Frankenkieselsteine: The Abby Normal Economy of the Internet of Things

A gothic laboratory with a humanoid, made up of IoT devices, on the table.

It’s Alive! But Is It Secure?

Mary Shelley’s Frankenstein was never really about the monster. It was about the hubris of invention: the thrill of proving something could be done, without pausing to ask whether it should. Two centuries later, we’ve recreated that story in silicon and Wi-Fi. We stitched together sensors, cameras, and microcontrollers, zapped them with connectivity, and shouted: “It’s alive!” The Internet of Things (IoT) was born.

But just like Victor Frankenstein’s creation, the IoT is a creature we don’t fully understand and can’t fully control. The market’s incentives rewarded speed to shelf, low sticker prices, and glossy feature lists. Each device is a reminder of the old industry joke: “The S in IoT stands for Security.” Convenience, novelty, and low prices drove demand. Security has been, at best, an afterthought...the equivalent of sewing a few extra stitches on the monster’s arm and hoping it holds. And so devices went out the door, alive, humming, and mostly ignored.

The result is a world where your baby monitor can be hijacked by strangers, your fridge can be conscripted into a botnet, and your car can be taken over from a laptop in the passenger seat. These aren’t horror-movie hypotheticals; they’re documented attacks.

And what about the villagers? In Shelley’s tale, they grabbed torches. Our version is more mundane: most IoT owners barely notice, shrugging at firmware updates and default passwords, while the harm drifts downstream. Like digital pollution, the mess doesn’t vanish; it lands somewhere else: network providers, enterprise infrastructure, and ultimately society at large. We animate millions of devices with barely a thought for the consequences, and then wonder why the world feels a little more chaotic.

The Abby Normal Economy

The IoT boom felt like Victor’s first jolt of lightning: proof that the experiment “could work!” never mind whether it should. In startup labs everywhere, the same manic optimism hummed: patch later, scale now, apologize when breached. It’s an Abby Normal economy: not malicious, just wired wrong from the start. The wrong brain in the right body, and everyone too busy celebrating the spark to notice the mismatch.

The Internet of Things wasn’t built; it accreted. A thermostat here, a baby monitor there, a Wi-Fi chip grafted onto a lightbulb because someone in marketing thought “smart” would sell better than “efficient.” There was no grand design, just a thousand small experiments stitched together with open-source libraries, reference boards, and wishful thinking. To the Victors went the spoils.

That patchwork origin story is part of its charm...and its curse. Each generation of devices borrowed code and components from the elsewhere, inheriting both convenience and vulnerabilities. Manufacturers raced to connect everything faster than they learned to secure anything.

In the early days, it didn’t seem to matter. Who would bother hacking a toaster? But as prices dropped and volumes exploded, those same design shortcuts — hardcoded passwords, unencrypted traffic, outdated kernels — scaled right along with production. Suddenly, the throwaway logic of consumer gadgets had crept into cars, medical devices, and critical infrastructure.

The economic logic was airtight. Margins on IoT hardware are razor-thin; security adds cost and slows time-to-market. Consumers reward shiny new features, not invisible resilience. Retailers push price points, not patch cycles. The result was a Cambrian explosion of connected things, each with just enough intelligence to function...and just enough negligence to be dangerous.

If Victor Frankenstein had a procurement department, this is how he would’ve done it: low bid, fast turnaround, minimal oversight. “Don’t worry,” they’d say, “we’ll fix it in firmware.” Except firmware updates are expensive, and many devices never receive them at all. Once shipped, they’re immortal...a permanent population of vulnerable endpoints, forever connected, forever neglected.

What began as a technological wonder has become a kind of living fossil record of past design decisions. Each insecure webcam and abandoned router is a preserved mistake, still humming quietly on someone’s network, waiting to be rediscovered by the next botnet.

And yet, the industry keeps animating new creations. Not out of malice, but momentum. The monster must grow; the market demands it. Devices are cheap, margins thin, and differentiation fleeting. Security, meanwhile, remains an externality: a problem for the next release, or the next victim.

The Monster Nobody Owns

Every human-created-monster story has a moment of disavowal...that scene where the creator steps back, horrified, and mutters: “This wasn’t what I intended.” The Internet of Things hit that moment years ago, but instead of a single Victor Frankenstein, it has thousands of little ones...Frankenkieselsteine, if you will (go ahead...you can put that into a translator), each owning a small piece of the creature, while no one owns the whole.

That diffusion of responsibility is the defining feature of IoT’s security failure. Consumers buy devices assuming they’re safe. Manufacturers ship devices assuming users will patch them. Retailers sell them assuming regulators are watching. Regulators assume the market will self-correct. In the end, everyone assumes, and no one secures.

When the Mirai botnet took down major parts of the internet in 2016, investigators traced it back to hundreds of thousands of hacked webcams and DVRs...devices that had been mass-produced, white-labeled, and forgotten. No one could even say who was responsible for patching them. The creators were long gone; the devices lived on. Frankenstein would’ve recognized the pattern.

The incentives couldn’t be clearer...or more perverse.

  • Manufacturers compete on features and price. Security slows release cycles and adds cost, so it’s deprioritized or ignored.
  • Consumers can’t evaluate security and don’t feel the pain when their devices are weaponized against someone else.
  • Attackers thrive on the resulting asymmetry: they exploit collective neglect for near-zero cost.
  • The broader ecosystem bears the cleanup: ISPs, enterprises, governments. The externalities are real, but the accountability isn’t.

If you’ve been reading The Security Economist for a while, you’ll recognize this as another flavor of the digital pollution that shows up in data breaches. Economically, this is a textbook market failure. Security is a public good: non-rivalrous and non-excludable. Everyone benefits from a safer ecosystem, but no single actor has sufficient incentive to pay for it. The result is predictable: underinvestment, externalized harm, and a steady accumulation of insecure devices.

And because most IoT devices are cheap, disposable, and invisible, consumers don’t behave like victims; they behave like bystanders. A hacked camera doesn’t cost the manufacturers money or reputation; it costs their customers uptime or privacy. The harm drifts downstream, just like pollution. The manufacturers emit it, and the users ignore it until something bad happens to them. At that point, they may not even know what to clean up, or how.

Attempts to fix this with voluntary standards or labeling schemes haven’t shifted the math. A security certification badge adds cost but doesn’t move units. The economics still favor the factory that cuts corners. Until the cost of insecurity lands somewhere close to where it originates, the creature will keep growing: an expanding population of unpatched, unowned, undead devices wandering the world’s networks.

And the irony is that IoT security failures don’t look like drama. They don’t scream or lurch through the streets. They whisper. They exfiltrate data, amplify DDoS traffic, quietly erode trust in connected infrastructure. No torches, no pitchforks...just quiet decay.

That’s what makes this monster so resilient: it doesn’t look like one. The threat isn’t a single breach; it’s the normalization of systemic fragility. We’re living inside Victor’s workshop now, surrounded by half-finished experiments, each humming with just enough life to be dangerous.

It Could Work! (Until It Doesn’t)

In Shelley’s novel, Victor Frankenstein spends the back half of the story trying to escape his creation. He hides, denies, rationalizes. What he never does is accept responsibility. That, too, feels familiar. Today’s IoT ecosystem is a village haunted not by a single monster, but by a thousand little Frankenkieselsteine: each creator assembling their own tiny miracle, selling it, and then quietly walking away once it twitches to life.

When an IoT device is hijacked into a botnet, every manufacturer insists, like Frederick Frankenstein mid-breakdown, that it wasn’t their fault...merely a tragic misunderstanding of responsibility. The firmware? Open source. The vulnerability? User error. The patch? Coming soon. Everyone’s shouting “It could work!” while the lab burns around them; and when the smoke clears, someone mutters “Put… the candle… back!” as if the problem were just a missing toggle, not a missing conscience.

When vulnerabilities surface, the pattern repeats: the vendor blames the supplier, the supplier blames the integrator, the integrator blames the user. By the time the villagers notice smoke, the Victors have already moved on to the next release cycle. In this market, the Victors receive the spoils — quarterly growth, glowing reviews, investor applause — while the villagers pay the price in cascading failures and lost trust.

There’s a psychological comfort in distance. Each small manufacturer sees only its own widget, not the aggregate risk of millions of them connected together. Each decision...skip code review, hard-code a credential, postpone a patch...feels trivial in isolation. But stitched together, those decisions animate a global organism that no one can control. The monster isn’t in the lab; it’s in the supply chain.

Researchers play the role of Cassandra here, shouting warnings from the edge of the village, and often punished for their trouble. Disclosure timelines drag, legal threats loom, and the same design flaws resurface with new logos. The story keeps repeating because the incentives never change. Responsibility is expensive, and neglect is profitable.

The economics reward abandonment. Once a product ships, maintaining it costs money but rarely generates new sales. Many devices are orphaned within months, left online but unsupported. Firmware updates stop; liability ends. Yet the devices keep running...like unattended experiments, still breathing electricity, still connected to everything else.

And so the villagers keep paying: in compromised networks, in the slow corrosion of trust. The market celebrates another “smart” success story, and the workshop fills with fresh prototypes. The Victors win again.

The tragedy more than mere neglect; it’s normalization. A culture that treats insecurity as inevitable is one that quietly accepts collective harm. Until that changes...until the cost of walking away outweighs the cost of staying...the Frankenkieselsteine will keep tinkering, the Victors will keep winning, and the villagers will keep sweeping up the ashes.

Monsters Don’t Regulate Themselves

The moral of Frankenstein isn’t that creation is evil; it’s that creation without accountability is. The same principle applies to the Internet of Things: invention has outpaced responsibility. The market alone can’t correct that imbalance, because the incentives are wired backward.

Security doesn’t sell, at least not in the ways that matter at scale. Consumers rarely demand proof of safety before connecting a thermostat or a camera to their Wi-Fi. They assume that if it’s on the shelf, it’s been vetted...that someone, somewhere, has looked under the hood. But in IoT, there is no such someone. No Consumer Product Safety Commission (CPSC) for code, no UL mark for firmware. The result is a trust vacuum where the cheapest product wins, and everyone quietly prays it’s “secure enough.”

We’ve seen this movie before. The twentieth century was full of industrial miracles that later required an alphabet soup of agencies to contain their side effects: FDA, EPA, NTSB. Each was born from catastrophe: poisoned food, polluted rivers, flaming aircraft. The lesson was that markets don’t self-regulate when the harm is diffuse. They externalize it until it becomes visible enough to outrage the public.

The digital world hasn’t yet had its Cuyahoga moment...no river of data catching fire...but the pattern is familiar. We’re surrounded by invisible spills: botnets built from baby monitors, data leaks from doorbells, power grids buckling under compromised sensors. The damage is real, but abstract, and that makes it easy to ignore.

A CPSC for connected devices wouldn’t stop innovation; it would professionalize it. Mandating baseline security standards — timely patching, support lifecycles, transparent disclosure — isn’t bureaucratic overreach. It’s the cost of doing business in a world where harm travels at network speed. The EU’s Cyber Resilience Act gestures in that direction, and the U.S. has pilot efforts like the NIST IoT labeling program, but both remain voluntary. Voluntary frameworks are what you get when policymakers still believe the monsters can police themselves.

The truth is, they can’t. Not because they’re malicious, but rather because they’re rational. Every rational actor in the system responds to short-term incentives: ship faster, cut costs, grow market share. Those who choose to bear the short-term costs of better security are outcompeted by those who don’t. Without structural correction...without fines, recalls, bans...there’s simply no reason to do otherwise.

In Shelley’s story, one of the many tragedies is that society let Victor keep building, even after his creation terrorized the village. We’ve birthed a thousand Victors and called it innovation. Maybe it’s time we built a few regulators and called it civilization.

Reanimating Responsibility

Mary Shelley ended Frankenstein in ice: the creature vanishing into the Arctic mist, Victor dead, the wreckage of ambition scattered across the ice floes. It’s a fitting metaphor for where the Internet of Things now drifts: an expanse of abandoned devices, unsupported software, and frozen accountability. The experiment lives on, but the experimenters have moved on.

The story doesn’t have to end that way. We could choose to reanimate not just our machines, but our sense of responsibility for them.

In Young Frankenstein, the monster finds peace only when Frederick shares part of his own brain: an act of literal empathy, a kind of regulatory transfusion. Maybe that’s the model we need: creators who share not just code, but consequence. Shared responsibility, not abdicated risk. Creation that includes care. Because what’s stitched together in pursuit of innovation still needs a conscience to keep it whole.

That begins with recognizing that security isn’t a product feature; it’s infrastructure. It’s the digital equivalent of clean water or food inspection: invisible when it works, catastrophic when it fails. We don’t rely on manufacturers to self-certify bridge safety or airplane design. We created systems to do that because the stakes demanded it. Connectivity now underpins our homes, hospitals, and grids; it deserves the same scaffolding of trust.

Some of that will come through regulation: the structural incentives that make safety the path of least resistance. But another part is cultural, rebuilding a public expectation that security is non-negotiable. That expectation can’t come from fear alone; it must arise from familiarity. People need to see secure design the way they see seatbelts or circuit breakers: unremarkable, obvious, standard.

We can also learn from our own metaphors. In Shelley’s world, the creature wasn’t evil at animation; it became monstrous when it was abandoned. The same holds for our devices. A connected gadget left unpatched, unsupported, or unregulated isn’t malicious. It’s neglected. Every unmaintained camera or router is a creature left out in the cold, still humming, still connected, still ours.

Perhaps that’s the real horror here: not that our creations turned on us, but that we turned away first.

If the Victors took the spoils, we can still decide who pays the costs. We can fund the digital equivalents of product safety boards, enforce warranties of responsibility, and demand transparency from those who profit from perpetual connection. We can stitch security back into the social contract, where it always belonged.

Because monsters don’t appear out of nowhere. They’re built, incentivized, and then ignored. The real act of creation now isn’t making smarter things; it’s making a smarter system for keeping those things safe.