Welcome to the age of inter-trustability

September 2016 News & Events

The concept of the Internet of Things (IoT) is getting a lot of airtime right now. The IoT is the global network of the future where everything is connected to everything. It’s not a future technology or idea, however, if you have a smart home or even a portion of a smart home, you’re already in an IoT world.

If you have a smart watch or fitness band, you’re also in this world and you probably have no idea who is able to access your information. In security speak, if your security systems are talking to each other, building management systems and human beings via a centralised platform, you’re already ‘IoTing’.

The real IoT, however, goes far beyond the above. In a smart city, for example, street lights, traffic lights (or robots in South Africa), manhole covers and highway gantries (if used competently for the benefit of the users, like that will ever happen) are all examples of ‘things’ that are going to be on the network, sending and receiving information. More than simply sending or receiving information, the things will be acting on information: a simple example would be switching on the heater when the temperature falls below a set level.

My belief is that the key to the IoT, its very foundation if it is to be successful, is security. Yes, IoT will require IT security skills, but IT security doesn’t cut it and IT security people don’t have the ability to handle IoT – they would pick it up easily, but it will be a learning curve. Physical security doesn’t have it either, we can’t even secure an IP camera. Can you imagine asking your financial director for more budget to firewall the air conditioner, or encrypt the controller that waters the garden at certain times of the day?

One of the key areas in which IoT differs from traditional information security is in scale. You are looking at a best-case scenario of having 10 times the number of devices than we currently have online, with more reasonable estimates 20 to 50 times the number. Your free antivirus package is not going to do you much good. For one, the daily updates will crash the Internet.

Another key area is the diversity in the IoT. A plane normally used to fly you overseas is a thing, as is an electronic component in your toaster, and these things aren’t always polite enough to speak IP. Especially in the industrial world, installations are designed to last for many years, not be replaced every three years, meaning you will face a variety of protocols. And doesn’t the security industry have enough issues with IP alone?

What we will require is a security foundation built into the IoT, with standard protocols that deliver ‘inter-trustability’ between devices. To gain our trust, IoT systems will have to build a chain of trust across a variety of devices, using hardware and software security solutions that form part of the core of each device, each platform they are connected to, and every other device.

The bolt-on security we try to use in today’s information-rich environment can’t manage that task. Simply consider your Windows operating system and the apparent ease with which almost anyone with a bit of technical knowledge can get the better of you. When running a nuclear power plant, you don’t want that type of risk – or at least I think most people in the developed world have realised this; a certain family that wants to build nuclear power stations in South Africa probably doesn’t care as long as their cut makes it to Panama.

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Fully-integrated browser AI
News & Events
Opera Mini now provides all its smartphone users with its own free built-in browser AI, Aria, including AI chat, Ask Aria and image generation. According to an Opera survey, 80% of South Africans want AI tools integrated into their browser.

Read more...
Amendments to the Private Security Industry Regulations
Technews Publishing Agriculture (Industry) News & Events Associations
SANSEA, SASA, National Security Forum, CEO, TAPSOSA, and LASA oppose recently published Amendments to the Private Security Industry Regulations regarding firearms.

Read more...
Local innovation driving excellence in FM
Securex South Africa News & Events
As organisations seek cost-effective, sustainable, and high-quality solutions, home-grown facilities management innovation is proving to be a critical driver of operational efficiency and long-term success.

Read more...
Local is a lekker challenge
Secutel Technologies Technews Publishing AI & Data Analytics
There are a number of companies focused on producing solutions locally, primarily in the software arena, but we still have hardware producers churning out products, many doing business locally and internationally.

Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.

Read more...
PIV-ready High Sec Controller 7000
News & Events
Gallagher Security announced the release of the latest addition to its controller product range; the High Sec Controller 7000, which incorporates all the core functions of the C7000 Standard variant released less than 18 months ago.

Read more...
The impact of GenAI on cybersecurity
Sophos News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.

Read more...
Lack of optimism for African economy
News & Events
African Leadership University publishes the 2025 Africa Workforce Readiness Survey, which shows that only 21% of South African employers are optimistic about the future of the country’s economy, the lowest of any country polled.

Read more...