TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»Why it’s So Hard to Implement IoT Security
    Cyber Security

    Why it’s So Hard to Implement IoT Security

    January 15, 2019Updated:January 15, 2019No Comments7 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Have you been attacked? Digitpol the global investigation firm can help you, visit Digitpol’s website to learn more.


    Harmonizing Security Across IoT Infrastructures that are Connected to Both Brownfield and Greenfield Systems is Easier Said Than Done

    The Internet of Things (IoT) is integrating the physical world and computer-based systems more and more through a vast network of electronics, software, sensors, actuators and connectivity. According to Statista, the IoT juggernaut is growing nearly 20-percent annually and on track to hit $8.9 trillion by 2020. All the while, a quarter of all IoT remains devoted to industrial settings — the Industrial Internet of Things (IIoT).

    Unfortunately, as the new opportunities for innovation, efficiency and convenience multiply, so do the IoT-related vulnerabilities and attack surfaces for malicious actors to exploit. And because cyber attacks take advantage of the weakest link in a chain, organizations can’t just pick and choose which IoT vulnerabilities to address — they have to deal with them all, in real-time. 

    The reality is: IoT security is a tough challenge — involving everything from hard to implement standards; hard to reach industrial components; and hard choices on how to integrate security seamlessly around both older “brownfield” and newer “greenfield” IoT systems and equipment.

    Lots of Guidance, but Not Enough of it is Practical

    IoT and IIoT security challenges range from insecure web and mobile interfaces and network services, to poor encryption, authentication and physical security. Especially in industrial settings, organizations are realizing they must address the entire IoT ecosystem, including: operational technology (OT) running on factory floors; new devices connected to IIoT cloud platforms; IT systems that link to business systems; new devices and sensors, and everything in between. 

    Groups like the National Institute of Standards and Technology (NIST) and International Society of Automation (ISA) have tried to help by issuing IoT and IIoT cybersecurity standards  — but such guidelines are complex, difficult to understand and hard to implement because they often lack clear implementation recommendations. Equipment manufacturers and integrators are left to determine how to achieve the appropriate safety, reliability, resilience and privacy for the requisite security levels for their devices. Oftentimes, this means that standards are not put into real-world practice because the perception is that they are too complex.

    The Trusted Computing Group’s TPM 2.0 standards, for instance, give guidance for embedding a unique secret key into microchips and firmware to help prove the identity of IoT devices, but the technical documentation runs more than 3,000 pages. 

    These challenges have left the industry unprepared for IoT-focused attacks. In fact, a recent survey found that 97 percent of respondents believe unsecured IoT devices represent a significant risk for their organizations.  

    The Industrial IoT is Especially Mission Critical — and Even Harder to Secure

    From Stuxnet in 2010, all the way to expanded Triton-style attacks of 2018, industrial systems have become prime targets — a fact that’s particularly troubling and consequential. While a data breach at Target or Equifax can be devastating and compromise the privacy and finances of millions of customers, a cyber attack on critical infrastructure can cause incalculable damage, operational breakdowns and even the loss of life. 

    Consider accidents like 1979’s Three Mile Island nuclear meltdown and the 2010 BP Deepwater Horizon Oil Spill; they may have both been accidents, but the control system breakdowns involved are the same kind that could easily be caused by a well-executed cyber attack. In fact, a purported 2014 hack at a German steel mill sabotaged a blast furnace — causing it to malfunction and create significant damage to the facility. 

    Keep in mind that, for refineries and some other complex industrial operations, emergency shutdowns can take a year or more to recover from. This means lost revenue, damaged reputations and even the possibility of bankruptcy. 

    Unfortunately, IIoT security is especially hard to implement. Many industrial components were built long ago and designed to run continuously. This makes it tough to retrofit systems for security; some industrial control systems have been in place for decades, with maintenance windows as fleeting as four hours every year.  

    The Right Approach to IoT Security  

    Enterprises are increasingly realizing that, to protect the organization and maintain operations, they must implement security across the entire IoT ecosystem — and especially in industrial settings.  

    A top challenge is to overlay security onto “brownfield” problem spaces involving older equipment and legacy systems. At the same time, it’s critical for manufacturers to bake in security from the beginning for new “greenfield” devices that are being developed. 

    Harmonizing security across IoT infrastructures that are connected to both brownfield and greenfield systems is easier said than done. On the brownfield side, some systems simply can’t be upgraded — meaning your only choice is to replace the system or find a way to place a secure gateway in front of it. Other brownfield elements may be incrementally upgraded with stronger authentication, more encryption or better web, mobile or physical security. On the greenfield side, security should be incorporated into the design of all the devices and components as early as possible in their development and production cycles. 

    Finally, developers should understand that even if a brand new system is stamped secure from the factory, its operational capacity could still be compromised if it’s going into an environment that doesn’t have security across the board.

    Implementing Better IoT Security in Your Own Organization

    By now, it should be clear that there’s no one-size-fits-all solution that someone can simply buy and turn on with the flip of a switch. Instead, IoT security is something that must be implemented with the right strategies and industry partnerships tailored to your organization and its vulnerabilities. 

    Whatever your specific implementation approach may be, it should involve a security stack that can address requirements across a diverse landscape of endpoints. Also, make sure your security solution is powerful enough to enhance security of storage, communications and containerized applications. And ensure any industrial devices meet requirements for US NIST 800-63B AAL3 — the highest level of authentication assurance. 

    Most of all, your ability to implement these high levels of security should not be bogged down by reams of complex standards and guidance manuals. The right industry partners can package up that complexity to ensure you’ve got the proper security and compliance in place — without drowning in documentation. Demand comprehensive security from your vendors that is still simple enough to understand and implement.

    Developing stronger IoT security has become a primary focus across all organizations —  especially those dealing with critical infrastructure. Whether you’re an equipment manufacturer or service provider, everyone benefits from a better understanding of the existing IoT security landscape, and how to strengthen it. 

    view counter

    Dean Weber is Chief Technology Officer (CTO) at Mocana. He previously served as director and CTO at CSC Global CyberSecurity, and CTO at Applied Identity, which was sold to Citrix. Earlier, he was Chief Security Architect at Teros; a manufacturer of application security gateways. He was responsible for developing and implementing solution deployments including assessment and intelligence gathering at TruSecure/ICSA Labs (now Verizon Business Security Solutions). Mr. Weber helped found a large Midwestern reseller-integrator specializing in secure architectural design and deployment for both public- and private-sector clients, and he served for many years as its technical vice president. Additionally, he spent several years in the U.S. Navy working in physical and electronic security.

    Previous Columns by Dean Weber:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.