Attacks/Breaches

10/19/2017
12:20 PM
50%
50%

IoT Deployment Security Top Concern for Enterprises

A new survey shows that 63% of respondents are worried about the impact of the Internet of Things on corporate security technologies and processes.

A majority of enterprises cite cybersecurity as their main concern with corporate Internet of Things deployments, according to a survey released this week commissioned by BlackBerry.

In the survey, which queried 200 IT decision makers, 63% of respondents cited security as their top concern about IoT technologies and processes in the enterprise, yet only 37% of participants said they had a formal digital strategy in place. A full 78% of respondents indicated interest in a solution that would allow them to manage all their endpoints in one place. Nearly two-thirds of respondents (61%) identified hackers and cyberwarfare as a major threat from the IoT.

"If a device isn’t secure, it shouldn’t 'work' for companies or consumers. Organizations that connect unsecured IoT devices to their network are ultimately putting attack vectors inside their company. The risk of losing their IP and customers’ information is not worth the reward or using an IoT device that simply works," says Marty Beard, chief operating officer for BlackBerry.

He adds that endpoint security is the most important aspect of IoT security because the endpoint is the easiest to attack and tends to be the place where employees will bypass security for convenience. 

Read more about the survey here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
10/20/2017 | 6:45:30 AM
Locking Down
IoT is definitely a major concern because there isn't a centralized mechanism for monitoring these devices even with MDM that will cover 100%. Smart devices outside of the realm of mobile typically have default to weak credentials making them easy points into the network if not segmented correctly.
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Empathy: The Next Killer App for Cybersecurity?
Shay Colson, CISSP, Senior Manager, CyberClarity360,  11/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Post a Comment
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15759
PUBLISHED: 2018-11-19
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perfo...
CVE-2018-15761
PUBLISHED: 2018-11-19
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges...
CVE-2018-17190
PUBLISHED: 2018-11-19
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code ...
CVE-2018-1841
PUBLISHED: 2018-11-19
IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.
CVE-2018-18519
PUBLISHED: 2018-11-19
BestXsoftware Best Free Keylogger 5.2.9 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\BFK 5.2.9\syscrb.exe" file because of insecure permissions for the BUILTIN\Users group.