The very term Internet of Things (IoT) can sound like the buzziest of buzzwords. We all know we need to be aware of and plan for it, but sifting through all the security guidance about the IoT can be overwhelming.

Moving Beyond Buzzwords

To help cut through the noise, IBM released a new report, “Smart Things Call for Smart Risk Management,” detailing five key facts about the IoT to help security teams build IoT security into their risk management program. Users and manufacturers of connected devices and solutions can take action to reduce security risks by understanding these basic facts about the IoT.

Security technology is usually most efficient and effective when it is built in during the design and implementation phases. To ensure systems are functioning as expected, even when under attack, IoT systems can be tested with red team experts and monitored by specialized IoT platforms.

Read the complete report: Smart things call for smart risk management

The Increasing Value of IoT Security

According to Gartner, the number of connected things in use worldwide will exceed 20 billion by 2020. As the IoT becomes more ingrained into everyday business and our personal lives, we will be increasingly dependent on the data, insights and value it brings. However, it is important not to take these contributions to business and society for granted.

One particular area of potential complacency is security: As IoT adoption and value increases, it becomes even more important to secure the investments made and benefits accrued.

IoT risks and vulnerabilities vary widely, from annoying security issues to potentially apocalyptic exposures. Devil’s Ivy for example, exploited a flaw on connected cameras that enabled perpetrators to view video feeds and block access. More serious threats included unpatched vulnerabilities in radiation monitoring devices (RMDs) that could be used by attackers to endanger critical infrastructure.

The traditional approach of air-gapped security controls is also at risk as devices and solutions become more connected. Supervisory control and data acquisition (SCADA) and industrial control system (ICS) technologies are now under threat from a growing list of malicious actors. Furthermore, innovation in medical practices and the application of IoT in health care highlights the importance of protecting sensitive personal data.

Learn More

At this year’s Black Hat, IBM announced the launch of two new security testing practice areas focused on automotive security and the IoT. The announcement emphasized the importance of a multipronged approach to IoT security. Access to X-Force Red penetration testing alongside the trusted Watson IoT Platform is of paramount importance to solution developers and adopters.

To learn more about building IoT security into your risk management program, read the IBM report, “Smart Things Call for Smart Risk Management.”

More from Risk Management

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

How cyberattacks on grocery stores could threaten food security

4 min read - Grocery store shoppers at many chains recently ran into an unwelcome surprise: empty shelves and delayed prescriptions. In early November, Ahold Delhaize USA was the victim of a cyberattack that significantly disrupted operations at more than 2,000 stores, including Hannaford, Food Lion and Stop and Shop. Specific details of the nature of the attack have not yet been publicly released.Because the attack affected many digital systems, some stores were not able to accept credit/debit cards, while others had to shut…

Taking the fight to the enemy: Cyber persistence strategy gains momentum

4 min read - The nature of cyber warfare has evolved rapidly over the last decade, forcing the world’s governments and industries to reimagine their cybersecurity strategies. While deterrence and reactive defenses once dominated the conversation, the emergence of cyber persistence — actively hunting down threats before they materialize — has become the new frontier. This shift, spearheaded by the United States and rapidly adopted by its allies, highlights the realization that defense alone is no longer enough to secure cyberspace.The momentum behind this…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today