Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Poor security threatens Internet of Things hypergrowth

By Robert R. Ackerman Jr.
Internet of Things
October 29, 2021

Most people familiar with computers and information technology know something about the Internet of Things (IoT) and probably own an IoT device or have seen it in use in the workplace. IoT adds internet connectivity to computing devices, mechanical and digital machines, and a huge array of non-computer objects.


Its growth, meanwhile, has been astounding — so much so that it has often been called the second phase of the internet.


There are now more than 11 billion connected devices worldwide, up from almost nothing a decade ago. This number is expected to swell to more than 27 billion in 2025, according to IoT Analytics, and most consumers and companies that employ IoT are happy they do. It includes “smart” home devices, such as smart cameras and doorbells; Wi-Fi enabled lights; toys; smart appliances; healthcare and fitness devices; smart automobiles with nascent self-driving capabilities; and industrial sensors.   


Such objects have become a fundamental driver of global digitization, making life at home and in business easier and more productive.


Nonetheless, the IoT universe has a huge shortcoming that could gum things up.


In a world replete with endless cyberattacks, IoT devices have minimal security, in part because cybersecurity stewards and their bosses are busy with other things and aren’t demanding improvement. Neither does it help that IoT has much lower memory and computational capabilities than normal IT systems and cannot be centrally managed and configured. So IoT manufacturers focus mostly on developing and making ever more connectable products in a relentless effort to steal market share from competitors.


IoT is no longer new, but it has still been compared to the early days of the internet. Companies rushed haphazardly into the internet gold rush without adequately addressing internet security, and viruses, worms and spam became ubiquitous. At a subdued level, history may be repeating itself with IoT.


The upshot is that IoT remains based on a shaky business model, notwithstanding its whirlwind success. It’s true that internet users seldom put security first. But this doesn’t mean they don’t care about security at all, especially if they have been attacked, as more and more have. IoT device makers deliver updates for firmware — the device’s operating system — but many only for a short duration and most similarly fail to provide sufficient security updates.


This has consequences. According to the Nokia Threat Intelligence Report 2020, IoT devices recently were responsible for 33 percent of all infections observed in mobile networks, double the percentage in 2019. In large part, cybercriminals doubled down on security weaknesses amid the Covid-19 pandemic in an aggressive move to steal personal data. Companies have been the biggest targets because many have lots of IoT devices, providing a huge number of entry points for hackers to ultimately access all the data available on their networks.


The first major attack exploiting vulnerable IoT devices occurred five years ago, when internet service provider Dyn since acquired by Oracle, was successfully breached by an IoT botnet. It was among the largest denial-of-service attacks ever launched, bringing down huge portions of the internet, including Twitter, the Guardian, CNN, Netflix and Reddit. The botnet was made possible by Mirai malware, which searches the internet for vulnerable devices.


There have not been many other huge IoT-based attacks because hackers in the interim have focused much more on phishing schemes and, in particular, lucrative ransomware attacks. There have been plenty of smaller attacks, however, especially in healthcare. The vast majority of global healthcare providers that have implemented IoT devices have experienced a cyberattack on at least one of those devices, according to a worldwide survey of 700 security leaders by Swedish software company Irdeto.


Another high-profile attack occurred late last year when dozens of customers of Amazon-owned Ring, a provider of home security in the form of smart cameras installed on doorbells or inside people’s homes, were attacked and harassed and sometimes threatened with violence. Recently, other IoT users not attacked per se but analyzed by cybersecurity pros and deemed highly vulnerable included Peloton, the popular indoor spin bike company; cardiac pacemaker manufacturer Abbott; electric car manufacturer Tesla; and Owlet, the maker of a Wi-Fi baby heart monitor.


The question now is whether IoT device manufacturers will change their ways and incorporate better security from scratch. In addition to the aforementioned roadblocks, such an expensive move could threaten relatively low price points in a competitive market and pressure profits.


Corporate customer pressure is the key to change. This may happen at some point as corporate CISOs become increasingly aware that IoT devices are a significant attack vector. One bright spot is the passage of a new law late last year — The IoT Cybersecurity Improvement Act — which mandates tougher security requirements for IoT devices sold to federal government agencies. If the federal government ultimately sees fewer IoT security issues, as a result, corporations may take notice and similarly begin requiring stricter standards.


In the meantime, here are some measures that companies and often consumers can take to improve IoT security:

  • Scrutinize IoT vendors. When possible, refrain from buying their products if they don’t provide security updates on an extended basis.
  • Regularly check for patches and updates. Vulnerabilities can come from any layer of IoT devices. Even older vulnerabilities are still being used by cybercriminals to infect devices, demonstrating how long some unpatched devices stay online.
  • Regularly change default passwords. Too many people use the same login and password for every device they use, an open door for cybercriminals. The default password on every new device must be changed, and every login must be unique for every employee and require strong passwords.
  • Apply network segmentation. This way, users can minimize the risk of IoT-related attacks by creating an independent network for IoT devices, preventing hackers from deeply penetrating the entire system.


It’s worthwhile to bear in mind that technology today can amplify the consequences of a successful data breach more than ever. And now, industries and consumers are relying heavily on inherently vulnerable IoT devices. If this doesn’t change, this could ultimately undermine many of the benefits of the internet.

KEYWORDS: cyber security Internet of Things (IoT) ransomware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bob ackerman

Robert R. Ackerman Jr. is founder and managing director of AllegisCyber Capital and co-founder of cyber startup foundry DataTribe. He was the first investor to create a venture fund focused exclusively on cybersecurity and data science and has been investing in cybersecurity for more than 15 years in the U.S. and select international markets. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Enterprise Services
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cyber Tactics Column
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Drones: Nuisance or Serious, Immediate Threat?

    Things are looking up for the commercialization of drones

    See More
  • digital-cyber

    Five tips for chief information security officers to increase their strategic value to the CEO and board of directors

    See More
  • cyber_lock

    Companies need to enhance cybersecurity amid the continuation of COVID-19 in 2021

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!