Partner Perspectives  Connecting marketers to our tech communities.
12/5/2016
01:55 PM
Jonathan Anderson
Jonathan Anderson
Partner Perspectives
50%
50%

Protect Your Company From Hackable Holiday Gifts

This holiday season promises to be full of devices, apps, and connectivity. Planning and executing appropriate security precautions now will save your business from a serious breach later.

Every year new toys, games, and devices come out with increasing levels of Internet connectivity. Some of these lack fundamental security precautions and end up on the Most Hackable Holiday Gifts list. After the holidays, some of these devices will end up in the office, used by employees for their work as part of your BYOD policy, or brought in to share, show off, and play with. In addition to providing entertainment for the office, they also present risks to your data and systems.

The vast majority of people start using their new devices soon after they open them. However, fewer than half follow appropriate security measures such as changing default configurations and passwords, installing critical updates, or adding security software. Here’s a look at this year’s most hackable holiday gifts.

Bring Your Own Device

Laptops, tablets, and smartphones top the list of this year’s hackable gifts, and more than 50% of consumers surveyed by Intel Security plan to purchase at least one of these devices. While readily hackable in their default form, most organizations are well protected against threats from these devices, blocking them from the corporate network or quarantining them on an isolated network segment unless they meet the corporate security standard.

Media Players

Media players and streaming sticks are becoming popular and will likely make it into the office as people use them to stream music, watch TV shows, or use them to easily connect their devices to corporate monitors. Employees will connect them to the office Wi-Fi network, not realizing the potential risk of an unsecured device or the vulnerabilities of older, unpatched software. Again, blocking access to unauthorized devices or restricting them to an isolated network segment is the best defense.

Home Automation

Controlling things around the house, from thermostats to door locks, is another growing market that may not show up on your risk assessment. However, these devices are connected to the Internet through home routers and may provide attackers with a path into your company when employees work from home. Hackers and security researchers have already demonstrated that they can compromise some of these devices. In addition, employees will be checking on their smart home devices from the office, frequently visiting third-party websites and using smartphone apps with uncertain security profiles. Completely blocking access to these tools will likely cause a backlash from employees. Web gateways, data loss prevention, and network traffic analysis will be necessary to detect and prevent breaches, data exfiltration, or credential theft from compromised home automation sites.

Drones

Whether used for fun or for business, you can pretty much guarantee that a drone will be passing through your business in the next 12 months. Wireless connectivity, smartphone apps, and even the onboard software all present potential threats to your information security. Again, blocking access to unauthorized devices or restricting them to an isolated network segment is the best defense. However, if your employees are using these devices for business purposes such as promotional videos or aerial photos, they may end up connected to the core network. Additional precautions then become necessary, including ensuring software versions are up to date, changing default passwords, and installing appropriate security controls.

This holiday season promises to be full of devices, apps, and connectivity. Planning and executing appropriate security precautions now will save your business from a serious breach or cyberattack later and still allow your employees to enjoy their new toys. Learn more about the McAfee Most Hackable Holiday Gifts list and follow us @IntelSecurity

Jonathan Anderson is responsible for technical strategy and integrating security into future IoT solutions at Intel Security. Prior to joining Intel, he served 14 years across both Cisco and HP where he continuously interlocked with customers, sales force, and product teams ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Want Your Daughter to Succeed in Cyber? Call Her John
John De Santis, CEO, HyTrust,  5/16/2018
Don't Roll the Dice When Prioritizing Vulnerability Fixes
Ericka Chickowski, Contributing Writer, Dark Reading,  5/15/2018
Why Enterprises Can't Ignore Third-Party IoT-Related Risks
Charlie Miller, Senior Vice President, The Santa Fe Group,  5/14/2018
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Security through obscurity"
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11232
PUBLISHED: 2018-05-18
The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrectly used as a local variable.
CVE-2017-15855
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, the camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer, which resides in u...
CVE-2018-3567
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WLAN while processing the HTT_T2H_MSG_TYPE_PEER_MAP or HTT_T2H_MSG_TYPE_PEER_UNMAP messages.
CVE-2018-3568
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, in __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur.
CVE-2018-5827
PUBLISHED: 2018-05-17
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in WLAN while processing an extscan hotlist event.