Internet of threats

Issue 9 2020 Information Security

Internet of Things (IoT) refers to any object or device that is connected to the Internet. This rapidly expanding set of ‘things’, which capture, send and receive data, includes cars, appliances, smart watches, lighting, home assistants, home security and more. It’s predicted that by 2025, there will be 41,6 billion units of IoT connected devices worldwide.

Internet-connected devices can make us more efficient, save time and money, and allow us connectivity from almost anywhere, but they also require that we share more information than ever.


Kabelo Makwane.

The security of this information, and the security of these devices, is not always guaranteed. Once a device connects to the Internet, it could be connecting to all sorts of risks. As the number of connected devices increases, especially as more people are working remotely with fewer security barriers at home, so do the possible entry points for cyber criminals. The IoT creates new security challenges for the IoT devices themselves, their platforms and operating systems, their communications, and even the systems to which they’re connected.

Protecting IoT devices, as well as their software, operating platforms and data, from the threat of a cyber-attack should be a number one priority for businesses and individuals, but all too often, we’re focused on the cost-effectiveness and convenience of IoT rather than its vulnerabilities. According to technology research firm Gartner, 25% of identified attacks in enterprises involve the IoT, although the IoT accounts for less than 10% of IT security budgets.

Simple steps in IoT security

The first step in device protection, whether it’s at home or in a business, is to identify the devices on your network and determine their risk profile. An IoT security solution with Next-Generation Firewall, like that of the Palo Alto Network or Check Point IoT, can do this for you, determining which IoT devices are not running endpoint protection, and safeguarding all of them regardless.

Botnets can scan for easily identifiable usernames and passwords to take control of a device. Changing a device’s factory security settings from the default username and password to something unique and as long as possible is a simple precaution in IoT device protection. Strengthening access control mechanisms and user authentication can ensure greater security to the IoT framework.

Tamper-proof precautions for hardware can restrict entry points, stopping attackers from taking control of a device or reaching important data. They can also offer additional security features to software-based solutions.

Attackers are always finding new methods to gain access to data stores and systems. Whether it’s your computer, smartphone, or other network devices, the best defence is to stay on top of things by updating to the latest security software, web browser, and operating systems. If you have the option to enable automatic updates to defend against the latest risks, turn it on.

Securing the network is important in preventing hackers form intercepting communications between the device and cloud application. In addition, device data should always be encrypted when it is being sent, to protect against attacks. Identity verification and multifactor-authentication to gain access to the network and the devices on the network, as well as the applications, to ensure that communication is not compromised.

Businesses need to see the whole picture

Many organisations traditionally have a decentralised line of action when it comes to cybersecurity, differing their tactics according to region, department and even product. However, as the IoT connects all parts of an operation in various ways and at vast scale, collecting a huge scope of data (some accessed by third parties), a more integrated and holistic stance to IoT cybersecurity is needed.

IoT cybersecurity in a business needs to fortify every layer of the IoT stack, at every level, and throughout a product’s life cycle, where there’s collaboration between other players and stakeholders in the industry to establish effective protection measures. Anticipating scenarios, prioritising points of risk, and having a ready-to-adapt response plan will also mitigate the fallout of a potential attack.

Integrated solutions include Fortinet, which can provide security across an entire infrastructure. Vodacom Business has advanced reporting capabilities that, when using the Fortinet FortiAnalyzer, gives customers both real-time alerts and historic reporting to better understand the types of attacks they are under and where they are being attacked from.

Cisco IoT Security Services Framework is another example of a solution that works through the entire value chain of a network, securing the technology (such as application, infrastructure and cloud security), the operational processes, and the people.

We can’t stop all cyberattacks from happening, but we can put proactive measures in place that mitigate threats to IoT devices, infrastructure, systems and valuable data. This is especially important in a business, where if IoT is secure, organisations can then truly maximise on the cost-saving, efficiency, and connectivity benefits of IoT.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Africa’s largest Zero Trust platform
NEC XON Information Security Commercial (Industry)
Africa has reached a significant cybersecurity milestone with the successful deployment of the continent’s largest Palo Alto Networks Prisma Access and Prisma Access Browser Zero Trust environment, supporting secure remote access for more than 40 000 users for a large enterprise in Africa.

Read more...
Supply chain attacks top threat over 12 months
Information Security
Supply chain attacks have become the most prevalent cyberthreat confronting businesses over the past year, according to a new Kaspersky global study, with nearly one-third of companies worldwide experiencing a supply chain threat in the past year.

Read more...
From vibe hacking to flat-pack malware
Information Security AI & Data Analytics
HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Microsoft 365 security is a ticking time bomb
Information Security
Across boardrooms and IT departments, a dangerous assumption persists that because data is stored in Microsoft 365 and Azure, it is automatically secure. This belief is fundamentally flawed and fosters a false sense of protection.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.