defences. They required the absence of basic ones at the moment of setup.

And it's worth naming the risk that arrives before the device even does: the supply chain. Hardware can be exposed before it reaches your loading dock — which is why commissioning discipline, asset tracking, and a clean chain of custody from supplier to desk matter more than most organisations realise.

The regulator and the insurer are both watching Day One

Two forces have quietly raised the stakes on all of this.

The first is the Privacy Act 2020. Information Privacy Principle 5 requires organisations to protect personal information with "such security safeguards as are reasonable in the circumstances." That obligation doesn't switch on once a device has accumulated a comfortable pile of data — it applies from the moment the device is capable of holding or reaching personal information. A laptop deployed with default credentials, on Day One, is arguably already in breach of your reasonable-safeguards duty. "We hadn't got around to configuring it" is not a defence anyone wants to test in front of the Privacy Commissioner.

The second is your cyber insurer. The market has hardened considerably. Insurers now routinely ask — as a condition of cover, not a nice-to-have — whether you maintain an accurate asset inventory and a documented hardening baseline. Increasingly the logic is blunt: no register, no evidence of due diligence, no payout. The asset list you build during commissioning isn't just good hygiene; it's the paperwork that stands between a covered incident and a declined claim.

Getting the first death right

Every device lives three lives and dies three deaths — the day it's switched on, the day its vendor stops supporting it, and the day it leaves your building. This series is about all three. But the first death is the one that sets the tone for everything after, because a device commissioned badly is a device you'll be fighting for its entire working life.

This is precisely the "messy middle" that gets skipped when internal teams are stretched thin — the asset tagging, the imaging, the staging and hardening that happens before a device ever reaches a user's hands. Done properly, commissioning turns Day One from your weakest moment into your strongest. Done as an afterthought, it hands attackers a key cut to fit before you've even changed the locks.

The new gear really can be a fresh start. It just has to be born locked.

Check out the Divers Device Management Support Service

Next in the series — Act II: "The Slow Betrayal: When Loyal Equipment Becomes Your Biggest Liability." What happens when the device that has served you faithfully for years quietly stops being supported — and becomes the front door you forgot you left open.



Previous
Previous

When Loyal Equipment Becomes Your Biggest Liability

Next
Next

What's Happening to Your Freight Bill Right Now