IoT running wild compromises security

1 May 2017 Editor's Choice, Surveillance, Information Security

At the Genetec IP security seminar held in Midrand, Johannesburg recently, regional sales manager, Brent Cary said, “While Internet of Things (IoT) is growing at an unprecedented rate, new opportunities to access compromised data for cyber criminals is increasing due to a lack of network security.

Brent Cary – Genetec.
Brent Cary – Genetec.

“Constant connectivity and the rapid flow of information may offer new and convenient ways to do business and create value, but it also places the corporate network at significant risk. The reality is that your network is only as secure as the weakest piece of hardware or software on it,” says Cary.

Quoting the founder of Linux, Linus Torvalds, Cary added that ‘the only way real security is done is by a network of trust.’ He says there are four physical security actors, all of whom play a vital role in this network of trust:

• The end user, who will have an IT policy in place, should be conducting their own supplier risk assessment to know exactly what devices are sitting on their IT network.

• The consultant, who should be conducting the manufacturer risk assessment and informing the end-user of any possible risks associated with the suppliers.

• The system integrator should be following the Manufacturer Configuration Recommendations and Guides to Hardening Your Security System. (Free Genetec Download at https://www.genetec.com/about-us/news/blog/a-guide-to-hardening-your-security-center-system, short URL: www.securitysa.com/*genetec1.)

• And finally, the manufacturer, who has the responsibility to ensure they are secure by default; have a security development lifecycle; provide secure coding and testing procedures; offer a product security policy (security versus usability) and help educate their fellow actors as to how they are contributing to a more secure network.

Cyber criminals want valuable assets and intellectual property. Physical security data is not on the top of the assets at risk (e.g. video recording) and this might be the reason why, in the past, physical security systems placed less importance on cyber security. This is a weakness as the physical security system could be the entry point to access more critical assets.

“The loss is not just financial, cybercrime leads to a loss in confidence; brand compromise, loss of integrity and loss of customers. There is also the possibility of lawsuits and legal exposure, even ransom demands,” says Cary.

Globally, the threat has made itself real and Cary says that organisations are starting to take network security seriously. A recent PWC ‘Global State of information Security’ report found that over 91% of respondents follow a risk-based cybersecurity framework, but what was most interesting is the fact that 69% are moving to a cloud-based cybersecurity service.

“Companies are handing the responsibility to trusted advisors as opposed to trying to do it themselves. The reality is that there is a shortage of skills with service providers that are not adequately equipped to manage the complexity of a corporate network and increased cybercrime,” explains Cary.

He says Genetec is turning twenty years old this year and believes that the threat hasn’t changed, rather it has just evolved. But in South Africa there is work to be done: “Local businesses need to pay more attention to what the risks are on their IT networks. Very few, if any end-users have driven the conversation regarding cybersecurity, I have only had this brought up twice with the last 100 customers. This is way too few and is why education is critical to the market. The more people understand where the weaknesses are, the easier it is to secure the network.

“We are seeing growth within the subscription economy across all technologies, enabling customers to manage their security requirements on a Software-as-a-Service (SaaS) basis, which also includes support. This approach is encouraging interest from businesses in a variety of sectors and improving overall network security.”

For more information contact Brent Cary, Genetec, [email protected], www.genetec.com



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
South African fire standards in a nutshell
Fire & Safety Editor's Choice Training & Education
The importance of compliant fire detection systems and proper fire protection cannot be overstated, especially for businesses. Statistics reveal that 44% of businesses fail to reopen after a fire.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
LidarVision for substation security
Fire & Safety Government and Parastatal (Industry) Editor's Choice
EG.D supplies electricity to 2,7 million people in the southern regions of the Czech Republic, on the borders of Austria and Germany. The company operates and maintains infrastructure, including power lines and high-voltage transformer substations.

Read more...
Standards for fire detection
Fire & Safety Associations Editor's Choice
In previous articles in the series on fire standards, Nick Collins discussed SANS 10400-T and SANS 10139. In this editorial, he continues with SANS 322 – Fire Detection and Alarm Systems for Hospitals.

Read more...
Wildfires: a growing global threat
Editor's Choice Fire & Safety
Regulatory challenges and litigation related to wildfire liabilities are on the rise, necessitating robust risk management strategies and well-documented wildfire management plans. Technological innovations are enhancing detection and suppression capabilities.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.