Story image

IoT device security is a business responsibility, too

09 May 2018

IoT devices provide ample opportunity to attackers looking to use them as entry points for network compromise schemes – and despite the risks, security is still being overlooked.

ESET says that the Internet of Things has gone beyond a trendy buzzword to a genuine set of emerging technologies that will improve business operations and improve experiences for consumers.

However, the security issues that plague IoT devices persist, leading to devices that have little or no built-in security.

ESET senior research fellow Nick FitzGerald explains that even when basic security measures are built in, users don’t often change usernames or passwords from the defaults. This, he says, makes it easier for hackers to gain access to the devices.

“Many of these devices are used in applications that make their security critical. For example, automatic braking systems in trains or buses could create life-threatening situations if they were sabotaged by cybercriminals. It’s therefore essential to carefully consider security when implementing IoT devices and to not trust that security will be managed by the vendor,” he explains.

There is one way to address this challenge, which is to use ‘mutually-suspicious platforms.

The company explains:

“Isolating cores, memory, applications, operating system code, and other resources can form a breach-resistant group of barriers. This can make it more difficult for software developers, but the resulting applications are also far more secure, making this approach ideal when safety is at stake.”

Airgapped systems may have been secure in the past such as Controller Area Network (CAN bus) or ICS-related protocols, but they are now more likely to be fully connected and vulnerable to attack. They must also be defended.

FitzGerald says that cyber attacks are growing more intense, more severe, and are happening more often.

“IoT devices and other connected networks are providing new ways for attackers to sneak in the back door of organisations.”

“Businesses shouldn’t let this stop them from embracing new and emerging technologies, especially those that promise to deliver business efficiencies and potential new revenue streams. However, it is essential for businesses to be well aware of the security implications and take the right steps to protect their networks.” 

He says that organisations should choose IoT products that include security by design. They should also look for vendor commitments surrounding product maintenance, and those who deliver firmware or software updates for the device’s entire serviceable life.

“This approach removes the need for consumers or organisations to make security-related decisions by defaulting to secure settings. Two ways businesses can improve IoT security is to change default passwords to unique passwords and to regularly update the product with patches and other security updates.” 

Secureworks Magic Quadrant Leader for Security Services
This is the 11th time Secureworks has been positioned as a Leader in the Gartner Magic Quadrant for Managed Security Services, Worldwide.
Google puts Huawei on the Android naughty list
Google has apparently suspended Huawei’s licence to use the full Android platform, according to media reports.
Using data science to improve threat prevention
With a large amount of good quality data and strong algorithms, companies can develop highly effective protective measures.
General staff don’t get tech jargon - expert says time to ditch it
There's a serious gap between IT pros and general staff, and this expert says it's on the people in IT to bridge it.
ZombieLoad: Another batch of flaws affect Intel chips
“This flaw can be weaponised in highly targeted attacks that would normally require system-wide privileges or a complete subversion of the operating system."
Forget endpoints—it’s time to secure people instead
Security used to be much simpler: employees would log in to their PC at the beginning of the working day and log off at the end. That PC wasn’t going anywhere, as it was way too heavy to lug around.
DimData: Fear finally setting in amongst vulnerable orgs
New data ranking the ‘cybermaturity’ of organisations reveals the most commonly targeted sectors are also the most prepared to deal with the ever-evolving threat landscape.
IXUP goes "post-quantum" with security tech upgrade
The secure analytics company has also partnered with Deloitte as a reseller, and launched a SaaS offering on Microsoft Azure.