Story image

Here's why you need to be aware of the internet of things

03 Nov 15

The rise of the internet of things is bringing new an exponential increase in security threats for both business and consumers as vulnerabilities in IoT devices are exploited.

Security vendor F-Secure says the proliferation of connected devices opens up innumerable security vulnerabilities that many people are unaware of.

Gartner has predicted that 4.9 billion connected things will be in use this year. With the global population at around 7.3 billion, this equates to more than one connected device for every two people on the planet – and it’s a number that is expected to increase exponentially.

Jonathan Banks, F-Secure ANZ director of operations, notes that connected devices are all around us – home heating systems, refrigerators, and smart televisions.

“They are beginning to affect every facet of our lives and make things easier and more convenient,” he says.

“However, the rise of the IoT also presents an exponential rise in security threats to businesses and individuals, as vulnerabilities in IoT devices are increasingly exploited by malicious cyber criminals.”

F-Secure says there are three reasons to pay close attention to the rise of the IoT and be aware of the potential threats that the connected devices present:

Threats are increasing The Australian Securities and Investments Commission issues a report earlier this year, noting that malicious cyber attacks on IoT devices are on the rise.

Meanwhile, an HP internet of things research study last year showed that 70% of the most 10 commonly-used connected devices contain serious vulnerabilities.

PricewaterhouseCoopers says the internet-connected devices that make up the IoT are vulnerable to attack because they lack the fundamental security safeguards that larger and more powerful connected devices are equipped with as a matter of course.

Says Banks: “Using smartphones as a point of control exacerbates IoT cyber threat risks because they are often unsecured.

“Cambridge University research shows that around 87% of the billions of Android smartphones globally have been exposed to at least one of 11 critical vulnerabilities.”

Smart cities are emerging At the same time, smart cities, in which connected devices are heavily used, are on the agenda for government and private enterprises alike, with IoT technology becoming a central element in public and civil infrastructure.

Examples include combining network-connected sensing and metering infrastructure with the existing electricity network to improve the efficiency of the electricity sector.

“Clearly, incorporating connected devices into this kind of infrastructure opens up the potential for vulnerabilities that malicious attackers can use to compromise public facilities, putting people and infrastructure at risk,” Banks says.

IoT data is becoming a big business As free online applications such as Gmail and Facebook have become more popular, the idea that data can be used as a lucrative commodity has come to the fore. Now, with individuals around the world adopting connected devices, IoT data is increasingly being collected and commoditised.

Device manufacturers, digital solutions providers and telecommunications companies use IoT data as a revenue source, which presents yet another security concern. As this data becomes more widely used by different companies for different purposes, the greater the potential for a data breach becomes.

“With so much IoT-derived data going around, all it takes is one weak link in the data chain for malicious criminals to obtain personal or sensitive user information, so it is vital to be diligent and careful about where your data goes and how it is treated,” Banks says.

What MSPs can learn from Datto’s Channel Ransomware Report
While there have been less high profile attacks making the headlines, the frequency of attacks is, in fact, increasing.
Cisco expands security capabilities of SD­-WAN portfolio
Until now, SD-­WAN solutions have forced IT to choose between application experience or security.
AlgoSec delivers native security management for Azure Firewall
AlgoSec’s new solution will allow a central management capability for Azure Firewall, Microsoft's new cloud-native firewall-as-a-service.
Kiwis losing $24.7mil to scam calls every year
The losses are almost five times higher compared to the same period last year, from reported losses alone.
How to configure your firewall for maximum effectiveness
ManageEngine offers some firewall best practices that can help security admins handle the conundrum of speed vs security.
Exclusive: Why Australian enterprises are prime targets for malware attacks
"Only 14% of Australian organisations are continuously training employees to spot cyber attacks."
Exclusive: Why botnets will swarm IoT devices
“What if these nodes were able to make autonomous decisions with minimal supervision, use their collective intelligence to solve problems?”
"Is this for real?" The reality of fraud against New Zealanders
Is this for real? More often than not these days it can be hard to tell, and it’s okay to be a bit suspicious, especially when it comes to fraud.