Author: Prayukth K V

  • La Confianza digital en la era del IoT

    La Confianza digital en la era del IoT

    En el mundo pospandémico, un habilitador tecnológico que será testigo del mayor nivel de adopción es Internet de las cosas. Hemos alcanzado un punto de inflexión en el viaje de adopción de IoT y ahora estamos mirando una curva de crecimiento de palo de hockey en términos de la cantidad de puntos finales y diversidad de casos de uso. Entonces, ¿será un viaje tranquilo a partir de ahora? Lamentablemente, la respuesta es un no.

    Seguridad: la base de la confianza digital y el crecimiento exponencial

    Para capitalizar la demanda de datos habilitados para IoT, varias partes interesadas a menudo pasan por alto la seguridad. Esto crea un entorno atractivo para que los piratas informáticos exploten, lo que genera múltiples problemas en áreas como el retorno de la inversión y la acumulación de valor. Los dispositivos de IoT operan en la cúspide de los mundos real y virtual y, dado que la seguridad tiene poca o ninguna prioridad, estos dispositivos se convierten en conductos para que los piratas informáticos entren, exploten y salgan a voluntad. Los piratas informáticos también pueden utilizar estos dispositivos para lanzar ataques de denegación de servicio en la infraestructura de terceros, lo que causa más daño y genera ramificaciones legales.

    La investigación de Subex ha demostrado cómo los piratas informáticos se adhieren a los proyectos de IoT en una etapa muy temprana, como una prueba de concepto o un piloto, y se quedan para monitorear las redes esperando pacientemente que aparezcan datos o activos de interés en la red o la infraestructura conectada. También implementan una variedad de malware y troyanos para mantener la red bajo vigilancia durante períodos prolongados.

    Dichos desafíos pueden generar preocupaciones de confianza para varias partes interesadas, incluidos usuarios finales, inversores, empleados y proveedores. Por lo tanto, las preocupaciones de seguridad deben abordarse no solo de acuerdo con las normas de cumplimiento, sino también de acuerdo con el entorno de amenazas predominante y los cambios proyectados en este entorno a corto plazo y en el futuro. Crear un entorno de confianza digital en un proyecto de IoT requiere inversiones y una comprensión profunda del entorno de amenazas y sus implicaciones.

    Mejorar la confianza digital en el mundo de IoT puede generar una serie de beneficios. Para empezar, los proyectos en varias etapas se beneficiarán enormemente, ya que la posición de seguridad mejorada ayudará a garantizar operaciones sin interrupciones y, por lo tanto, mejorará la confianza de las partes interesadas. Las empresas emergentes pueden esperar un mayor acceso a las opciones de financiación y los proyectos innovadores en las empresas establecidas pueden esperar movilizar más fondos de fuentes internas.

    En general, la economía digital de una nación en sí misma puede beneficiarse de una atención tan granular a la seguridad de IoT y la confianza digital. Hoy en día, muchas corrientes comerciales vitales y sectores de infraestructura dependen en cierta medida de IoT y esta dependencia aumentará en los próximos días. Las inversiones en seguridad de IoT ayudarán a orientar mejores resultados para estas corrientes y sectores, lo que tendrá un efecto en cascada en la economía.

    Consideraciones importantes para mejorar los resultados de seguridad de IoT y la confianza digital:

    • Alinear las necesidades de seguridad con los más altos estándares internos
    • Invierta en dispositivos y otros componentes de infraestructura para obtener valor en lugar de ahorrar costos
    • La seguridad de IoT debe verse como un conducto para permitir la confianza digital.
    • Todas las partes interesadas deben estar sensibilizadas sobre los mandatos y consideraciones de seguridad.
    • La generación de confianza digital debe ser un ejercicio continuo con inversiones, recursos y atención provenientes de todas las partes interesadas en todo momento.
    • Las oportunidades para mejorar la postura de seguridad deben ser un área clave de atención.

    Adiós 2020 … 2021, ¡no puedes venir lo suficientemente pronto!

    Leer Blog

  • How cybersecurity challenges and trends will mark 2021?

    How cybersecurity challenges and trends will mark 2021?

    As 2021 emerges on the horizon, here are the top trends that our threat researchers feel will define the New Year.

    Ransomware propagation: the first quarter of 2021 will provide some respite to cybersecurity teams battling ransomware. Already we are seeing signs of a slowdown as malware developers are investing more time in developing new ransomware. This respite is however temporary as new and stronger ransomware and variants will start emerging from April.

    Attack fatigue: nation state actors have shown signs of fatigue setting in. After ruthlessly targeting vulnerable sectors such as healthcare and manufacturing during the pandemic, many hackers have retreated to the comfort of their basements. This trend is expected to continue till the end of Jan 2021.

    Manufacturing, retail and healthcare on the radar: attacks on these sectors will intensify.

    Media and entertainment (M&E) industry will be most impacted sector in 2021. This is based on the trends we are currently seeing especially the activity in the malware forums we are tracking.

    Deep fake videos will be weaponized with greater intensity as part of multi-stage phishing campaigns

    Botnet farms to increase: as 5G rollout gathers pace, more IoT devices will be added some of which will not have the bare minimal levels of security in place.

    Industrial control systems to bear the brunt of sophisticated attacks. Industrial espionage at a large scale will hit energy, power, oil, gas and manufacturing companies

    Data stored on public cloud will be the target of cloud jacking in a more organized manner

    Subex is here to help

    We will be glad to help you address your security challenges in the New Year. At Subex, we have a robust and evolved IoT and OT security solution backed by consulting and SoC services tailored to your unique cybersecurity needs.

    Subex is today securing the business of its customers around the world. Our suite of solutions bring features such as cyber deception, device discovery, threat detection and deflection and prevention of lateral movement of threats. These are essential to keep your business safe and protected.

    The article is originally published at Subex Secure

    Learn the important considerations for improving IoT security outcomes and digital trust

    Read Blog

  • Digital Trust in the era of IoT

    Digital Trust in the era of IoT

    In the post-pandemic world, one technology enabler that will witness the greatest level of adoption is the Internet of Things. We have reached an inflection point in the IoT adoption journey and are now staring at a hockey stick growth curve in terms of the number of endpoints and use case diversity. So is it a smooth journey from here on? The answer unfortunately is a no.

    Security: the foundation of digital trust and exponential growth
    To capitalize on the demand for IoT-enabled data, various stakeholders often overlook security. This creates an enticing environment for hackers to exploit leading to multiple problems in areas such as return on investments and value accretion. IoT devices operate on the cusp of real and virtual worlds and with security being accorded little or no priority, these devices turn into conduits for hackers to enter, exploit, and exit at will. Such devices can also be used by hackers to launch Denial of Service attacks on third-party infrastructure causing more damage while attracting legal ramifications.

    Subex’s research has shown how hackers latch on to IoT projects at a very early stage such as proof of concept or pilot and stick around to monitor the networks patiently waiting for data or asset of interest to appear on the network or the connected infrastructure. They also deploy a range of malware and trojans to keep the network under watch for long periods.

    Such challenges can create trust concerns for various stakeholders including end-users, investors, employees, and vendors. Thus, security concerns must be addressed not just according to compliance norms but as per the prevailing threat environment and projected changes in this environment in the near term and future. Creating an environment of digital trust in an IoT project requires investments and a deep understanding of the threat environment and its implications.

    Improving digital trust in the IoT world can lead to a range of benefits. To begin with, projects at various stages will benefit immensely as the improved security posture will help ensure disruption-free operations and thereby improve stakeholder confidence. Start-ups can expect more access to funding options and innovative projects in established businesses can expect to mobilize more funds from internal sources.

    On the whole, the digital economy of a nation itself can stand to benefit from such granular attention to IoT security and digital trust. Today, many vital business streams and infrastructure sectors are relying on IoT to some measure and this dependency will increase in the days to come. Investments in IoT security will help guide better outcomes for these streams and sectors thereby having a cascading effect on the economy.

    Important considerations for improving IoT security outcomes and digital trust

    • Align security needs to the highest internal standards
    • Invest in devices and other infrastructure components for value rather than cost savings
    • IoT security should be viewed as a conduit for enabling digital trust
    • All stakeholders should be sensitized towards security mandates and considerations
    • Building digital trust should be an ongoing exercise with investments, resources, and attention coming from all stakeholders at all times
    • Opportunities for improving security posture should be a key area of attention

    Why Your business needs a Chief Trust Officer (CTrO)?

    Read Blog