Securing Overlooked IoT Devices from Cyber Criminals

Securing Overlooked IoT Devices from Cyber Criminals

When it comes to cybersecurity, many organizations overlook IoT devices; but it is imperative that they are given equal consideration, as these devices are connected to the internet (i.e. printers, security cameras and smart home hubs) and can serve as an open door for cyber criminals. According to cybersecurity and anti-virus provider, Kaspersky, 1.51 billion IoT breaches occurred from January to June 2021, with many cyber criminals exploiting the telnet remote access protocol. Keeping this in mind, a vital part in creating an effective cybersecurity plan is securing internet-enabled devices—especially in hybrid environments, with work being done both in the office and remote.

To protect against a cybersecurity incident, organizations must be aware of popular device vulnerabilities, develop strong security protection methods for devices, and provide ample cybersecurity training to employees. Education is the greatest tool at our disposal and being aware of the threats is the first step in a comprehensive security plan.

1. Understanding the Threat – Device Vulnerabilities and Exploits

IoT devices can often be overlooked when creating an effective cybersecurity plan, but due to their connection to the internet, any vulnerability in the device can act as a back door to the entire network. IoT devices are constantly being developed and utilized in workspaces, and the implementation of new devices that potentially lack security measures can create a dangerously open environment that can lead to unauthorized access to both new and legacy devices. Common vulnerabilities to address include:

  • Weak Password Management: The first vulnerability that cyber criminals exploit is the use of weak passwords for IoT devices. Default and guessable passwords are the largest weak spot for IoT security, with many individuals overlooking how a weak password for a device such as a printer can lead to larger scale attacks (i.e., DDoS and ransomware).
  • Lack of Consistent Updates to Devices: IoT devices can lack regular updates and patches to cyber vulnerabilities, which makes the device become more exposed over time. Devices can have strong security when first released, but once a vulnerability is realized by a malicious actor, the device then becomes vulnerable to the exploit until an update is released to patch the vulnerability.

2. Setting Safeguards for IoT Devices

Once organizations are aware of the security vulnerabilities of IoT devices, they can then move to creating safeguards to better protect their devices. Setting safeguards for IoT devices encompasses better password management, stronger cybersecurity practices, and proper education:

  • Use of Strong Credentials: Creating unique and strong credentials for every IoT device can increase the level of security. Utilizing a password management tool will then become paramount to creating strong passwords. Regularly updating passwords and using special characters can ensure that password security is consistently up to date.
  • Ensuring Regular Device Updates: IoT products have been exploited for their lack of regular updates to patch certain cybersecurity flaws, which creates an open door for malicious actors. Devices may be secure at first, but regular updates are needed to ensure that vulnerabilities may not be used to exploit devices. Organizations must consider the devices they purchase and thoroughly investigate if the company regularly updates the software to address any vulnerability that may be discovered. Communicating with manufacturers on device security and updates, as well as reporting vulnerabilities, will lead to a stronger cyber mainframe for connected devices.
  • Educating Staff in IoT Security: Taking the time to educate staff that use office IoT devices will provide another safeguard for the organization as a whole. When staff are aware of how IoT devices can be exploited and the signs to look out for when evaluating a cyber-incident, they can then take swift action to remedy the incident and collaborate to prevent further attacks.

3. Collaborating with Security Professionals to Continually Secure Devices

Now more than ever, with cyber criminals willing to utilize any vulnerability in an organization’s mainframe, it is important to collaborate with cybersecurity professionals to develop measures to secure the system. Leaders must work with security professionals to create a plan that provides best practices and guidelines that include how to help protect devices (such as up-to-date operating systems, browsers, and firewalls), multi-factor authentication, and data protection.  

Regardless of an organization’s cybersecurity strategies, hybrid work may continue to bring new and disruptive challenges. As a result, the scope of work for security professionals will become more robust, which makes it imperative for organizations and staff to work with cyber professionals and understand the daily risks. Cybersecurity professionals can help guide leadership and staff to implement and enforce new security policies, as well as work more strategically on a regular basis to help mitigate new and emerging threats.

About the Author

Mark Sinanian is Vice President of Marketing at Canon Solutions America. Mark began his career at Canon USA in 1985 as a Technician, where he first began his expertise in technology and security. Throughout his multi-decade long career at Canon, Mark has leveraged his insights in cybersecurity in thought leadership pieces, guiding how people and organizations can better secure their systems.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West 2024: Post-Show Recap

    ISC West 2024 is complete. And from start to finish, the entire conference was a huge success with almost 30,000 people in attendance. Read Now

    • Industry Events
    • ISC West
  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3