Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Poor security is holding back the Internet of Things

by The Gurus
September 22, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

The Internet of Things promises to connect products and industries – it’s in our cars, our cities and our homes, here to make our daily routine that little bit more convenient. The ongoing innovation by developers and manufactures, paired with the endless opportunity in the industry, shows to all that IoT certainly has huge headroom for growth.
However, with this eagerness to get hi-tech products to the masses, security models are unfortunately often overlooked and are fast becoming a major concern, holding back the rapid growth experts predict.
In recent years, there have been far too many privacy and security related incidents involving IoT devices. We’ve seen severe weaknesses in connected cars, prompting legislators to introduce legal security requirements for car manufacturers, to entire electrical grids and critical infrastructures suffering cyber-attacks through vulnerabilities in their computing systems.
Devices can be too easily modified and this opens up a variety of relatively easy avenues for attackers to try and find a way to exploit the hardware, seriously putting organizations’ private data and IP at risk and in turn destroying users’ privacy.
IoT risk vs. reward
Home automation systems are often found to be the most frequent to get hit with these cyber-attacks, as the audience they are targeted for are not tech savvy  and at point of purchase are not aware of any security issues. Hackers can manipulate and expose a whole host of flaws with many new pieces of technology that we welcome into our homes. For example, it was reported a cloud-based baby monitor service which allowed users access to the device over the internet, had a vulnerability allowing hackers to easily extract the device’s serial number, subsequently allowing hackers the access to other cameras. Flaws such as this could have been prevented simply by implementing an authentication scheme on a per-account basis, sometimes it’s even as simple as not changing the default admin password.
IoT supports devices from a large number of manufacturers, who will implement ‘backdoors’ they can access to make changes like firmware upgrades and remote diagnostics. However, unless field devices use mutual authentication or other encryption techniques, firmware updates can be compromised.  Even if individual devices are designed with device-level security, an interconnected architecture may still expose vulnerabilities.
Electronic devices in general have accessible interfaces such as JTAG ports and MAC addresses that provide an increased ‘attack surface’, making these devices highly vulnerable to invasive attacks that reverse engineer security. Devices that invariably share components and firmware across product lines could also allow a vulnerability detected in one system, to be exploited in another one using the same chipset.
Most IoT systems also have field sensors that can be subject to physical security issues. Critical sensors can malfunction if subjected to higher operating temperatures or voltage ranges, or they could simply be vandalized or even replaced with rogue devices connected to a cybercriminal’s Bot network.
Quite often, IoT devices are ‘watered down’ versions of more sophisticated systems, which may lead to vulnerabilities. For example, the consumer version of a thermostat made by an industrial HVAC manufacturer had security vulnerabilities not found in the industrial-grade version.
Protection and resilience
To ensure the public’s faith inIoT systems is not shaken to the detriment of future development, they must be designed to prevent attacks, be resilient under attacks and be able to detect and recover from such attacks. One example would be secure chips with secret keys, which can make it difficult for malicious actors to introduce rogue devices undetected. To make critical devices harder to reverse engineer, physical unclonable functions can be used to create unique identifiers that only exist when the chip is powered up.
When it comes to preventing attacks in the first place, identity is at the foundation of security – it’s equally important to create a robust and comprehensive notion of identity for IoT devices. Identity, analytics and visualization tools  will help gain insights,  via an easy-to-comprehend visual. These insights can also help create an advanced landscape of threats, especially for large-scale IoT systems.
Organisations are now taking notice of the security threats that come with IoT. With hackers constantly improving and developing new techniques to break down systems; IoT providers and industry bodies are working of a framework to allow sharing best practices as well as  creating ‘security standards’ to ensure vunerabilities are identified and recified before these devices are available on the market. This should help establish a robust security model for IoT, removing the bottleneck preventing the explosive growth that experts predicted – without putting users’ privacy at stake.
 
Author: DJ Singh, Digital Strategy Architect at Wipro Digital

ShareTweet
Previous Post

Intelligence sharing is a moral responsibility, say security professionals

Next Post

Employee access to social media poses biggest internal security threat to organisations and organised cybercrime poses biggest external threat, new research reveals

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol