• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

PRESSLED

Your Leading News Source

PRESSLED
Your Leading News Source

  • Home
  • BUSINESS
  • MONEY
  • POLITICS
  • REAL ESTATE
  • US
  • Meet the Reporters
  • About/Contact

IoT News – How Zero-Trust Should be Expanded to Include your Embedded Devices/IoT

May 29, 2021 by Staff Reporter

By Chris Rouland, Founder and CEO of Phosphorus.

Earlier this year, Ubiquiti, a Silicon Valley-based IoT device maker, disclosed that it had been hacked. Customer account credentials were exposed which allowed hackers to gain full access to all application logs, databases, user database credentials and information required to forge single sign-on (SSO) cookies. This level of access would allow the attackers to remotely authenticate to countless Ubiquiti cloud-based devices, putting customers’ devices, such as routers, network video recorders and security cameras, deployed in corporations and homes around the world at risk.

With an international presence in 200 countries and more than 85 million devices deployed, Ubiquiti had a colossal challenge on its plate. Once the vulnerabilities were identified and credentials were changed, customers were encouraged to reset passwords and implement two-factor authentication.

Security veteran, Brain Krebs recommended that all Ubiquiti customers change the passwords on any devices that haven’t been changed since January 11, 2021. He also suggested users delete any profiles on these devices, ensure devices have the latest firmware, re-create those profiles with new and unique credentials, and seriously consider disabling any remote access on the devices.

While this is a good first step, challenges exist on a mass scale at the enterprise level.

Automation in the Enterprise

On average it takes 4 hours per year to manually secure each device. If an organization has 40,000 devices, that nets out to 160,000 man-hours per year to keep those devices secure without automation. Automating basic security hygiene measures, including inventory management, patching and credential management, is crucial for IT teams not just when recovering from an attack but to harden the network and complete the basic security control conditions for defense-in-depth. In addition to helping IT teams keep pace with device proliferation, it is cost-effective, allows teams to focus on more important matters and be better protected against attack.

By automating device security, organizations can remove software bugs, malicious code, and increase performance of devices. Invest in a solution that automatically and periodically rotates credentials on your IoT devices to keep your things in compliance.

Secure the Networks with a Zero-Trust Approach

When thinking about the zero trust model, CIOs often prioritize the network and the cloud, but ignore devices. They are often overlooked or thought to be a smaller part of the pie, however, devices actually make up about 43% of the access points. Organizations that are not including devices as the third prong in their zero-trust strategy are leaving themselves massively vulnerable.

In many cases, it is unlikely IT teams are able to manually track all IoT devices in an organization. However, a zero-trust model must ensure that unknown and unwanted devices cannot gain access to the network. The zero-trust approach reinforces that not all devices are automatically trusted, and constantly checks and re-checks each user when trying to access data. With all these t new IoT devices that touch nearly every aspect of the workplace connecting to the network, the potential attack surface is greatly widened. Without including IoT devices as the third prong in a zero-trust strategy, organizations are spending millions on security but still leaving networks vulnerable by not including IoT in that strategy.

With IoT devices being used in nearly every industry and McKinsey estimating that 127 devices hook up to the internet for the first time every second, organizations need to be better aware of and prepared for the increasing attack surface. Including IoT devices in your zero-trust strategy and ensuring that basic hygiene measures are taken care of will greatly harden your network and protect against vulnerabilities that may arise from IoT device manufacturer hacks, like what happened with Ubiquiti.

About the author: Chris Rouland is founder and CEO of Phosphorus. He is a renowned leader in cybersecurity innovation and has founded several multi-million dollar companies, including Bastille, the first to enable assessment and mitigation of risks of the Internet of Radios, and Endgame, the leader in endpoint security. He was also Chief Technology Officer and “Distinguished Engineer” for IBM and Director of the X-Force for Internet Security Systems. Chris holds a 20+ patents and a Masters’ Degree from Georgia Institute of Technology.

>>>ad: Don't Miss TODAY'S BEST Amazon Deals!

Originally Appeared Here

Filed Under: BUSINESS

Primary Sidebar

More to See

Entrepreneurs mourn loss of Tech Nation

The UK tech community has reacted with an outpouring of shock and sadness upon learning that Tech Nation, the entrepreneur network that has supported … [Read More...] about Entrepreneurs mourn loss of Tech Nation

Live news updates from February 1: Fed lifts rates 0.25 points, Eurozone inflation slows sharply

© APFedEx will cut more than 10 per cent of its global leadership team, adding to the more than 12,000 employees it has shed over the past seven … [Read More...] about Live news updates from February 1: Fed lifts rates 0.25 points, Eurozone inflation slows sharply

N.J. town votes to let redevelopment of former Lord & Taylor site move forward

The Westfield Town Council voted 7-1 on Tuesday to introduce an ordinance that allows for a downtown redevelopment plan to move forward.It will next … [Read More...] about N.J. town votes to let redevelopment of former Lord & Taylor site move forward

Privacy Policy | Terms and Conditions | About/ Contact
Copyright © 2023 · PRESSLED · As Amazon Associates we earn commissions from qualifying purchases · Log in

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT