Enterprises lack visibility and control of IoT devices on their network

Traditional security tools fall short in securing a growing number of diverse IoT devices driving need to rethink IoT security strategy.

  • 8 years ago Posted in
ForeScout Technologies has published the findings of its new “European Perceptions, Preparedness and Strategies for IoT Security” survey. The research revealed that while the majority of respondents acknowledge the business opportunity presented by the Internet of Things (“IoT”), and the growing number of IoT devices connected to their enterprise networks, their organisations lack understanding of how to properly secure them.
 
“The staggering growth of IoT is creating both value and risks for enterprise organisations,” said Jan Hof, International Marketing Director, ForeScout Technologies. “While IoT is recognised by many as an opportunity to improve and streamline business processes, there are associated security risks that need to be addressed – first and foremost through visibility of devices as soon as they connect to the network. You cannot secure what you cannot see.”
 
Commissioned by ForeScout and conducted by a non-affiliated third party, Quocirca, the survey of 201 senior IT decision makers in the UK and German speaking regions of Germany, Austria and Switzerland (‘DACH’) assessed their organisations’ IoT security practices. Key findings from the survey include: 
 
?     Increased size and diversity of attack surface: The average business expects to be dealing with 7,000 IoT devices over the next 18 months. Even smaller businesses expect the numbers to be hundreds or thousands; far more than they are used to securing when it comes to traditional user endpoints.
?     Healthcare lagging in IoT readiness: One third of respondents say the IoT is already having a major impact on their organisation and a further third expect it to soon. IT and telecoms are the most advanced industries in terms of IoT readiness with healthcare, which many think stands to benefit significantly from the IoT, lagging behind.
?     Uncertainty over identification and control: 65% of respondents have ‘quite’, ‘little’ or ‘no’ confidence in terms of being able to identify and control all IoT devices on their network. This uncertainty is substantiated by the fact that many IoT operating systems are open source and can therefore be adapted by device manufacturers, leading to many variants.
?     Agentless approach is the only way: Being able to discover and classify IoT devices without the use of agents (most of which will only support popular operations systems such as Windows, Android, iOS and OS X) was perceived by 64% of respondents as ‘extremely important’ or ‘quite important’, with this figure increasing to 73% within the healthcare sector, which has the most unusual range of devices including CT scanners, diabetic pumps and heart monitors.
?     Biggest IoT security challenge? IT functions working together: Getting the various IT functions (networking, security, DevOps, etc.) at an organisation to work together was perceived by 83% of respondents as one of the top IoT security challenges. A minority of survey participants considered lack of personnel to be problem, but well over half worry about budgets and the availability of appropriate products.
 
Bob Tarzey, Analyst and Director at Quocirca (who conducted the survey), said, “IoT deployments already involve millions of devices in businesses across Europe. Many will have limited processing power and require low power usage. Others will have unusual operating systems and, in certain cases, the Things involved will be unknown to IT security teams when they first request network access. All of this requires tools that can manage and understand the security status of all network attached devices, without the need to install agents.”
Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
73% of organizations lack automated patch management, and 62% experienced incidents involving...
Quest Software has signed a definitive agreement with Clearlake Capital Group, L.P. (together with...
Dell EMC PowerProtect Cyber Recovery for AWS provides a fast, easy-to-deploy public cloud vault to...
Aqua’s cloud native application protection platform becomes the only solution that protects cloud...
54% of organisations working on a security transformation project now or in the next 12 months.
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Zscaler Zero Trust exchange cloud-based architecture enables superior green security capabilities...