Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
7/26/2018
11:15 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Trend Micro Survey Confirms A Disregard for the Risk of an IoT Breach

LONDON--(BUSINESS WIRE)--Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global leader in cybersecurity solutions, today released survey findings that show businesses are most concerned about losing customer trust in the event of an Internet of Things (IoT) related cyber attack, however they remain unprepared. The survey, which was issued to 1,150 IT and security decision makers across the globe,1 indicates major discrepancy between the investment in IoT systems and security to protect them.

As the growing number of connected devices opens businesses up to additional cyber threats, close to half (43%) of IT decision makers and security decision makers say that security is an afterthought when implementing IoT projects (peaking at 46% in Germany). In addition, while nearly two-thirds (63%) agree that IoT-related cybersecurity threats have increased over the past 12 months (rising to 71% in the UK and the US), only about half (53%) think connected devices are a threat to their own organisation (75% in Japan).

Additionally, the results suggest there could be minimal testing taking place ahead of implementation to ensure new devices added to corporate environments are secured. The survey also showed businesses are experiencing an average of three attacks on connected devices in the last 12 months. Thirty-eight percent of those that have already implemented, or plan to implement, an IoT solution enlist security decision-makers in the implementation process. This falls to one in three for smart factory implementation (32%), with a similar proportion enlisting the help of security teams for the roll out of smart utility (31%) and wearables (30%) projects. This suggests that a significant proportion of businesses globally could be unwittingly opening themselves up to a range of threats.

“IoT systems are the future for businesses and many new types of connected devices are being introduced to corporate networks,” said Kevin Simzer, chief operating officer, Trend Micro. “While this is beneficial for business operations, the embedded operating systems of IoT devices aren’t designed for easy patching, which creates a universal cyber risk problem. The investment in security measures should mirror the investment in system upgrades to best mitigate the risk of a breach that would have a major impact on both the bottom line and customer trust.”

Security, responsibility, reputation, and business impact

According to businesses, the top consequences as a result of a breach include loss of customer trust (52%) closely followed by monetary loss (49%). Despite the recent introduction of GDPR making it top of mind for many, the following consequences were ranked significantly lower. Some of the areas businesses think an IoT breach would impact are:

  • Customer trust (52%)
  • Monetary loss (49%)
  • Loss of personally identifiable information (32%)
  • Being fined by regulators (31%)
  • Breaking data security regulations (28%)

With breaches having the potential for a significant impact on business operations – such as jeopardising GDPR compliance or taking critical networks offline – the research confirms that cybersecurity cannot be an afterthought and it must be key to the IoT implementation process from the offset.

Simzer at Trend Micro continued: “The significant investment in this technology across the globe is testament to the fact that IoT solutions can bring many advantages to businesses. But if security is not baked into the design of IoT solutions, and SDMs aren’t involved in the IoT implementation process, businesses could face damages far greater than the benefits this connected tech delivers.”

The findings show significant investment is going toward IoT systems, with businesses spending over $2.5 million on average each year. Given the substantial financial investment, and the significant impact to organizations that could come from a cyber attack against these systems, security must be equally prioritized to mitigate this risk.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Tough Love: Debunking Myths about DevOps & Security
Jeff Williams, CTO, Contrast Security,  8/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5638
PUBLISHED: 2019-08-21
Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user accou...
CVE-2019-6177
PUBLISHED: 2019-08-21
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Le...
CVE-2019-10687
PUBLISHED: 2019-08-21
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-11601
PUBLISHED: 2019-08-21
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
CVE-2019-11602
PUBLISHED: 2019-08-21
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.