| Abstract: |
Police and defence organisations are deploying Internet of Things (IoT) devices at a pace that has outrun their ability to secure them. Body-worn cameras, perimeter sensors, drone fleets, vehicle telematics and smart barracks equipment now sit on operational networks where a single compromised node can leak location data, disrupt command channels, or serve as a pivot into classified systems. This paper proposes a resilient, privacy-preserving threat intelligence and IoT threat-management framework tailored to the constraints of law-enforcement and defence environments intermittent connectivity, strict data-sovereignty rules, and adversaries with above-average resources. The framework combines federated threat-intelligence sharing, so that indicators of compromise can be exchanged across units without exposing raw operational data, with an edge-based anomaly detection layer that keeps sensitive traffic analysis inside the perimeter. A prototype was evaluated on a simulated testbed of 240 IoT endpoints across three network segments (field, base, and command), using five categories of empirical measurement: device inventory and exposure, attack-traffic classification, detection latency, false-positive behaviour, and privacy-leakage risk under federated sharing. Results show a mean detection latency of 1.8 seconds against simulated botnet and reconnaissance traffic, a false-positive rate of 4.1 percent after tuning, and no observable degradation of differential-privacy guarantees when the noise budget was held below ε = 1.2. |