Understanding IoT Identity

Share this post

IoT Identity

What is a surefire way to mess up the security of your IoT implementation? Use the same secret for all of your devices? Allow former employees to access the devices in the system? How about leave default passwords on devices?

It turns out that there are a lot of surefire ways to mess things up. You probably assume that your security team has this figured out. Here is a not-so-secret… no one has IoT Identity figured out yet. The most advanced organizations from a security perspective have made some great strides. I have spoken to many of the organizations with significant IoT deployments over the past many years. It is clear that there is a lot to fix.

The Mirai botnet attack from two years ago, was eye-opening to some. It brought down significant web properties such as Twitter and Spotify. The webcams, routers and cable boxes that used hardcoded or default passwords were one of the key drivers of the attack. But what has changed since then? Many devices out there share the same secret between devices or use the default password. There are lots of other ways to mess up IoT Identity too.

IoT Identity Practical Advice

If you are trying to better secure your IoT implementation, we have some practical advice. I wrote a white paper on IoT Identities and Privileges. It is written from the perspective of someone who has been helping companies secure their IoT identities for years.

The white paper takes the view of real world requirements. It covers the organizational challenges often missed when discussing IoT security. Securing an IoT architecture is a shared responsibility between the providers of the infrastructure, service, platform, application and the end customer. Thinking that one organization will be able to solely manage the solution is unrealistic. That means that you need to partner with your suppliers and customers to improve the security of the IoT solution.

There are many frameworks for security and some emerging ones for IoT security. The white paper culls the key pieces of many of these frameworks to provide clear guidance on the most important things to focus on for IoT security.

It then covers many of the keys for better IoT Identity and Access Management. These include the privileged user, architecture, systems and credentials.

It concludes with six specific recommendations for better managing your IoT implementation securely.

IoT Identity White Paper

IoT Identity White Paper

For a complimentary copy of the IoT Identity white paper, please send us an email at [email protected]. Please write IoT security white paper in the subject line.

We published the white paper in conjunction with our partner, Beyond Trust. We also, did a webinar on The 5 Crazy Mistakes Administrators Make with IoT System Credentials with them. It covers threats from ex-employees, credential management and more!

For help with your cybersecurity strategy to improve your company’s security posture, call Fractional CISO today. We can be reached at (617) 297-9509 or visit our website and find out how we can assist you.

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales