Danger - unauthorised devices in the workplace

1,500 per cent increase in IoT traffic through the Zscaler Cloud highlights dangerous rise in unauthorised devices brought into the workplace.

  • 4 years ago Posted in

Zscaler has released the company’s second annual Internet of Things (IoT) report, IoT Devices in the Enterprise 2020: Shadow IoT Threat Emerges. Zscaler customers are now generating more than 1 billion IoT transactions per month in the Zscaler™ cloud, which amounts to a 1,500 per cent increase since Zscaler’s May 2019 report. By analysing two weeks of this traffic through Zscaler cloud, Zscaler found 553 different IoT devices across 21 categories from 212 manufacturers.

 

Organisations around the world are observing this Shadow IoT phenomenon, where employees are bringing unauthorised devices into the enterprise. With this onslaught of unknown and unauthorised devices, IT and security teams often won’t know these devices are on the corporate network nor how they impact an organisation’s overall security posture. 

 

Key Findings:

  • Unauthorised IoT devices on the rise: The top unauthorised IoT devices Zscaler observed include digital home assistants, TV set-top boxes, IP cameras, smart home devices, smart TVs, smart watches, and even automotive multimedia systems
  • Manufacturing & retail industries top IoT traffic volume: Manufacturing and retail customers generated the highest IoT traffic volume (56.8%) followed by enterprises (23.7%), entertainment and home automation (15.7%), and healthcare (3.8%)
  • Majority of IoT transactions are insecure: 83 per cent of IoT-based transactions are occurring over plain-text channels, whereas only 17 per cent are using secure (SSL) channels
  • Exponential increase of IoT malware: Zscaler blocked 14,000 IoT-based malware attempts per month. That number has increased more than seven times since the May 2019 research
  • New exploits emerging to target Unauthorised devices: New exploits that target IoT devices are popping up all the time, such as the RIFT botnet, which looks for vulnerabilities in network cameras, IP cameras, DVRs, and home routers

 

“We have entered a new age of IoT device usage within the enterprise. Employees are exposing enterprises to a large swath of threats by using personal devices, accessing home devices, and monitoring personal entities through corporate networks,” said Deepen Desai, Vice President of Security Research, Zscaler. “As an industry, we need to implement security strategies that safeguard enterprise networks by removing shadow IoT devices from the attack surface while continuously improving detection and prevention of attacks that target these devices.”

 

Over the quarter, Zscaler blocked approximately 42,000 transactions which were IoT-based malware and exploits. The top malware families included Mirai, Gafgyt, Rift, Bushido, Demonbot and Pesirai. The top destinations connected to by IoT malware families and exploits are the United States, the UK, Russia, The Netherlands and Malaysia.

In response to the growing threat posed by Shadow IoT devices brought into the enterprise, IT organisations must first be able to gain visibility into the existence of unauthorised IoT devices that are already inside the network. Organisations should be considering a Zero Trust approach that ensures any communication between devices and people is with known entities and is within your organisation’s policy to reduce the IoT attack surface.

Beacon, NY, Dec 20, 2024– DocuWare unveils its AI-powered Intelligent Document Processing...
85% of IT decision makers surveyed reported progress in their companies’ 2024 AI strategy, with...
Lopitaux joins as global companies embrace GenAI solutions at scale and look to build their own...
Predictive maintenance and forecasting for security and failures will be a growing area for MSPs...
NVIDIA continues to dominate the AI hardware market: powering over 2x the enterprise AI deployments...
Hitachi Vantara survey finds data demands to triple by 2026, highlighting critical role of data...
81% of enterprises plan to increase investments in AI-powered IT operations to accelerate...
Hitachi Vantara survey finds data demands to triple by 2026, highlighting critical role of data...