Many of you reading this article have used one or more Internet of Things (IoT) devices in your daily routines. Most IoT devices connect to the internet and constantly exchange data with other online devices and individuals. However, their constant connectivity makes them susceptible to cyberattacks if proper security measures are not taken.
A study by Kaspersky revealed that the number of cyberattacks targeting IoT devices doubled between 2020 and 2021. The majority of these attacks resulted in data breaches that put millions of people’s information at risk. This increase in cyber threats targeting IoT devices should concern everyone as we all rely heavily on these devices in our daily lives.
From the cars we drive to the watches we wear, our televisions, phones, speakers, and most electronic devices are now connected to the internet, making them vulnerable to cyberattacks. This is why everyone needs to be aware of the current state of IoT security and the common threats these devices face. It is crucial for us to take necessary precautions to protect ourselves from becoming the next victims of cyberattacks.
The current state of IoT security
Most IoT devices have unpatched software.
One of the security issues we should all be concerned about is the fact that most of our IoT devices do not receive periodic security updates. The software on most IoT devices is difficult or almost impossible to update.
For instance, many smart TVs don’t get regular updates. Only a few popular brands roll out software updates for their TVs for a few years after production. Besides TVs, soundbars, smart fridges, and many other smart devices in our homes rarely get updates.
The lack of updates for most devices is mainly because brands don’t have any incentive to continue releasing security and feature updates after selling these devices. When HiSense sells you a TV, they won’t get any more money from you beyond the profit they earn after the sale.
So, there is no incentive for HiSense to continue sending over-the-air updates to their smart TVs unless users are willing to pay a monthly or annual subscription fee for such services. But let’s be honest; most people are unwilling to pay a monthly or annual fee for security updates. This leaves such devices vulnerable to exploitation of known vulnerabilities.
People are not concerned about security updates of IoT devices
Unless it is a phone or computer, not so many people are concerned about updating their other devices. Even when companies put in the effort to release periodic security updates for their devices, many people don’t bother installing those updates.
One of the reasons behind this behavior is that most IoT devices don’t have intuitive user interfaces. Computer and phone operating systems are more mature and intuitive, making it easy for most users to do tasks such as updating their devices to the latest software. This is not the case with many other smart devices.
I own a Sony Sound Bar, and one of my major complaints is its complex and unintuitive user interface. The good news is that I don’t usually connect it to the internet, so it is less exposed to cyber threats. The user interfaces of many other smart home devices are just like my Sony sound bar, so people find updating them unintuitive.
The lack of encryption
Data stored and sent from most IoT devices is usually not encrypted. A report by network security firm Zscaler found that over 91.5% of data transactions performed by IoT devices in corporate networks were unencrypted. This number should be higher for IoT devices in non-corporate environments.
The lack of encryption makes the data on these devices very vulnerable in case of an attack. For instance, if attackers ever get access to your home network, there is a high chance that they will compromise the data on your smart devices, including smart TVs, cameras, smart speakers, and more. Even for the devices that support encryption, many people are not aware of it or do not bother utilising it.
Sensitive data on IoT devices
As people rely more on IoT devices to do their everyday tasks, putting their sensitive data on these devices has become inevitable. For instance, our smartwatches can measure and store sensitive health data, including real-time body temperature, blood pressure, blood oxygen, physical activity, and more.
Other IoT devices, such as IP cameras, also store a lot of our sensitive data that we wouldn’t wish to expose to the internet. Such data can be misused if it gets into the hands of cyber attackers.
More cyber-attacks on medical IoT devices
The medical industry is among the sectors cyber attackers target the most. That’s why cyber-attacks on healthcare Internet of Things (IoT) devices are becoming a growing concern as more medical devices connect to the internet. Such devices can include everything from hospital equipment and medical devices to wearables and home health monitoring devices.
These devices store and transmit sensitive patient information, making them a prime target for hackers. Compromising medical IoT devices can result in the theft of patient data, disruption of critical medical procedures, and even potential harm to victims (patients).
With the sensitivity and critical nature of the information and services provided by healthcare IoT devices, manufacturers and healthcare organisations must prioritise their security. Some of the security measures they can implement include regularly updating the software and firmware of these devices and conducting regular security assessments to identify and patch all their security loopholes.
Biggest threats facing IoT devices
As we shared earlier, the increase in the usage of IoT devices has attracted the attention of hackers and other cybercriminals. Some common threats that individuals or organisations using IoT devices need to be concerned about include the following;
1. DDoS attacks
Attackers can use IoT devices as part of a botnet to carry out massive distributed denial of service (DDoS) attacks, causing widespread disruption in services that rely on the internet. One of the popular examples of DDoS attacks on IoT devices is the Mirai botnet attack in 2016.
In this attack, hackers compromised IoT devices to attack Dyn (a major domain name system provider). This led to a widespread internet disruption for websites and platforms affiliated with this service provider.
2. Malware and viruses
Attackers can compromise user data or interrupt the usage of IoT devices using malware and viruses. The worrying fact is that most IoT devices do not support installing third-party antivirus software that detects and deletes malware before it causes any damage.
That means most IoT devices have to rely on the security capabilities in their firmware or OS. Hackers can also use unsecured IoT devices as a gateway for transmitting viruses to other IT infrastructures of an organisation or individual.
3. The use of weak passwords
Most people don’t bother using strong passwords on their IoT devices. Some don’t even use passwords at all. It should also be noted that some IoT devices don’t allow users to create a password. This leaves their data exposed if an attacker gets access to their devices.
4. Unencrypted data storage and transmission
Many IoT devices store and transmit sensitive information in an unencrypted format, making it vulnerable to interception and exploitation. The idea of encryption is only embraced in larger computing devices such as desktop personal computers, servers, and maybe smartphones.
Encrypting data on IoT devices is not something that most people give their attention to.
Besides, not so many IoT devices include this option in their operating systems. For example, I don’t know so many smart TVs that give users the option to encrypt the data stored and sent from their TVs. This exposes all the user data if an attacker ever gets access to the IoT device.
Final thoughts
In summary, the current state of Internet of Things (IoT) device security should be a concern for everyone as the number of connected devices continues to grow. Despite the potential benefits of these devices, they are vulnerable to a range of security attacks, including data breaches, malware and virus attacks, DDoS attacks, and more.
These attacks can result in the theft of sensitive information, disruption of critical services, and even harm to individuals. That’s why it is imperative that IoT device manufacturers and users prioritise the security of these devices. Manufacturers need to roll out regular updates for their IoT devices. They should also make updating much easier and more intuitive.
On the other hand, users need to be aware of the potential attacks their IoT devices face and take the necessary steps to secure them. Ultimately, IoT security will only improve if manufacturers and IoT device users work together to ensure these devices are safeguarded from potential attacks.
If you want to beef up the security of IoT devices, consider checking out our Microsoft Defender for IoT/OT service.


