Posted in

Five Skillsets Needed for Securing IoT Today

On October 21, 2016 a sophisticated Distributed Denial-of-Service (DDoS) attack was launched that left customers of Amazon, Netflix, Twitter, and more without service, multiple times throughout the day.  TechTarget reported that the attack was leveled against Dyn, a Domain Name System (DNS) provider that services those brands, along with many others.  One of the contributing factors to the attack was that the hackers were able to infect Internet of Things (IoT) devices with the Mirai botnet. They were able to identify IoT devices that used default usernames and passwords (such as username: admin, password: admin ), and turn them into drones in their DDoS cyberattack.

John Pironti, president of IP Architects, went on to explain to TechTarget, “The use of IoT devices for recent DDoS attacks has shown how fragile and insecure many of these devices currently are ¦. The first use was for DDoS, but these same devices are likely to be used as entry points to the internal networks they connect to as well as they become more pervasive.”

Gartner projects that 20 billion IoT devices will be used by companies worldwide by 2020. This added mobility and productivity also brings the promise of multiplied threat vectors and vulnerabilities. If companies are to guard against the upcoming threat, innovative approaches to data security need to be adopted. CompTIA, the IT professional association, recently published their Evolution of Security Skills. In it they lay out crucial skillsets that your IT and IS teams should master to fully realize cybersecurity for your integrated environment.

Shift from Defense to Offense

For CompTIA, companies face the challenge of learning new skillsets as they navigate through a myriad of constant, evolving threats.  Companies, in their view, must shed the mentality of trying to prevent all attacks.  This is an impossible challenge.   Organizations must shift to proactive measures, including external audits, penetration testing, and security training. Strong defenses will always play a role, but they must be coupled with ongoing offensive activity.

This means routinely testing your network.   Learn from other recent data breaches in, and out of, your vertical industry and test to see how your system responds.  What vulnerabilities are you able to uncover?  What attack surfaces are exposed? Are you fully prepared to respond to the attack?

The more you test, shore up, and test your network again; the more you will be prepared for when an attack happens.  

Refine Your Arsenal of Data Security Tools/Skillsets

Beyond going on the offensive, CompTIA goes on to list skillsets and tools that are of growing importance for data security.  Below is a curated list of some of the tools and skillsets that I feel should become part of your standard arsenal.  Although CompTIA lists more (and in some cases does not call some of these out directly), I felt these were especially worth mentioning:

  • Credential Management: unique, strong passwords should be required for all devices and users with the password lifecycle managed with a password management system.

  • Authentication: Each device and user should be authenticated when signing onto the network.  Multi factor authentication should be used for users and blockchain is showing real promise as a trustless way to authenticate devices, even after long periods of non-use.

  • Encryption: There are two types of data; data that someone wants to steal and everything else.  If it is the former, encrypt it.  Both data-in-flight and data-at-rest – encrypt it.

  • Encryption Key Management:  Encryption is only strong if the key is kept safe.  If the key is compromised, the data is lost.  That is why every encryption project should include, robust, centralized encryption key management.

  • Real-Time Monitoring: Most networks are compromised days, even months before an actual breach happens. By monitoring security logs, in real time with a SIEM, it could mean the difference mitigating an attack or dealing with a major breach of data.  Here, also, is where blockchain could play a role.  Since blockchain is an immutable, distributed ledger (in this case of security logs), if deployed in an integrated environment, it could provide tamper-proof logs for SIEMs to monitor.

Final Thoughts

Most companies, in some form or another, are experiencing the benefits of an IoT integrated system.  But as hackers are getting more savvy, IoT devices increasingly become a liability.  If businesses are to weather these coming attacks, they will have to go on the offense and build a more replete data security toolkit.  

One of the more exciting technologies to come to the foreground in securing IoT is blockchain.  Ahmed Banafa did an amazing job laying out some of the core concepts of securing IoT with blockchain.  If you have a chance, read it.  It is a good primer on the current challenges and opportunities that blockchain presents.

Lastly, the only way to be truly ready is to be proactive.  Test your system for known vulnerabilities.   Build responses to attack scenarios. Fill gaps exposed by penetration testing with the tools listed above. And have your cyber security team build muscle memory with repeated drills so that you are ready when, not if, an attack occurs.

Ken Mafli is a Data Security Wonk at Townsend Security and their Demand Generation Manager.  For the last four years he has helped enterprise level clients around the world secure their data with Townsend Security’s encryption and key management systems.  He regularly writes on the topics of data security trends, cryptography, and the changing landscape of the industry.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.