IoT
5/31/2017
11:59 AM
50%
50%

Most Security Pros Expect to Suffer Cyberattacks via Unsecured IoT

A new report shows the majority of security professionals believe within the next two years they will be victims of DDoS and other attacks due to unsecured IoT devices.

IT security professionals expect their companies' wireless printers to wireless thermostats and other IoT devices in the next two years to rebel against them in a big way as cyber attackers take advantage of vulnerabilities in the software and devices, according to a report released today by the Ponemon Institute.

The Internet of Things (IoT): A New Era of Third Party Risk report, which surveyed 553 risk management professionals, found that 94% of these security pros believe that in the next two years unsecured IoT devices and IoT applications will likely lead to a catastrophic event; data loss or theft (78%); DDoS attack (76%); and a cyberattack (76%).

As a result, companies need to track third-party IoT devices and IoT software connecting to their network and provide a way to centrally monitor their activities, according to Larry Ponemon, chairman and founder of the Ponemon Institute and the report's author, and Charlie Miller, senior vice president of Shared Assessments, which sponsored the report.

But less than half of the survey respondents say they monitor the risk of IoT devices used in the workplace. 

Source: Ponemon Institute

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

As for holding IoT third-party vendors accountable, Miller suggests it should be addressed in the vendor contract. But he admits that isn't easy: "Many rely on a contractual relationship for security. It is easy to say, but can be difficult to manage."

Ponemon suggests CISOs take several steps toward managing the security risks around IoT third-party devices and software.

"Currently, there are no standards, or processes, or checklists to reduce the risk of IoT," Ponemon says. "One of the first steps is around governance and figuring out who should own the responsibility of unsecured IoT devices and working with the third parties who bring in IoT."

The second step is to take inventory of all IoT tools and relationships that have business risks - like wireless printers or wireless security cameras - and establish IoT categories such as security that would include security cameras, rather than every camera.

And lastly, CISOs should consider creating specific policies and procedures for each category of IoT, Ponemon says. An IoT refrigerator poses a different security risk than an IoT printer, for example.

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

The report also shows that a vast majority of companies use traditional network firewalls and anti-malware software to guard their network from unsecured IoT devices and IoT applications:

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

Ponemon says while protecting the enterprise running IoT devices and applications, organizations also must avoid making security so difficult that it stops innovation or interferes with operations. 

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Microsoft, Mastercard Aim to Change Identity Management
Kelly Sheridan, Staff Editor, Dark Reading,  12/3/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20009
PUBLISHED: 2018-12-10
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
CVE-2018-20010
PUBLISHED: 2018-12-10
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
CVE-2018-20011
PUBLISHED: 2018-12-10
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
CVE-2018-20012
PUBLISHED: 2018-12-10
PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.
CVE-2018-20015
PUBLISHED: 2018-12-10
YzmCMS v5.2 has admin/role/add.html CSRF.