Official workshop at IoT 2026

Security that moves at the speed of connected systems.

Security Command, Continuous Threat Detection and Vulnerability Mitigation for IoT Ecosystems

17 November 2026First day of IoT 2026
Half-day workshopResearch + challenge lab
IoT security & resilienceAcademia meets operations

Paper submission deadline: 14 August 2026, Anywhere on Earth (AoE)

Continuous security posture managementIoT + Edge + CloudAI-assisted security operationsZero TrustHands-on challenge labACM ICPS proceedings

From isolated findings to measurable, risk-informed action.

SCC4IoT 2026 brings together researchers, cloud-security engineers, IoT architects, operators, students, and public-sector practitioners to advance continuous security across heterogeneous IoT, edge, cloud, container, and cyber-physical environments.

The workshop connects research with operational practice across four linked capabilities: asset and exposure visibility, risk-based prioritisation and remediation, application-vulnerability discovery, and anomalous-behaviour investigation.

01

See

Map assets, identities, attack paths, exposures, and dependencies across the IoT-to-cloud estate.

02

Prioritise

Rank findings by exploitability, impact, reachability, and operational context—not severity alone.

03

Investigate

Use telemetry, analytics, and AI-assisted workflows to detect and explain anomalous behaviour.

04

Mitigate

Design auditable remediation, evidence export, closure verification, and continuous improvement.

Research, systems, evidence, and operational lessons.

Topics include, but are not limited to:

Security posture & exposure

CSPM, attack-path analysis, asset discovery, exposure management, and continuous control monitoring.

Threat detection & response

IoT devices, edge nodes, VMs, containers, Kubernetes, serverless workflows, and CPS environments.

Application security

Security testing of IoT dashboards, APIs, digital twins, mobile companions, and web services.

Risk-based operations

Prioritisation, mute rules, false-positive reduction, remediation verification, and SIEM/SOAR export.

AI for security operations

Machine learning, federated learning, graph analytics, and LLMs for detection, triage, and assistance.

Trust & governance

Zero Trust, IAM, privacy, supply-chain security, responsible disclosure, compliance, and human factors.

Datasets & testbeds

Real-world datasets, reproducible tools, benchmarks, digital twins, experimental platforms, and artefacts.

Practice & deployments

Incident studies, public-sector experience, DevSecOps workflows, standards, and lessons from deployment.

Plan your submission.

All deadlines are 23:59 Anywhere on Earth (AoE).

14Aug 2026

Open

Paper submission

Submit anonymised manuscripts through the IoT 2026 EasyChair system.

18Sep 2026

Decision

Author notification

More than one month is reserved for rigorous peer review and discussion.

02Oct 2026

Final

Camera-ready papers

Mandatory final-paper deadline set by the IoT 2026 organising committee.

17Nov 2026

Workshop

SCC4IoT 2026

Half-day programme on the first day of the IoT 2026 conference.

Three ways to contribute.

Original, unpublished work is invited.

6–8 pages

Research papers

Evaluated methods, architectures, algorithms, models, systems, or comprehensive empirical studies.

4–6 pages

Experience & case studies

Deployments, incidents, operational lessons, governance practices, and evidence from real environments.

2–4 pages

Position, dataset, tool & demo

Emerging ideas, reproducible resources, provocative positions, early-stage results, and demonstrations.

3+

reviews targeted
per submission

Robust and constructive peer review

Submissions will be assessed for relevance, technical quality, originality, clarity, evidence, reproducibility, practical value, and potential to stimulate discussion. Conflicts of interest will be managed carefully, and double-anonymous review will be used where permitted.

In line with ACM guidance, acceptance requires at least two positive reviews. Accepted papers are expected to appear in the IoT 2026 companion proceedings within the ACM International Conference Proceedings Series, subject to conference requirements.

Call for Papers

Help shape continuous, measurable IoT security operations.

We especially welcome reproducible work, interdisciplinary contributions, early-career researchers, practitioners with deployment evidence, and perspectives from under-represented regions.

Open submission portal ↗

Authors must follow the official IoT 2026 and ACM formatting, publication, registration, and presentation requirements. At least one author of each accepted paper must register for the full conference.

A focused half-day experience.

Four hours of research, practice, and collaboration.

Opening

Welcome, goals, safety briefing & challenge scenario

Invited keynote

From IoT findings to risk-informed action

Technical Session I

Visibility, exposure & vulnerability discovery

Break

Coffee and demonstrations

Technical Session II

Detection, investigation & response

Panel

AI-assisted IoT security operations: opportunities and limits

Closing

Research agenda, awards, takeaways & next steps

Secure a simulated IoT-cloud estate.

The guided lab translates security research into operational decision-making. Participants work with synthetic data, temporary accounts, and a safe simulated environment—never production targets.

  • Create a justified mute or suppression rule without concealing material risk.
  • Analyse and remediate a high-severity infrastructure or container finding.
  • Identify and interpret a web-application vulnerability.
  • Export prioritised findings and produce a concise remediation record.

The motivating workflow is inspired by Security Command Center, while the workshop remains platform-neutral and welcomes open-source and commercial alternatives. A non-command-line route and observer role will support accessibility.

scc4iot-lab / findings

$ scan --estate iot-cloud-sim

Discovering assets and attack paths...

[HIGH] Public workload → exposed API → device control

[MED] Container image contains outdated package

[INFO] 42 assets mapped / 7 findings prioritised

$ investigate --finding F-204

Evidence bundle ready. Remediation workflow created ✓

Organised across research and practice.

Programme committee invitations and speaker confirmations will be announced as they are finalised.

PC
Programme Committee

To be announced

Invitations are being extended to experts in IoT security, cloud and edge security, AI-assisted security operations, application security, and cyber-physical systems.

Committee development: The final Programme Committee will be formed from confirmed invitees and will balance expertise, geography, career stage, and disciplinary perspective.

Turn security findings into trustworthy action.

Submit your research, system, dataset, case study, tool, demonstration, or position paper.