Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

The Complete Guide to IoT Security

/ / 7 min read
Featured image for our blog: The Complete Guide to IoT Security

Internet-of-things (IoT) devices are staples of industrial, healthcare, and commercial networks. They collect process or patient data, communicate with databases and other assets on the network or in the cloud, and play a central role in physical industrial and commercial outcomes, or patient care. 

As a result, IoT security must be part of a strategy that protects operational technology (OT), patient devices, and smart commercial assets in warehousing, transportation, retail, and logistics. Exploitable vulnerabilities in smart, connected devices are a serious risk to business outcomes, industrial and commercial process availability, and the reliability of medical devices. 

This guide to IoT security will focus on several areas:

  • The types of IoT assets prevalent in OT and healthcare environments

  • Who and what has access to them

  • The exposures that put IoT at risk

  • What makes up an IoT security strategy

What is the Internet of Things (IoT) and Why Does It Need Protection?

Defining IoT Across Industries

IoT devices on industrial and healthcare networks collect process and patient data and share it via purpose-built gateways over the internet or cellular networks to a local or cloud-based collector. These devices are often sensors that collect real-time inventory, environmental, or patient data, for example. This information is used to manage equipment maintenance, keep processes available and on time, or inform patient diagnoses and treatments. 

Typical industrial use cases for IoT sensors include: monitoring wear and tear on equipment, monitoring power usage and improving energy efficiency, navigating warehouse picking, and real-time logistics. Within healthcare, the internet-of-medical-things (IoMT) include body-worn sensors that track patient vital signs, infusion pumps, and even hospital beds that track patient movement to ensure their physical safety. 

The Need for Dedicated IoT Security

IoT devices expand the enterprise attack surface dramatically, yet rarely are they designed securely. Instead, they’re manufactured with functionality and deployment in mind. A typical manufacturing enterprise or hospital may have thousands of IoT devices and sensors on the network, further complicating security. 

IoT security strategies require visibility into these difficult-to-manage assets on the network. Asset management informs the rest of the security program, including controls such as segmentation, privileged access controls, and more. IoT assets, however, are often vulnerable because of insecure design decisions. Devices often run outdated operating systems, vulnerable code, default credentials, and other exposures including legacy, insecure communication protocols. Some controls may be limited, including endpoint detection and response (EDR), encryption, and logging on embedded IoT systems. 

Exposure management, including addressing legacy vulnerabilities and insecure configurations out of the box, face similar update challenges to OT or medical devices. Firmware updates could require taking a production line offline, disrupting a medical device, or coordinating with a third-party manufacturer or service provider.

Attackers, meanwhile, have made child’s play out of turning IoT assets into large botnets, or exploiting internet-facing devices to gain a foothold on process networks, or the corporate network. Once compromised, an IoT device can become a stepping stone into more valuable systems. An attacker may use it to discover neighboring assets, steal credentials, move laterally or access operational networks.

Researchers have also demonstrated how attackers may target IoT devices directly. Cameras can be disabled or hijacked, building systems manipulated, industrial sensors altered and medical devices disrupted. The potential impact depends heavily on the device's role and its connectivity to other systems.

Securing IoT in Industrial, Commercial, and Healthcare Environments

IoT Security Risks in OT and Commercial

IoT devices that interact with OT and other cyber-physical systems (CPS) pose a consequential risk to the business. An attacker compromising IoT assets or gateways could access sensitive process data that if manipulated could negatively impact production lines and service delivery. Manipulation of sensor data can potentially cause operators or automated systems to make incorrect decisions.

Safety and availability are predominant priorities for OT, nudging aside conventional patching and systems updates. This lengthens the times organizations are exposed, especially in times when a publicly available exploit is in the wild for a vulnerability. Companies cannot reboot for every critical vulnerability, forcing security teams to rely on compensating controls such as virtual network segmentation, continuous monitoring and threat detection, and tight access controls to lock down IoT in OT and commercial environments. 

IoT is especially pervasive in commercial environments, which rely on connected cameras, access-control systems, HVAC controllers, lighting systems, printers, digital signage and smart-building technologies. This overlap with OT introduces familiar security challenges, instead with a much more diverse technology infrastructure, vendor landscape, protocols, and security capabilities. 

IoT Security Risks in Healthcare

Healthcare presents a distinct challenge. A compromise of a medical IoT device has obvious ramifications to patient safety and clinical operations. A breach of medical IoT can also lead to a lateral compromise of the enterprise network, putting patient data at risk and threatening stringent compliance efforts.  

Healthcare organizations therefore need to understand not only whether a device is vulnerable, but how critical that device is, what systems it communicates with and what could happen if it were compromised.

Core Pillars of an IoT Security Strategy

Three pillars make up a successful IoT security strategy: 

  • Visibility and asset discovery

  • Exposure management

  • Zero-trust segmentation and secure remote access

Visibility and Asset Discovery

Organizations need continuous discovery of IoT and connected devices that identifies device type, manufacturer, model, firmware, location, communications, vulnerabilities and relationships with other assets.

Passive discovery is particularly important in OT and healthcare because active scanning can disrupt sensitive systems.

But simple inventory is not enough. Security teams need contextual visibility that explains what each device does, what it connects to and how important it is to business or operational processes.

Exposure Management

Exposure management involves a more holistic approach to security that goes beyond traditional vulnerability management. Asset inventories that correlate device information with vulnerability data and insights into insecure configurations paint a true picture of asset risk in terms of business impact and the attack paths that threat actors may take. 

Exposure management then becomes a more thorough approach to IoT security and allows organizations to prioritize which assets are remediated or mitigated with compensating controls. 

Security teams will then be able to prioritize the devices and attack paths that represent the greatest risk rather than attempting to patch everything equally. When patching is impossible or impractical, organizations can compensate by restricting communications, removing unnecessary services, strengthening authentication or isolating the device.

Zero Trust Segmentation, Secure Remote Access.

Zero-trust principles provide a modern trust model where users and devices are explicitly authenticated, and access is limited based on a continuous evaluation of a user or device health. 

Segmentation is an invaluable control informed by zero-trust. IoT devices should be isolated from systems they do not need to communicate with, reducing the ability of attackers to move laterally after compromising a device.

Remote access is also an attack vector that can introduce additional risk. Third parties such as vendors, contractors, and remote workers, require connectivity to manage IoT assets critical to OT or healthcare. Zero trust ensures that identities are continuously verified and authenticated based on factors beyond identity information to include device health, geographic location, and risk scores. 

Making IoT Security Operational

IoT assets are invaluable in the modern enterprise where efficiency and cost savings are constantly under pressure. These assets are responsible for sensitive data collection, patient monitoring, environmental controls, and patient health across these respective industries. 

Increasingly, chief information security officers (CISOs) are being tasked with not only ensuring device security, but have a clear and current picture of the risks associated with every IoT device. Systematic, programmatic risk reduction is essential to shutting down attack paths and other exposures introduced by IoT devices. 

As IoT continues to expand across OT, healthcare and commercial environments, visibility must become the foundation, exposure management the prioritization mechanism, and zero-trust segmentation and secure access the controls that keep risk in check.

Talk to an expert about IoT security and Claroty xDome.

Industrial Internet of Things (IIoT) Internet of Medical Things (IoMT)
Related Articles Tagged with Industrial Internet of Things (IIoT) or Internet of Medical Things (IoMT)

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook