Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Challenges of IoT in the Workplace
Articles

Challenges of IoT in the Workplace

Sarah LahavBy Sarah LahavDecember 11, 2015Updated:January 24, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Internet of Things (IoT) has been the subject of industry analyst, and tech-media, excitement for just about forever. From an IT security perspective, cyber-criminals must be rubbing their hands together in excitement when they read that the US Federal Trade Commission estimates there now to be twenty-five billion devices online, with separate HP research stating that that 70% of IoT devices are insecure. And as such, there are a number of IoT risks that corporate IT departments, and consumer users, need to consider and address.

  1. IoT devices are as unsecure as you let them be. There might not be sufficient security functionality embedded within the IoT device, due to a lack of local resources or capacity. This will of course change over time, but for now it needs to be addressed and security might instead need to reside within the web service in front of the device. IoT vendors must do more to build security into their products; and corporate IT departments and consumer customers need to vote with their wallets and put security over convenience and price when buying IoT devices. Cheap, ubiquitous, and insecure IoT devices are ultimately the cyber-criminal’s best friend.
  2. IoT devices are entry points to corporate networks. Poorly secured IoT devices, on a corporate network with known, or easily guessed, passwords and passcodes, are the perfect entry point for cyber-criminals. If the device is a router or another kind of control or network device, then it’s even better for criminals because they can modify the firewall and other network services to their nefarious ends. And even if the IoT device is deemed a risk-free end-point, for example an internet-connected fridge, there are potential exploits because internet-connected white goods still have susceptible functions such as sending emails. So corporate IT departments, and consumer users, need to lock down their IoT devices – locking down admin rights and changing default passwords, adding in as much complexity as possible. There is also the need to think about defense in more depth, putting IoT devices on a firewalled, and possibly non-routable, network.
  3. IoT control devices can be hijacked for criminal activity. Medicine is an exciting opportunity for IoT, not just for passively collecting patient observations but also controlling medical devices, in real-time, in response to collected observations. Imagine a heart-monitor constantly sending heart data to a system that analyzes it, along with blood oxygen levels and other data, and decides to modify one of the control units – maybe to deliver a drug to the patient. In the wrong hands, this set up could be a death-dealing device. Access to other IoT devices can offer cyber-criminals control over your life, especially keyless entry systems for your house, garage, gate, or car that can be cloned to give the criminal physical access. Only choosing IoT products with proven security credentials, which are likely to cost more than the weak ones, is essential as is the ongoing secure installation and management.
  4. Convenience and price is put ahead of security. IoT device vendors might want to give consumers an Apple-like experience, of simplicity and convenience, or they might want to compete based on price. Both strategies can be at the expense of security. Plug-and-play without configuration should not be possible – there needs to be some configuration by the consumer because they at least need to program the IoT device with a passcode or password that only they know. If you can just plug a device into your corporate or home network with no configuration, then you have likely unwittingly created an opportunity for a cyber-criminal.
  5. Forgotten IoT devices are secret doors to your network. People, especially corporate IT departments with huge asset estates, can forget about older or unused devices, and some of these devices will be IoT-enabled. These devices might not be monitored or maintained but they will remain on the network and will potentially become risks over time; as security exploits are found and patches produced, these forgotten IoT devices will never be patched. Once an attacker finds such a device they will find a way to hijack it.

So while the IoT offers a great deal of business and consumer-world opportunity, both corporate IT organizations and home users need to ensure that they are aware of, and mitigate, the risks associated with IoT devices.

[su_box title=”About Sarah Lahav” style=”noise” box_color=”#336588″]Sarah LahavSysAid Technologies’ first employee, Sarah is now CEO and a vital link between SysAid and its customers since 2003. As CEO, she takes a hands-on role evolving SysAid with the dynamic needs of service managers. Previously, Sarah was VP Customer Relations at SysAid and developed SysAid’s Certification Training program, advancing the teaching methods and training technology that is in place today.
Sarah holds a B.Sc. in Industrial Engineering, specializing in Information Technology from The Open University in Israel, and spends her free time with her three beautiful children.[/su_box]

Sarah Lahav

CEO, SysAid Technologies

  • Sarah Lahav
    5 New Year’s Resolutions for IT Professionals
  • Sarah Lahav
    6 Technology Predictions for 2016
  • Sarah Lahav
    Future of Cloud Computing
  • Sarah Lahav
    BYOD Advice for CIOs

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}