127 views

Why a secure IoT environment matters

By Sanjay Aurora

On the evenings of 22 and 24 October 2016, national telco StarHub's home broadband services unexpectedly were disrupted – an unprecedented occurrence in normally safe, efficient, and connected Singapore.

Subsequent investigations revealed the incidents stemmed from a Distributed Denial-Of-Service (DDoS) attack propagated by hackers. By taking control of connected devices such as routers and webcams, the perpetrators willfully shut down StarHub's broadband servers through an overwhelming spike of internet traffic from the affected devices.

DDoS attacks, while not a new form of cyber threat, have risen to prominence as cyber attackers have used them on large scale to great impact recently. Just weeks before the StarHub disruptions, a similar hack took place on the American East Coast which denied millions access to favourite websites and internet services such as Reddit and Twitter. In an ominous parallel on 28 November, another DDoS attack on Germany's largest telco, Deutsche Telekom, affected around 900,000 customers.

The implications of these attacks on hundreds of thousands of consumers go far beyond the disruption of internet services. Connected devices on networks, or the so-called 'Internet of Things' (IoT), whilst holding vast promise for businesses and consumers, have morphed into two-pronged threats. If devices in homes can be compromised, imagine the implications for businesses, infrastructure, and public institutions.

Highly skilled and well-resourced international advanced persistent threat (APT) groups or nation-state attackers, who have strong interest in obtaining inner network access, will look to take advantage of the growing IoT trend. With Gartner predicting 21 billion connected 'things' by 2020, companies will only become further exposed to attack as they deploy more and more connected devices.

Attacks of this scale have made it more evident than ever that the world is entering a new era of threat, and faith in trusted institutions can come undone at a moment's notice. For instance, power plants in Ukraine were hacked at the start of 2016, causing power outages to 80,000 homes for six hours. The big institutional banks have also bled millions to criminal hacks throughout the year.

In this heightened cyber climate, complete visibility of a network is crucial and organisations can no longer afford to keep the security of internet-connected devices as an afterthought. To prevent connected devices and networks from becoming unwilling accomplices, organisations must be able to detect any unusual behaviors across all their internet environments and across the thousands of daily minor incidents which will be impossible to manually keep tabs on.

There should hence be mounting pressure for companies to make themselves more resilient and adopt 'immune system' technology that uses machine learning and advanced algorithms to detect serious or suspicious threat indicators in real-time amidst the noise of daily activities, instead of relying on legacy tools to secure their IoT environment. Otherwise, there will only be more of these attacks seen as the world continues to embrace the Internet of Things.

Join Singapore Business Review community
Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

You're the reader we write for. You're also the person our partners want to reach.

If that sentence describes you — a founder, a C-suite, someone whose attention companies pay good money for — then you already understand why SBR works. We've spent twenty years earning the trust of readers exactly like you. Which is exactly what makes this an interesting place for your company to show up, too.

The ways it can show up are broader than most people assume — thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The right fit depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.

If your company has something this audience should know about, we'd like to hear what you're working on.

No rate cards until we understand the brief. It's a better use of everyone's time.

Top News

30 One-Sentence Stories From People Who Have Built Better Habits
None of these stories are mine. They were sent to me by readers of Atomic Habits. My hope is that these examples will illustrate how real people are putting the book into practice. They will show you what people are actually doing to build good habits and break bad ones. And hopefully, they will spark some ideas for how you can do the same.
SBR 5 Lorem Ipsum News 2 [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 4 Lorem Ipsum [8 May Top Stories]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Exclusives

How Experts Figure What to Focus On
eliminate the distractions. Commit to one thing and become great at that thing.”
Exclusive three SBR 12 Lorem Ipsum [8 May]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.
SBR 3 Lorem Ipsum [ Exclusive 2]
Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged. It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Event News

Video [Event News]
Lorem Ipsum has been the industry's standard dummy text ever since the 1500s, when an unknown printer took a galley