IoT
5/31/2017
11:59 AM
50%
50%

Most Security Pros Expect to Suffer Cyberattacks via Unsecured IoT

A new report shows the majority of security professionals believe within the next two years they will be victims of DDoS and other attacks due to unsecured IoT devices.

IT security professionals expect their companies' wireless printers to wireless thermostats and other IoT devices in the next two years to rebel against them in a big way as cyber attackers take advantage of vulnerabilities in the software and devices, according to a report released today by the Ponemon Institute.

The Internet of Things (IoT): A New Era of Third Party Risk report, which surveyed 553 risk management professionals, found that 94% of these security pros believe that in the next two years unsecured IoT devices and IoT applications will likely lead to a catastrophic event; data loss or theft (78%); DDoS attack (76%); and a cyberattack (76%).

As a result, companies need to track third-party IoT devices and IoT software connecting to their network and provide a way to centrally monitor their activities, according to Larry Ponemon, chairman and founder of the Ponemon Institute and the report's author, and Charlie Miller, senior vice president of Shared Assessments, which sponsored the report.

But less than half of the survey respondents say they monitor the risk of IoT devices used in the workplace. 

Source: Ponemon Institute

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

As for holding IoT third-party vendors accountable, Miller suggests it should be addressed in the vendor contract. But he admits that isn't easy: "Many rely on a contractual relationship for security. It is easy to say, but can be difficult to manage."

Ponemon suggests CISOs take several steps toward managing the security risks around IoT third-party devices and software.

"Currently, there are no standards, or processes, or checklists to reduce the risk of IoT," Ponemon says. "One of the first steps is around governance and figuring out who should own the responsibility of unsecured IoT devices and working with the third parties who bring in IoT."

The second step is to take inventory of all IoT tools and relationships that have business risks - like wireless printers or wireless security cameras - and establish IoT categories such as security that would include security cameras, rather than every camera.

And lastly, CISOs should consider creating specific policies and procedures for each category of IoT, Ponemon says. An IoT refrigerator poses a different security risk than an IoT printer, for example.

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

The report also shows that a vast majority of companies use traditional network firewalls and anti-malware software to guard their network from unsecured IoT devices and IoT applications:

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

Ponemon says while protecting the enterprise running IoT devices and applications, organizations also must avoid making security so difficult that it stops innovation or interferes with operations. 

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Meet 'Bro': The Best-Kept Secret of Network Security
Greg Bell, CEO, Corelight,  6/14/2018
Four Faces of Fraud: Identity, 'Fake' Identity, Ransomware & Digital
David Shefter, Chief Technology Officer at Ziften Technologies,  6/14/2018
Containerized Apps: An 8-Point Security Checklist
Jai Vijayan, Freelance writer,  6/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-5236
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.
CVE-2018-5237
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
CVE-2018-6211
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
CVE-2018-6212
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and incorrect proc...
CVE-2018-6213
PUBLISHED: 2018-06-20
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.