Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - New Trustwave Report Shows Disparity Between IoT Adoption And Cybersecurity Readiness
Study & Research

New Trustwave Report Shows Disparity Between IoT Adoption And Cybersecurity Readiness

ISBuzz TeamBy ISBuzz TeamMarch 2, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Trustwave and Osterman Research Survey Reveals IoT Adoption and Security Practices are Misaligned

Trustwave today released the “IoT Cybersecurity Readiness Report” which assess the current and future use of Internet of Things (IoT) technologies and corresponding security practices and implementation challenges across organisations in a wide-range of industries. Astonishingly, although most organisations surveyed plan to increase adoption of IoT into operations, only 28 percent consider security strategies specific to IoT as “very important.”

Osterman Research conducted the survey on behalf of Trustwave, primarily with midsize and large organisations with a median of 1,000 employees per organisation. Individuals with applied security experience or knowledge were targeted. A total of 137 surveys were completed in November 2017.

Key findings from the Trustwave IoT Cybersecurity Readiness Report include:

  • IoT use is growing rapidly –Sixty-four percent of organisations surveyed have deployed some level of IoT technology, and another 20 percent plan to do so within the next 12 months. The result will be that by the end of 2018, only one in six organisations will not be using at least a minimal level of IoT technology for business purposes.
  • Security concerns cited as top barrier to increased IoT adoption– Although greater than half surveyed plan on increasing use of IoT technologies, 42 percent are either unsure or have no plans to increase use. Fifty-seven percent cite security concerns as the number one barrier to greater IoT adoption, followed by “not relevant to operations” at 38 percent and “lack of budget” at 27 percent.
  • Disparity between IoT use and security– Only 28 percent of organisations surveyed consider that their IoT security strategy is “very important” when compared to other cybersecurity priorities within the organisation. More surprising, however, is that greater than one-third believe that IoT security is only “somewhat” or “not” important.
  • Most have already experienced an IoT-related security incident– Sixty-one percent of those surveyed who have deployed some level of IoT technology have had to deal with a security incident related to IoT. While most of the reported incidents involved actual attacks – e.g., malware infiltration (24 percent of the organisations surveyed) and successful phishing and/or social engineering attacks (18 percent), some were merely attempted attacks, such as misconfiguration attacks (11 percent). Additionally, organisations can be attacked by IoT devices from outside sources even though they have no IoT devices deployed internally. Overall, most believe they will experience an IoT security problem in the future, with 55 percent believing it will happen during the next two years.

 

  • Lack of patching policies and procedures – Only 49 percent of organisations surveyed have formal patching policies and procedures in place, and only about one-third patch their IoT devices within 24 hours after a fix becomes available.
  • Insufficient risk assessment for third-party partners and testing of IoT vendors–  Fewer than one-half of organisations consistently assess the IoT security risk posed by third-party partners, another 34 percent do so only periodically, and 19 percent don’t perform third-party IoT risk assessment at all. In addition, only 70 percent of organisations perform their own security testing or piloting of these devices, only 54 percent use published reviews, and only 32 percent use third-party testing services. Many (47 percent) rely on vendors’ security claims.
  • Confidence in IoT security is not high– Only 10 percent of those surveyed are “very” confident that they can detect and protect against IoT-related security incidents, while 62 percent are only “somewhat” or “not” confident that they can do so. The combination of a low emphasis placed on IoT security, the sizeable proportion of organisations in which security incidents have already occurred and the perception that future security incidents are a virtual certainty leaves decision makers with little confidence that they can defend against IoT-related security incidents.

“Any device or sensor with an IP address connected to a corporate network may open the doors to a devastating security incident,” said Lawrence Munro, vice president SpiderLabs at Trustwave. “As IoT adoption continues to proliferate, manufactures of IoT are sidestepping security fundamentals as they rush to bring products to market. We are seeing lack of familiarity with secure coding concepts resulting in vulnerabilities, some of them a decade old, incorporated into final designs. Because updating IoT devices by nature is more challenging, many remain vulnerable even after patches are issued, and often patches are not even developed. Organisations need to properly document and test each internet-connected device on their network or face introducing potentially thousands of new attack vectors easily exploitable by cybercriminals.”

“Interestingly, the security of IoT was identified as the leading barrier to greater adoption”, noted Michael Osterman, principal analyst with Osterman Research. “There have been numerous IoT-related security problems in the recent past and the problems will only get worse until decision makers make security the key issue in their selection and deployment of IoT-related devices.”

Download Report

To download a complimentary copy of the “IoT Cybersecurity Readiness Report,” which includes recommendations by Trustwave security experts, visit: https://www2.trustwave.com/IoT-Security-Report.html

[su_box title=”About Trustwave” style=”noise” box_color=”#336588″][short_info id=’60896′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}