Internet of threats

Issue 9 2020 Information Security

Internet of Things (IoT) refers to any object or device that is connected to the Internet. This rapidly expanding set of ‘things’, which capture, send and receive data, includes cars, appliances, smart watches, lighting, home assistants, home security and more. It’s predicted that by 2025, there will be 41,6 billion units of IoT connected devices worldwide.

Internet-connected devices can make us more efficient, save time and money, and allow us connectivity from almost anywhere, but they also require that we share more information than ever.


Kabelo Makwane.

The security of this information, and the security of these devices, is not always guaranteed. Once a device connects to the Internet, it could be connecting to all sorts of risks. As the number of connected devices increases, especially as more people are working remotely with fewer security barriers at home, so do the possible entry points for cyber criminals. The IoT creates new security challenges for the IoT devices themselves, their platforms and operating systems, their communications, and even the systems to which they’re connected.

Protecting IoT devices, as well as their software, operating platforms and data, from the threat of a cyber-attack should be a number one priority for businesses and individuals, but all too often, we’re focused on the cost-effectiveness and convenience of IoT rather than its vulnerabilities. According to technology research firm Gartner, 25% of identified attacks in enterprises involve the IoT, although the IoT accounts for less than 10% of IT security budgets.

Simple steps in IoT security

The first step in device protection, whether it’s at home or in a business, is to identify the devices on your network and determine their risk profile. An IoT security solution with Next-Generation Firewall, like that of the Palo Alto Network or Check Point IoT, can do this for you, determining which IoT devices are not running endpoint protection, and safeguarding all of them regardless.

Botnets can scan for easily identifiable usernames and passwords to take control of a device. Changing a device’s factory security settings from the default username and password to something unique and as long as possible is a simple precaution in IoT device protection. Strengthening access control mechanisms and user authentication can ensure greater security to the IoT framework.

Tamper-proof precautions for hardware can restrict entry points, stopping attackers from taking control of a device or reaching important data. They can also offer additional security features to software-based solutions.

Attackers are always finding new methods to gain access to data stores and systems. Whether it’s your computer, smartphone, or other network devices, the best defence is to stay on top of things by updating to the latest security software, web browser, and operating systems. If you have the option to enable automatic updates to defend against the latest risks, turn it on.

Securing the network is important in preventing hackers form intercepting communications between the device and cloud application. In addition, device data should always be encrypted when it is being sent, to protect against attacks. Identity verification and multifactor-authentication to gain access to the network and the devices on the network, as well as the applications, to ensure that communication is not compromised.

Businesses need to see the whole picture

Many organisations traditionally have a decentralised line of action when it comes to cybersecurity, differing their tactics according to region, department and even product. However, as the IoT connects all parts of an operation in various ways and at vast scale, collecting a huge scope of data (some accessed by third parties), a more integrated and holistic stance to IoT cybersecurity is needed.

IoT cybersecurity in a business needs to fortify every layer of the IoT stack, at every level, and throughout a product’s life cycle, where there’s collaboration between other players and stakeholders in the industry to establish effective protection measures. Anticipating scenarios, prioritising points of risk, and having a ready-to-adapt response plan will also mitigate the fallout of a potential attack.

Integrated solutions include Fortinet, which can provide security across an entire infrastructure. Vodacom Business has advanced reporting capabilities that, when using the Fortinet FortiAnalyzer, gives customers both real-time alerts and historic reporting to better understand the types of attacks they are under and where they are being attacked from.

Cisco IoT Security Services Framework is another example of a solution that works through the entire value chain of a network, securing the technology (such as application, infrastructure and cloud security), the operational processes, and the people.

We can’t stop all cyberattacks from happening, but we can put proactive measures in place that mitigate threats to IoT devices, infrastructure, systems and valuable data. This is especially important in a business, where if IoT is secure, organisations can then truly maximise on the cost-saving, efficiency, and connectivity benefits of IoT.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Banking’s AI reckoning
Commercial (Industry) Surveillance Access Control & Identity Management Fire & Safety Perimeter Security, Alarms & Intruder Detection Information Security Asset Management News & Events Integrated Solutions Infrastructure Security Services & Risk Management Education (Industry) Entertainment and Hospitality (Industry) Financial (Industry) Healthcare (Industry) Industrial (Industry) Mining (Industry) Residential Estate (Industry) Retail (Industry) Transport (Industry) Conferences & Events Products & Solutions Associations Videos Training & Education Smart Home Automation Agriculture (Industry) Logistics (Industry) AI & Data Analytics Facilities & Building Management IoT & Automation Power Management
From agentic commerce disputes to quantum-powered risk modelling, SAS experts offer a ‘banker’s dozen,’ 13 industry-defining predictions that will separate institutions that master intelligent banking from those still struggling with the basics.

Read more...
Axis signs CISA Secure by Design pledge
Axis Communications SA News & Events Surveillance Information Security
Axis Communications has signed the United States Cybersecurity & Infrastructure Security Agency’s (CISA) Secure by Design pledge, signalling the company’s commitment to upholding and transparently communicating the cybersecurity posture of its products.

Read more...
Eight African cybersecurity trends for 2026
Information Security
Check Point Software Technologies has released eight critical trends shaping Africa’s digital turning point in 2026, noting that their implementation will require the government, the private sector, and key civic institutions to cooperate.

Read more...
The year of the agent
Information Security AI & Data Analytics
The dominant attack patterns in Q4 2025 included system-prompt extraction attempts, subtle content-safety bypasses, and exploratory probing. Indirect attacks required fewer attempts than direct injections, making untrusted external sources a primary risk vector heading into 2026.

Read more...
AI cybersecurity predictions for 2026
AI & Data Analytics Information Security
The rapid development of AI is reshaping the cybersecurity landscape in 2026, for both individual users and businesses. Large language models (LLMs) are influencing defensive capabilities while simultaneously expanding opportunities for threat actors.

Read more...
SMARTpod Talks to Check Point Technologies about the African Perspectives on Cybersecurity report
SMART Security Solutions News & Events Information Security Videos
SMART Security Solutions spoke with Check Point's Hendrik de Bruin about the report, the risks African organisations face, and some mitigation measures.

Read more...
Securing the smart fleet
Information Security Transport (Industry) Logistics (Industry) IoT & Automation
Contributing around 10 to 12% of South Africa’s GDP, the transport and logistics sector supports almost every part of the country’s economic activity. The stakes for keeping these systems secure are higher than ever before.

Read more...
Who are you?
Access Control & Identity Management Information Security
Who are you? This question may seem strange, but it can only be answered accurately by implementing an Identity and Access Management (IAM) system, a crucial component of any company’s security strategy.

Read more...
Check Point launches African Perspectives on Cybersecurity report
News & Events Information Security
Check Point Software Technologies released its African Perspectives on Cybersecurity Report 2025, revealing a sharp rise in attacks across the continent and a major shift in attacker tactics driven by artificial intelligence

Read more...
What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.