Blog

Thought Leadership

IoT security: The threat before us

IoT security: The threat before usDefault blog imageDefault blog image
30
Sep 2021
30
Sep 2021

Attackers are increasingly gaining footholds into corporate environments to conduct ransomware or data theft operations via Internet-connected smart devices. Whether they be printers, lockers, aquariums, or conference rooms, these seemingly innocuous access points to corporate environments can provide attackers the critical initial access to conduct their attacks. These can also often be blind spots for many security teams.

When dropped into an organization’s digital environment for the first time and learning its surroundings, Darktrace often finds 15–20% more devices than anticipated. Most of these unexpected devices and areas of unsecured vulnerability result from an influx in IoT-enabled tech. This growing dependence on IoT devices will only continue to accelerate. There are currently more than 10 billion active IoT devices. This number is estimated to surpass 25.4 billion in 2030, though, by Darktrace’s predictions, it will in fact be much higher. We assess that almost all estimates around IoT usage by 2025 are too low.

As a result of the COVID-19 pandemic and hybrid work, the future workplace environment will only become more hands-free and interconnected. Broad adoption of 5G will not only mean more IoT devices, but also expanded capabilities as they become more efficient and highly connected.

People can walk in with an Internet-connected device on their wrist, or a security problem can enter a company through a newly updated Internet-connected vending machine. IT teams do not always know these devices are “smart” or vet them like they would with standard company technology.

IoT device manufacturers do not have a record of prioritizing the security of their devices, often sacrificing it for access and convenience, placing the burden on company security teams after the fact. Starting with one of these IoT devices that are typically not reinforced with security protocols makes it easier for a hacker to move laterally. Much like the threat from supply chains, it is easier for a hacker to go through an open window than a locked, guarded front door.

IoT compromise frequently appears as a lead threat across Darktrace’s global SOC operations. We have seen IoT devices intentionally brought into a corporate environment and used by an insider because of their small size, low signature, and capabilities, making them a powerful tool to evade traditional security defenses focused on external and known threats. Darktrace has even discovered crypto-mining malware on a door sensor, showcasing how creative attackers can get and all the different ways unsecured IoT can be misused.

IoT security is critical to prevent hackers from moving laterally throughout a company network. If hackers can breach one device within an organization’s digital environment, they can move to more critical devices with more sensitive data.

The good news is that security teams aren’t without resources to defend their environments. The first thing corporations need to have is a policy around IoT usage and adoption. The next and often most challenging step is increasing visibility and understanding of these shadow devices the instant they connect to the network in the first place. To meet this mission, some security teams use AI to identify the device and map ‘normal’ behaviors, then enforce a device’s behavior to disrupt any attacker’s efforts to use that device as an attack platform. Leveraging AI in this way also reduces the workload on already taxed security teams.

From a broader policy perspective, in tandem with internal security efforts, more pressure needs to be put on IoT manufacturers to make security a priority and part of the entire development and upgrade process. Disrupting attacks and hardening environments from attacker access points and attack vectors is everyone’s responsibility.

More in this series:

No items found.

Like this and want more?

Receive the latest blog in your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
INSIDE THE SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
AUTHOR
ABOUT ThE AUTHOR
Marcus Fowler
SVP, Strategic Engagements and Threats

As SVP of Strategic Engagements and Threats, Marcus works closely with senior security leaders across industries on cyber security strategy and business resilience, including across Darktrace’s Federal Division. Marcus focuses his research and analysis around emerging and next generation cyber threats, trends, and conflicts. Prior to joining Darktrace in 2019, Marcus spent 15 years at the Central Intelligence Agency developing global cyber operations and technical strategies. He has led cyber efforts with various US Intelligence Community elements and global partners. Prior to serving at the CIA, Marcus was an officer in the United States Marine Corps. Marcus has an engineering degree from the United States Naval Academy and a Masters’ Degree in International Security Studies from The Fletcher School. He also completed Harvard Business School’s Executive Education Advanced Management Program.

share this article
COre coverage

Good news for your business.
Bad news for the bad guys.

Start your free trial

Start your free trial

Flexible delivery
You can either install it virtually or with hardware.
Fast install
Just 1 hour to set up – and even less for an email security trial.
Choose your journey
Try out Self-Learning AI wherever you most need it — including cloud, network or email.
No commitment
Full access to the Darktrace Threat Visualizer and three bespoke Threat Reports, with no obligation to purchase.
For more information, please see our Privacy Notice.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get a demo

Flexible delivery
You can either install it virtually or with hardware.
Fast install
Just 1 hour to set up – and even less for an email security trial.
Choose your journey
Try out Self-Learning AI wherever you most need it — including cloud, network or email.
No commitment
Full access to the Darktrace Threat Visualizer and three bespoke Threat Reports, with no obligation to purchase.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Check out this article by Darktrace: IoT security: The threat before us