Story image

Here's why you need to be aware of the internet of things

03 Nov 2015

The rise of the internet of things is bringing new an exponential increase in security threats for both business and consumers as vulnerabilities in IoT devices are exploited.

Security vendor F-Secure says the proliferation of connected devices opens up innumerable security vulnerabilities that many people are unaware of.

Gartner has predicted that 4.9 billion connected things will be in use this year. With the global population at around 7.3 billion, this equates to more than one connected device for every two people on the planet – and it’s a number that is expected to increase exponentially.

Jonathan Banks, F-Secure ANZ director of operations, notes that connected devices are all around us – home heating systems, refrigerators, and smart televisions.

“They are beginning to affect every facet of our lives and make things easier and more convenient,” he says.

“However, the rise of the IoT also presents an exponential rise in security threats to businesses and individuals, as vulnerabilities in IoT devices are increasingly exploited by malicious cyber criminals.”

F-Secure says there are three reasons to pay close attention to the rise of the IoT and be aware of the potential threats that the connected devices present:

Threats are increasing The Australian Securities and Investments Commission issues a report earlier this year, noting that malicious cyber attacks on IoT devices are on the rise.

Meanwhile, an HP internet of things research study last year showed that 70% of the most 10 commonly-used connected devices contain serious vulnerabilities.

PricewaterhouseCoopers says the internet-connected devices that make up the IoT are vulnerable to attack because they lack the fundamental security safeguards that larger and more powerful connected devices are equipped with as a matter of course.

Says Banks: “Using smartphones as a point of control exacerbates IoT cyber threat risks because they are often unsecured.

“Cambridge University research shows that around 87% of the billions of Android smartphones globally have been exposed to at least one of 11 critical vulnerabilities.”

Smart cities are emerging At the same time, smart cities, in which connected devices are heavily used, are on the agenda for government and private enterprises alike, with IoT technology becoming a central element in public and civil infrastructure.

Examples include combining network-connected sensing and metering infrastructure with the existing electricity network to improve the efficiency of the electricity sector.

“Clearly, incorporating connected devices into this kind of infrastructure opens up the potential for vulnerabilities that malicious attackers can use to compromise public facilities, putting people and infrastructure at risk,” Banks says.

IoT data is becoming a big business As free online applications such as Gmail and Facebook have become more popular, the idea that data can be used as a lucrative commodity has come to the fore. Now, with individuals around the world adopting connected devices, IoT data is increasingly being collected and commoditised.

Device manufacturers, digital solutions providers and telecommunications companies use IoT data as a revenue source, which presents yet another security concern. As this data becomes more widely used by different companies for different purposes, the greater the potential for a data breach becomes.

“With so much IoT-derived data going around, all it takes is one weak link in the data chain for malicious criminals to obtain personal or sensitive user information, so it is vital to be diligent and careful about where your data goes and how it is treated,” Banks says.

On the road again: How to tackle mileage reporting for business
There may not be too much of a budget for company vehicles in an SMB’s day-to-day business, which means many people are increasingly using their own vehicles for work purposes.
Digital experience managers, get excited for Adobe Summit 2019
“Digital transformation may be a buzzword, but companies are trying to adapt and compete in this changing environment.”
HP extends laptop & workstation recall due to battery fire hazard
HP has extended its worldwide recall of several notebooks and mobile workstations due to the high risk of fire and burn hazards.
Privacy Bill may limit breach fines to $10,000
The Privacy Commissioner was seeking maximum breach fines of up to $1 million against body corporates.
Kathmandu breached, customer information accessed
Kathmandu is notifying potentially affected customers directly and has advised them to change their passwords for its online loyalty programme.
Was Citrix unaware of its own data breach until the FBI got involved?
According to a blog post from Citrix’s CSIO Stan Black, the FBI contacted Citrix on March 6 and advised that international cybercriminals had allegedly gained access to Citrix’s internal network.
How businesses can transform their customer experience in a realistic and timely way
“Businesses can’t simply decide to transform one day, then jump straight into making change for change’s sake."
Gartner: Marketing personalisation can be make or break
A Gartner survey shows brands risk losing 38% of customers because of poor marketing personalisation efforts.