The very term Internet of Things (IoT) can sound like the buzziest of buzzwords. We all know we need to be aware of and plan for it, but sifting through all the security guidance about the IoT can be overwhelming.

Moving Beyond Buzzwords

To help cut through the noise, IBM released a new report, “Smart Things Call for Smart Risk Management,” detailing five key facts about the IoT to help security teams build IoT security into their risk management program. Users and manufacturers of connected devices and solutions can take action to reduce security risks by understanding these basic facts about the IoT.

Security technology is usually most efficient and effective when it is built in during the design and implementation phases. To ensure systems are functioning as expected, even when under attack, IoT systems can be tested with red team experts and monitored by specialized IoT platforms.

Read the complete report: Smart things call for smart risk management

The Increasing Value of IoT Security

According to Gartner, the number of connected things in use worldwide will exceed 20 billion by 2020. As the IoT becomes more ingrained into everyday business and our personal lives, we will be increasingly dependent on the data, insights and value it brings. However, it is important not to take these contributions to business and society for granted.

One particular area of potential complacency is security: As IoT adoption and value increases, it becomes even more important to secure the investments made and benefits accrued.

IoT risks and vulnerabilities vary widely, from annoying security issues to potentially apocalyptic exposures. Devil’s Ivy for example, exploited a flaw on connected cameras that enabled perpetrators to view video feeds and block access. More serious threats included unpatched vulnerabilities in radiation monitoring devices (RMDs) that could be used by attackers to endanger critical infrastructure.

The traditional approach of air-gapped security controls is also at risk as devices and solutions become more connected. Supervisory control and data acquisition (SCADA) and industrial control system (ICS) technologies are now under threat from a growing list of malicious actors. Furthermore, innovation in medical practices and the application of IoT in health care highlights the importance of protecting sensitive personal data.

Learn More

At this year’s Black Hat, IBM announced the launch of two new security testing practice areas focused on automotive security and the IoT. The announcement emphasized the importance of a multipronged approach to IoT security. Access to X-Force Red penetration testing alongside the trusted Watson IoT Platform is of paramount importance to solution developers and adopters.

To learn more about building IoT security into your risk management program, read the IBM report, “Smart Things Call for Smart Risk Management.”

More from Risk Management

New Fakext malware targets Latin American banks

6 min read - This article was made possible thanks to contributions from Itzhak Chimino, Michael Gal and Liran Tiebloom. Browser extensions have become integral to our online experience. From productivity tools to entertainment add-ons, these small software modules offer customized features to suit individual preferences. Unfortunately, extensions can prove useful to malicious actors as well. Capitalizing on the favorable characteristics of an add-on, an attacker can leverage attributes like persistence, seamless installation, elevated privileges and unencrypted data exposure to distribute and operate banking…

Why federal agencies need a mission-centered cyber response

4 min read - Cybersecurity continues to be a top focus for government agencies with new cybersecurity requirements. Threats in recent years have crossed from the digital world to the physical and even involved critical infrastructure, such as the cyberattack on SolarWinds and the Colonial Pipeline ransomware attack. According to the IBM Cost of a Data Breach 2023 Report, a breach in the public sector, which includes government agencies, is up to $2.6 million from $2.07 million in 2022. Government agencies need to move…

Back to basics: Better security in the AI era

4 min read - The rise of artificial intelligence (AI), large language models (LLM) and IoT solutions has created a new security landscape. From generative AI tools that can be taught to create malicious code to the exploitation of connected devices as a way for attackers to move laterally across networks, enterprise IT teams find themselves constantly running to catch up. According to the Google Cloud Cybersecurity Forecast 2024 report, companies should anticipate a surge in attacks powered by generative AI tools and LLMs…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today