See
Map assets, identities, attack paths, exposures, and dependencies across the IoT-to-cloud estate.
Security Command, Continuous Threat Detection and Vulnerability Mitigation for IoT Ecosystems
Paper submission deadline: 14 August 2026, Anywhere on Earth (AoE)
SCC4IoT 2026 brings together researchers, cloud-security engineers, IoT architects, operators, students, and public-sector practitioners to advance continuous security across heterogeneous IoT, edge, cloud, container, and cyber-physical environments.
The workshop connects research with operational practice across four linked capabilities: asset and exposure visibility, risk-based prioritisation and remediation, application-vulnerability discovery, and anomalous-behaviour investigation.
Map assets, identities, attack paths, exposures, and dependencies across the IoT-to-cloud estate.
Rank findings by exploitability, impact, reachability, and operational context—not severity alone.
Use telemetry, analytics, and AI-assisted workflows to detect and explain anomalous behaviour.
Design auditable remediation, evidence export, closure verification, and continuous improvement.
Topics include, but are not limited to:
CSPM, attack-path analysis, asset discovery, exposure management, and continuous control monitoring.
IoT devices, edge nodes, VMs, containers, Kubernetes, serverless workflows, and CPS environments.
Security testing of IoT dashboards, APIs, digital twins, mobile companions, and web services.
Prioritisation, mute rules, false-positive reduction, remediation verification, and SIEM/SOAR export.
Machine learning, federated learning, graph analytics, and LLMs for detection, triage, and assistance.
Zero Trust, IAM, privacy, supply-chain security, responsible disclosure, compliance, and human factors.
Real-world datasets, reproducible tools, benchmarks, digital twins, experimental platforms, and artefacts.
Incident studies, public-sector experience, DevSecOps workflows, standards, and lessons from deployment.
All deadlines are 23:59 Anywhere on Earth (AoE).
Open
Submit anonymised manuscripts through the IoT 2026 EasyChair system.
Decision
More than one month is reserved for rigorous peer review and discussion.
Final
Mandatory final-paper deadline set by the IoT 2026 organising committee.
Workshop
Half-day programme on the first day of the IoT 2026 conference.
Original, unpublished work is invited.
Evaluated methods, architectures, algorithms, models, systems, or comprehensive empirical studies.
Deployments, incidents, operational lessons, governance practices, and evidence from real environments.
Emerging ideas, reproducible resources, provocative positions, early-stage results, and demonstrations.
reviews targeted
per submission
Submissions will be assessed for relevance, technical quality, originality, clarity, evidence, reproducibility, practical value, and potential to stimulate discussion. Conflicts of interest will be managed carefully, and double-anonymous review will be used where permitted.
In line with ACM guidance, acceptance requires at least two positive reviews. Accepted papers are expected to appear in the IoT 2026 companion proceedings within the ACM International Conference Proceedings Series, subject to conference requirements.
We especially welcome reproducible work, interdisciplinary contributions, early-career researchers, practitioners with deployment evidence, and perspectives from under-represented regions.
Authors must follow the official IoT 2026 and ACM formatting, publication, registration, and presentation requirements. At least one author of each accepted paper must register for the full conference.
Four hours of research, practice, and collaboration.
Analyse a simulated IoT-cloud estate, justify a suppression rule, triage a high-risk finding, identify an application weakness, and design an auditable remediation record.
The guided lab translates security research into operational decision-making. Participants work with synthetic data, temporary accounts, and a safe simulated environment—never production targets.
The motivating workflow is inspired by Security Command Center, while the workshop remains platform-neutral and welcomes open-source and commercial alternatives. A non-command-line route and observer role will support accessibility.
$ scan --estate iot-cloud-sim
Discovering assets and attack paths...
[HIGH] Public workload → exposed API → device control
[MED] Container image contains outdated package
[INFO] 42 assets mapped / 7 findings prioritised
$ investigate --finding F-204
Evidence bundle ready. Remediation workflow created ✓
Programme committee invitations and speaker confirmations will be announced as they are finalised.
Bahria University Lahore Campus, Pakistan
zunnurain.hussain@ieee.orgInvitations are being extended to experts in IoT security, cloud and edge security, AI-assisted security operations, application security, and cyber-physical systems.
Submit your research, system, dataset, case study, tool, demonstration, or position paper.