I expect the business unit that sells "secure" IoT devices, to follow the guidelines from Microsoft Security Response Center, but that is expecting too much I guess.
Expecting a Profit Center to follow instructions from a Cost Center is akin to expecting the US Congress to act on advice from the General Accounting Office.