IoT
5/31/2017
11:59 AM
50%
50%

Most Security Pros Expect to Suffer Cyberattacks via Unsecured IoT

A new report shows the majority of security professionals believe within the next two years they will be victims of DDoS and other attacks due to unsecured IoT devices.

IT security professionals expect their companies' wireless printers to wireless thermostats and other IoT devices in the next two years to rebel against them in a big way as cyber attackers take advantage of vulnerabilities in the software and devices, according to a report released today by the Ponemon Institute.

The Internet of Things (IoT): A New Era of Third Party Risk report, which surveyed 553 risk management professionals, found that 94% of these security pros believe that in the next two years unsecured IoT devices and IoT applications will likely lead to a catastrophic event; data loss or theft (78%); DDoS attack (76%); and a cyberattack (76%).

As a result, companies need to track third-party IoT devices and IoT software connecting to their network and provide a way to centrally monitor their activities, according to Larry Ponemon, chairman and founder of the Ponemon Institute and the report's author, and Charlie Miller, senior vice president of Shared Assessments, which sponsored the report.

But less than half of the survey respondents say they monitor the risk of IoT devices used in the workplace. 

Source: Ponemon Institute

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

As for holding IoT third-party vendors accountable, Miller suggests it should be addressed in the vendor contract. But he admits that isn't easy: "Many rely on a contractual relationship for security. It is easy to say, but can be difficult to manage."

Ponemon suggests CISOs take several steps toward managing the security risks around IoT third-party devices and software.

"Currently, there are no standards, or processes, or checklists to reduce the risk of IoT," Ponemon says. "One of the first steps is around governance and figuring out who should own the responsibility of unsecured IoT devices and working with the third parties who bring in IoT."

The second step is to take inventory of all IoT tools and relationships that have business risks - like wireless printers or wireless security cameras - and establish IoT categories such as security that would include security cameras, rather than every camera.

And lastly, CISOs should consider creating specific policies and procedures for each category of IoT, Ponemon says. An IoT refrigerator poses a different security risk than an IoT printer, for example.

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

The report also shows that a vast majority of companies use traditional network firewalls and anti-malware software to guard their network from unsecured IoT devices and IoT applications:

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

Ponemon says while protecting the enterprise running IoT devices and applications, organizations also must avoid making security so difficult that it stops innovation or interferes with operations. 

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Now about that mortgage refinance offer from Wells Fargo .....
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3937
PUBLISHED: 2018-08-14
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability...
CVE-2018-3938
PUBLISHED: 2018-08-14
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST r...
CVE-2018-12537
PUBLISHED: 2018-08-14
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
CVE-2018-12539
PUBLISHED: 2018-08-14
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows,...
CVE-2018-3615
PUBLISHED: 2018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.