Press play to start listening
A business can have a solid cybersecurity strategy and still have devices operating on its network that no one can remember adding. This could be a printer installed years ago, an outdated camera system or even a sensor connected to a building management platform. These can all easily hide from view while remaining part of an organization’s technology.
This can create a number of problems. Each device that’s connected can potentially introduce another pathway into a network. Especially when it runs outdated software, uses weak credentials or is no longer actively monitored. IoT/OT Asset Visibility can help organizations get a clear idea of what’s connected.
The biggest challenge is that modern networks are rarely just made up of computers and smartphones. Internet of Things (IoT) devices and operational technology (OT) are now used across manufacturing, healthcare, offices, warehouses and other environments. As more devices come online, keeping track of what is connected becomes even harder.
The problem with forgotten devices
Technology doesn’t always disappear when it stops being a priority. An old sensor could still be running long after the project it was installed for has ended; a building could have connected heating controls that were set up by a facilities team years ago or a security camera may have been added by a contractor and never made it onto the main IT inventory.
These situations are easy to overlook. The device might continue doing its job without causing any obvious problems, so there is little reason for anyone to think about it. Meanwhile, it might not be receiving the same updates, checks or monitoring as the company’s main computers and servers.
There’s also a difference between knowing that a device exists and knowing what it’s doing. An asset list might contain a model number and location, but that doesn’t necessarily tell a security team what software is running on the device or which parts of the network it can communicate with. It’s that missing information can make it harder to spot a security issue.
Connected doesn’t always mean secure
Many IoT and OT devices were built to carry out a particular job. Security wasn’t always a major consideration during their original design.
Some devices can remain in service for years with limited firmware support. Others depend on older software or communication methods that were developed before today’s threat landscape existed. Default passwords can also become a problem when nobody takes responsibility for changing them after installation.
This doesn’t mean every older or poorly documented device is a security incident waiting to happen. It just means that organizations need to know what they have and understand the risks attached to it.
The stakes can be higher when a connected device has access to important systems. A camera, sensor or piece of equipment might appear relatively harmless on its own, but an attacker who gains control of it could potentially use that access to look for other opportunities inside the network.
IoT and OT expand the attack surface
IoT and OT bring plenty of useful technology into modern organizations, but they also make the technology environment more complicated.
IoT devices can include cameras, sensors, smart appliances and specialist equipment. OT covers systems used to monitor or control physical operations, including industrial machinery and building management systems.
These devices aren’t always managed by the same people. An IT department might be responsible for laptops and servers while facilities staff look after building systems and engineering teams manage industrial equipment.
That separation can create gaps in knowledge. Each team has a good understanding of the equipment under its control, but there might not be a single view of everything connected across the organization. This can make it difficult to work out where the biggest risks are.
Visibility is the starting point
Before a company can protect a device, it needs to know that the device is there.
A useful asset inventory should provide more than a list of equipment. Security teams need information about where devices are located, how they connect to other systems and where possible, what software and configurations they use.
Having that information makes it easier to investigate unusual activity. It can also help teams work out which devices need attention first. Visibility is not a replacement for security controls. It simply gives organizations a much clearer starting point.
Closing the gaps
Getting better visibility doesn’t necessarily mean replacing old equipment. The first step can be much easier, and that’s to find out what is actually connected.
This could involve getting IT, security, facilities, and engineering teams to compare their existing asset lists. Automated discovery tools can then help uncover devices that have been missed or that do not appear in existing records.
Once those devices have been identified, organizations can start addressing the basics. That means changing default passwords, installing available firmware updates, separating certain devices from more sensitive parts of the network or removing equipment that is no longer needed.
The process also needs to be ongoing. Networks change all the time. A new device can be added during a project, an old system can be replaced or a temporary setup can remain in use much longer than expected.
The device nobody remembers connecting might not look like an obvious security concern. Until its presence, purpose and network access are understood, however, it remains another part of the environment that security teams have to account for.
(Photo by Growtika on Unsplash)