Intelligent CISO Issue 42 | Page 39

FEATURE exploited and infiltrated through their growing number of personal IoT devices , such as Amazon Echos , Google Homes , or smart fridges .
Many workers and the organisations that employ them aren ’ t aware of the threats posed by these commonplace IoT devices . They fail to assess and secure each one and their network becomes as weak as its weakest link as a result .
Finally , many devices – inside and outside the organisation – simply aren ’ t capable of running the necessary software updates to remain secure .
This is down to any number of factors , whether it be a lack of configuration to receive such updates or the fact that many devices still run via batteries and therefore cannot run even basic security controls .
A starter for 10
In order to properly secure today ’ s IoT devices , an essential step is a ground-up process for automatically maintaining a complete , accurate and up-to-date asset inventory , whereby IT teams can take stock of every single device on their network , its lasting security capabilities and the current risks it poses .
Once these have been evaluated , the next step is to remove , upgrade or isolate any device that cannot be properly secured . IT teams must find a suitable replacement or , at the very least , apply compensating security controls for mitigating any residual risks outside of appetite .
When it comes to bringing new IoT devices onto the network , it ’ s vital to ascertain how best to secure and configure each device and what steps must be taken to ensure they remain secure .
For new and existing devices alike , continual software updates must be undertaken at regular intervals to ensure the latest vulnerabilities are patched and that no one device is left unsecured .
Continuous due diligence and commitment to enterprise-wide IoT visibility are essential to any organisation looking to harness the booming IoT market .
Only by accounting for every single device and the risks they pose can organisations safely harness the tremendous potential of the IoT for years to come . u www . intelligentciso . com
39