TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

IoT at risk from hacks

by Mark Rowe

The expected growth of the global Internet of Things (IoT) market will lead to more security risks as hackers are presented with a greater surface area to compromise. This is according to Dave Worrall, CTO at Secure Cloudlink, a cloud security software company. He argues that passwords as a means of authentication have not been updated to cope with the rise of IoT and an increasingly digital economy. Hence, they must be eliminated from the IoT equation.

Dave Worrall says: โ€œWith any rapid technical revolution, such as IoT, security is often the last element to be updated. This, combined with the huge growth of cyber-crime and with lotโ€™s of newly connected devices, opens up a world of new opportunities for hackers, many of which the end user will be completely unaware of. There are counless scenarios where this will be the the case. Smart homes, that are filled with connected devices, are loaded with possibilities for hackers. Take a smart fridge for example, this will have access to personal information and, potentially, payment details. If itโ€™s authorsing payments on the usersโ€™ behalf, hackers can exploit this device and steal the userโ€™s credit card information. Smart buildings are another example. As these premises are controlled by IoT, as opposed to office maintencace staff, these buildings will be vulnerable to hacks, be it to gain illegal entry or to steal company data.

โ€œWhatโ€™s most worring is that some users will be completely unaware if they have fallen victim to a malicious hack, at least until it is too late. For instance, take a hacker targeting your bank account. By the time you realise that youโ€™ve been hacked or money has been moved, the hacker has gone. With IoT they will have used your fridge to deliver food somewhere else, told your car to get a service in a certain location and then stolen it, even emailed your childrenโ€™s school to tell them someone else is collecting them today. This is a distressing scenario that could, unfortunately, become a reality if IoT security is not taken seriously.

โ€œ2016 showed us that existing security features are not fit for purpose, with some of the biggest data breaches in history taking place. Considering that the increase in IoT will present hackers with a greater set of parameters to try and compromise, flaws within this form of technology must be addressed immediately before they spin out of control. To this end, the weaknesses of passwords will become even more apparent as they become proliferated across a larger number of connected devices.

โ€œPut simply, designs that were once appropriate have not been updated to keep up with todayโ€™s increasingly digital and connected economy. It only takes one password to compromise an entire IoT network, therefore changing this more regularly is simply not enough, especially considering that passwords are still one of the most common causes of data breaches. With the effectiveness of passwords continuing to deteriorate, whatโ€™s needed is a security solution that requires no passwords at all.

โ€œOnce the access mechanism is secured then the data transport mechanism must also be addressed. If you canโ€™t break into the IoT device then the data thatโ€™s transmitted between devices will be the next target. This must be securely encrypted. Too often product development timescales mean secure access, transport and communication is not addressed as standard layers of security create performance overheads which interfere with product functionality.โ€

Related News

  • Cyber

    CISO view

    by Mark Rowe

    Amy Lemberger, founder of The CISO Hub, argues that the real corporate cyber security issue is basic: no one senior is clearly…

  • Cyber

    Ransomware record year

    by Mark Rowe

    Last year was a record-breaker for ransomware activity globally, according to a cyber firm. Attacks rose 50 per cent year-on-year, reaching 7,874…

  • Cyber

    Respond from the outside-in

    by Mark Rowe

    As attack surfaces expand, security teams must respond from the outside-in, says Bharat Mistry, Director of Product Management, at the cyber firm…