Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT

Most Security Pros Expect to Suffer Cyberattacks via Unsecured IoT

A new report shows the majority of security professionals believe within the next two years they will be victims of DDoS and other attacks due to unsecured IoT devices.

IT security professionals expect their companies' wireless printers to wireless thermostats and other IoT devices in the next two years to rebel against them in a big way as cyber attackers take advantage of vulnerabilities in the software and devices, according to a report released today by the Ponemon Institute.

The Internet of Things (IoT): A New Era of Third Party Risk report, which surveyed 553 risk management professionals, found that 94% of these security pros believe that in the next two years unsecured IoT devices and IoT applications will likely lead to a catastrophic event; data loss or theft (78%); DDoS attack (76%); and a cyberattack (76%).

As a result, companies need to track third-party IoT devices and IoT software connecting to their network and provide a way to centrally monitor their activities, according to Larry Ponemon, chairman and founder of the Ponemon Institute and the report's author, and Charlie Miller, senior vice president of Shared Assessments, which sponsored the report.

But less than half of the survey respondents say they monitor the risk of IoT devices used in the workplace. 

Source: Ponemon Institute

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

As for holding IoT third-party vendors accountable, Miller suggests it should be addressed in the vendor contract. But he admits that isn't easy: "Many rely on a contractual relationship for security. It is easy to say, but can be difficult to manage."

Ponemon suggests CISOs take several steps toward managing the security risks around IoT third-party devices and software.

"Currently, there are no standards, or processes, or checklists to reduce the risk of IoT," Ponemon says. "One of the first steps is around governance and figuring out who should own the responsibility of unsecured IoT devices and working with the third parties who bring in IoT."

The second step is to take inventory of all IoT tools and relationships that have business risks - like wireless printers or wireless security cameras - and establish IoT categories such as security that would include security cameras, rather than every camera.

And lastly, CISOs should consider creating specific policies and procedures for each category of IoT, Ponemon says. An IoT refrigerator poses a different security risk than an IoT printer, for example.

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

The report also shows that a vast majority of companies use traditional network firewalls and anti-malware software to guard their network from unsecured IoT devices and IoT applications:

Ponemon Institute

[Charts Source: Ponemon Institute and The Santa Fe Group, Shared Assessments Program] 

Ponemon says while protecting the enterprise running IoT devices and applications, organizations also must avoid making security so difficult that it stops innovation or interferes with operations. 

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8818
PUBLISHED: 2020-02-25
An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore...
CVE-2020-8819
PUBLISHED: 2020-02-25
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass ...
CVE-2020-9385
PUBLISHED: 2020-02-25
A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode generation.
CVE-2020-9382
PUBLISHED: 2020-02-24
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's } parser function.
CVE-2020-1938
PUBLISHED: 2020-02-24
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that ...