While this is a case of "two wrongs make a right"[0] - anything that provides even some value without the backend up will still be connected, perennially at risk of getting taken over by a bad actor.
[0] And a pretty strong argument against "forever" IoT devices.
Maybe the solution is some sort of prepaid credit for a cloud computing network? like lambda or something. That would at least shift the burden of staying running.
[0] And a pretty strong argument against "forever" IoT devices.