Securing the Internet of Things

July 2018 Information Security, Industrial (Industry)

With more than 75 billion devices expected to be connected to the Internet by 2025, the Internet of Things (IoT) has become an integral part of the digital world. As we become more reliant on these devices for our work and personal lives, we need to be aware of their inherent security risks.

Jorina van Rensburg, MD of Condyn.
Jorina van Rensburg, MD of Condyn.

One of the biggest problems is the login and password details of connected devices. These are typically preconfigured by manufacturers. How many end-users change these default settings? Using sophisticated tools, hackers can ‘snoop’ the Internet for these standard details and can easily gain access to them, severely compromising the user.

Another challenge is how easy it has become for manufacturers to send through updates to connected devices. Because this communication is unencrypted, patches can be installed remotely for bug fixes. While ostensibly a good thing, they do leave back doors open for malicious users to exploit.

Of course, it is not always about accessing data but also spying on people. For example, the increasing number of smart televisions in homes have seen some manufacturers pull data that shows what consumers are watching. Even worse, those sets with embedded Web cameras can also be hacked and used to look into the homes of people without them even realising it.

Getting smart

People are not cybersecurity experts. Many will not read the terms of use or technical documentation. It is all about using the connected device as quickly as possible. This is where the term ‘plug-and-play’ comes from – the manufacturer provides standard settings designed to make the device as easy as possible to use when it lands in front of a consumer.

Alexei Parfentiev, senior business analyst at SearchInform, believes a distinction should be made between IoT and the Industrial IoT (IIoT).

“The former is person-oriented and makes people’s life comfortable. The latter is developed for an industry and must be optimised.” Smart appliances, for example, help people save electricity or take care of their health. Within some industries, devices are used to automate menial administrator tasks, increase enterprise productivity, and let employees focus on more strategic roles.

Irrespective of whether it is consumer-facing or enterprise-focused, the reality is that IoT devices need better security. “Manufacturers must take responsibility to protect these devices and warn users of possible cybersecurity threats. Sadly, making the sale seems to be the only priority. But the situation might improve if vendors are motivated to take IoT security more seriously. For example, regulators could fine manufacturers if found guilty of neglecting their corporate responsibilities when it comes to securing devices.”

So, while it becomes inconvenient if a smart home system fails and the doors do not open automatically, imagine the impact if an armament system or power station is compromised. Security therefore has to be a priority in this new era of connected devices and the IoT.

For more information, go to www.condyn.net





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Quality fire detection installation at Baywear Clothing
G2 Fire Fire & Safety Industrial (Industry) Products & Solutions
JZL Projects and Solutions was asked to provide a comprehensive yet cost-effective and reliable fire detection solution for Baywear Clothing that would be installed with minimum disruption to the factory.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
Get proactive with cybersecurity
Information Security
The ability to respond effectively to a cybersecurity breach is critical, but the missing piece of the puzzle is a thorough, proactive evaluation to ascertain weaknesses and identify any hidden threats.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
How to securely manage your digital footprint
Information Security Training & Education
Managing your online presence is critical to safeguarding your privacy and security. It is imperative to take a proactive approach, including using robust cybersecurity best practices.

Read more...
The state of code security in 2024
Information Security
The 2024 State of Code Security survey reveals that organisations have continued to shore up application security defences over the last year, according to OpenText Premier Partner iOCO Application Management.

Read more...
What is the level of safety and integrity of the software supply chain?
Information Security IoT & Automation
Organisations are embracing AppSec practices and focusing on their software security posture. However, they highlight that insufficient funding and security resources, plus a disconnect between developers and security teams, remain major roadblocks.

Read more...
Cybercriminals target financial service providers to get at sensitive client data
Information Security
According to Ryan van de Coolwijk, Product Head for cyber at iTOO Special Risks, hackers target financial service providers because they hold sensitive client information that unauthorised individuals could use for fraudulent activities.

Read more...