State of IoT Security in 2023 – John Gallagher, Viakoo
John Gallagher, VP of Viakoo Labs, joins TechStrong TV to discuss the state of IoT security in 2023, including the recently released National Cybersecurity Strategy, which cites driving the deployment of secure IoT devices as a key priority.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with John Gallagher who is vice president of vehicle labs? And we're talking about the state of iot security over the lack thereof of John welcome to the show. Thank you.
Mike good it to be here. I think we've been talking about iot security for some time ever since somebody started connecting all these various devices and then somebody sent some nasty bit of malware through and all kinds of interesting things started happening and it's been replicating ever since are we making any progress at the moment? It feels like more things are connected to the internet than ever.
But how good is our security? Well, you know just just like all parts of cybersecurity, right? You've got you've got two sides, right?
You've got the call it the the threat actors and you've got the defenses against them. And so what's happened over time. Of course with iot is that there's always been an element of threat actors wanting to or you know managing to you know, exploit them reach them and use them for for various purposes.
The the thing that's changed. I would say over the last, you know, you could say five to ten years in a broad sense. It's really three things.
The first is that these devices now aren't just it's not a dumb sensor at the end of the network. These are Serious compute devices they have processing storage and networking that really make them super attractive targets. I mean one small example is you know, if you follow DDOS attacks, right?
Which have been Both, you know in in volume and velocity increasing tremendously over the last few years. Of many of the malware agents were Bots that that you know deliver or executed a DDOS attack or hosted on iot devices and now they're using the innate compute and memory capabilities in them to do DDOS amplification. Right?
So you don't need to be sending out that many you need to be using a mechanism inside the network like an iot device to amplify them. So and there's many other examples. I mean that's just one that the recently came across the radar screen and and I thought was a good example of how iot devices have changed themselves and how threat actors are using those new capabilities to the detriment of the organizations who deploy them a second thing.
That's that's really changed significantly with iot is that The degree to which they're they're worked into what we would call cyber physical systems. You know that that it's one thing to have a system that doesn't impact other people, right? You know, that's that's wonderful today iot devices though manage many things out in the real world that that threat actors can take advantage of you know, we could range from anything where IP cameras are being exploited and deep fake videos or you know, use of the video feeds is being done all the way through to you know, chemical water balances in a water plant in Florida or you know pipelines getting closed down and shutting off Gas Distribution on the East Coast.
There's there's many cyber physical aspects that iot devices or leverageable for and then the last part is I iot security is tougher because today you've got something close to five. 20 times the number of iot devices are OT devices compared to traditional it systems. So simply the scale of them.
They're everywhere and it's been one of the fastest growing categories for adoption. So therefore now you have them in scale. And again, I'll point to the IP camera example again, you see these iot devices outside of buildings hanging off of walls.
Sometimes with exposed ports to them. So, you know, those those elements have made iot devices more powerful more significant more present and therefore more exploitable by threat actors and organizations have woken up to that. Imagine we seeing malware go from some Edge device and start laterally moving through the entire Enterprise or these things fairly isolated semi isolated.
What's He get into an interesting debate about this and and by the way, I'll highlight that debate has shifted right about five years ago is I talked to people that iot security they would very often and have to be honest. They're very common answer and commonly accepted was oh, I'm safe. Everything's on a segmented Network.
We followed good best practices, right? So nothing's on a corporate Network that you know, the iot devices communicate only to themselves. We restrict things and and if there's a problem if there's a vulnerability we use network access control to shut off those devices so that they can't impact the network.
Well, okay think that through for a minute you've now shut off the business critical systems that are delivering profits and capabilities and maybe even life safety. To your organization and its employees and customers shutting off devices in the iot and OT world is not the right place to stop right shutting them off and mitigating an attack in in process. Absolutely good.
I mean we work every organization we work with has that as part of their their arsenal of how to defend themselves, but you have to always follow mitigation like that with remediation and coming back to the the segmented Network aspect these segmented Network so-called, um often as time goes on have punched through as often have issues and we don't see necessarily that the safety that's provided by a segmented network is really the right thing to to rely on fully right because we have tons of examples many of your viewers will have their own examples from their own operations of everything was on a segmented Network yet. It's still got breached. It's still got exploited and it's still caused consequences to the organization.
Rob Lee actually from from dragos. Wonderful OT ICS Security Company CEO there he said recently in a form. I was in that he talks to the boards of directors more now than he does to CIS and what he tells them is if you're see so comes in and tells you we're safe because everything's on a segment and Network.
Maybe time to change your Visa. And it sounds like we kill the patient to save the arm, right? Yeah, exactly.
Yeah, and also, you know, how you how you Store these systems too. You know, when you when you use mitigation, you also have to think through to the recovery aspect and you know what we offer, you know, and what we've really highlight for iot security in general is the idea that you need to both remediate and repatriate because what makes iot different in an Enterprise context Is that you have not just the devices themselves, right? I mean, you know, I'm wearing a fit that you might be wearing a Fitbit great.
Thank God. They don't have anything to do with each other, right? They are independent actors managing something for us.
That is what the predominant case of iot is in the consumer space. Go to the Enterprise. It's a hundred percent different in the Enterprise.
It's teams of devices working together combined with applications to make a workflow happen what's referred to as a tightly coupled environment as opposed to Loosely coupled and so with a tightly coupled iot environment where again, it's a system of devices with applications with maybe multiple parts of the network involved to manage the workflow in business result from it there. You have to really treat it a little bit differently great. So with tightly coupled iot the repatriation of things making sure that devices and their applications and the work product.
I'll come back to the way that they should be. So that's why things like doing a firmware update or a password update onto a device on your iot network usually requires also updating. For example that same password into the application.
That's what repatriation is is bringing everything back together. So Enterprise iot security is a little bit different than what you'd see in the consumer space. Who's in charge of Enterprise iot security because they used to be at least the iot team was in charge of their iot stuff and the security folks were working for an IT team and this coming together or are we still at loggerheads?
That's it. That's a great question. Mike.
You've you've talked to people I can tell so that see here's here's the here's here's how we see it. Right? There's a Evolution everybody's on a security Journey right and part of that security journey, I think involves breaking down the silos in an organization, right?
I mean look threat actors don't view an organization as the manufacturing Department the physical security team the facilities team the IT team, they see it as an organization if they find a way to breach that Organization for any of those elements they're going to so I think organizations realize that and they've now started to as part of that Journey that they're on start to break down those silos. We've got some some is leading customers who I'd say maybe five years ago started to redo it a good example is is one large Fortune 100 company, uh, their director of physical security technology five years ago. was basically told hey don't think of your job as physical security technology think of it as iot And then as they further evolved they got rid of.
Security being handled by any specific department. They formed the committee that brought in. The various constituents it the ceases office and so forth and that's enabled them to both move faster and quicker and smarter with respect to to meeting some of the demands on on iot security other organizations, right?
There. Are aren't quite there. That's why I would yeah Hazard say that that everyone is on a different Journey here and where they are on it.
Everyone's different. What's what's important is that people realize that there's a journey that there's Evolution and some of the markers along the way that we point to our for example if an organization is not using Asset Discovery and specifically agentless asset Discovery to get to the iot devices and OT devices and know everything that's in their inventory. If you're not doing that or not aware of the need to do that.
You're probably in an earlier stage of your security Journey with respect to iot right and we partner with Everyone in that space right and and they there's tremendous capabilities and solutions from people like armis and foreskout and Clarity in order and nozomi and there's a lot of good Solutions out there. So organizations who are ready to take these steps, you know, if you if you're not doing assets Discovery do it. If you're doing asset Discovery, then it brings you to the point of realizing.
Okay. I have devices that there and they're vulnerable then they're probably ready for what we do in our phase which is the remediation aspect of it. Right?
That's but would you be ready for us if you weren't already doing asset Discovery, maybe not so the market shifting another Point thing I point to you again, I'd say your viewers probably have seen the growth of this too. One of the most exciting developments to me too exciting developments one is you have now more information sharing in an industry level. than ever before and the the growth of isacks or you know call IT industry consortiums or information sharing even at a regional or local level within an industry.
That's moving the needle I mean, I'm I'm involved with one that I'm very proud of actually because the group's done tremendous work the real estate cyber Consortium. It and collectively the members represent something like 21 billion square feet of commercial real estate in in North America. Those organizations are working together because they've collectively realized safety which cybersecurity is a form of isn't something that you go it alone or you know, it's a competitive advantage that no you you collaborate on that.
We see the same in energy or oil and gas or financial services. I mean many Industries now have evolved towards information sharing and then the other forcing function in in a related ways that the you know, the US government has made significant strides strides. I mean everything from the focus on zero trust the national cybersecurity strategy that's been announced and deployed over a year ago.
You had legislation that passed through called cersea which requires reporting of cybersecurity incidents many other examples, right? the national the scissors Known exploited vulnerability catalog the Kev catalog. That's a significant significant element to putting some light onto the iot security as issues.
So whether it's industry level coordination or whether it's governmental coordination and pushing it out to Industries. There's a lot that's happened over the last few years to help people on that journey and to Define where they need to go and what steps they should be taking to to do it. And again, I'm going to point to the industry coordination.
It really helps to not just have to deal with this alone because it's it's a battle and our opponents are quite you know, quite significant and strong. So we need everything everything we can muster to to address iot security. Well that does bring us to a debate that's going on or the bad guys getting smarter or is it just that we have a bigger attack surface to defend and therefore we're seeing more incidents because the probabilities are in their favor.
It's both. I mean if you're to make me choose one, I choose the latter, right? I mean the attack surface growth and how how profoundly accessible it sometimes is again, I'll point to cameras hanging outside of buildings with exposed sports, right?
I mean So the scale of the attack surface we present to thread actors is is great. But the Weaponry that they're using is equally as is great, you know again things like again, I'll point back to the volume of invosity of DDOS attacks. There's there's definitely technology that they are deploying To both, you know distribute the Bots and plant botnet armies more effectively and then as they're utilized and attached to targets and Amplified their significant technology development that's gone on there.
The use of AI is everyone needs to talk about these days right? I just came out from RSA and the degree to which you know generative AI is helping both the Defenders and the attackers. Is is profound so it's an arms race.
Obviously, the the threat actors have moved to I'd say a organized crime type approach, right? These are gangs these are criminal organizations and you know the structure and size that they have is is is profound. So, you know, no it's it's a little bit of both, right they've gotten better in their attack methods and the the capabilities that they have to launch attacks and at the same time we present to them.
A larger attack surface with maybe more vulnerabilities that are you know more easily accessible than before it's combination. Much of our focus is on playing defense, but somebody once said the best defense is a good offense. So are you starting to see organizations and governments as a whole saying?
Hey, we're not taking this anymore. That's a great question, you know. You know, um, I know the desire to is there, let's be honest, right?
I mean we the community that we exist in. Is a quite competitive Community, right? And so without without question there would be a desire to take it back to the to to the attackers or throw it back at them at some point.
Um, but but yeah a more serious answer would be that that no we are not yet at the state where we could be offensive in the capabilities. You do read and hear and see some of the gangs that are out there being taken down every now and then but it's still an issue of whack-a-mole right as soon as you defeat one gang a similar situation pops up elsewhere the degree to which threat vectors or attack vectors are democratized and spread around within that Community is significant. So I don't think we're quite yet at that point.
Otherwise, you'd be seeing I mean to me the form of taking it back to them. Is actually not in the cyberspace. It's in the physical space you'd see arrests, you'd see more hunting down of these these criminals.
And again, I'll point to an issue. I've been sort of looking at which is when when and how and maybe an example of what you're saying is when and how do we as an industry start to shift from? You know DDOS mitigation, which is what everybody does.
And there's great Technologies for it, but we're focused on mitigation. When do we start to focus on eradication right? When do we get to rooting out from the iot devices that they're housed?
And when do we root out the botnets that literally are existing in volume in so many places, right? That's a part of this industry that I I'm just fascinated by because Behind having these botnet Army's assembled is again an Enterprise they have priceless. Right.
They have they have Boards of directors. They've got quarterly sales targets there. I mean, they're operating in a very driven in business oriented fashion.
And so the the ability to go on the dark web and to harness tremendous power from these Bots is only because we're focused on mitigation. Right if we eradicated them. Oh their business model goes away.
So again, I I'd love to say that we're taking it back to them. I don't think we're quite there. I think every every security organization is so overstretched is so driven by What might be well sounding and good sounding priorities, but then you realize.
Maybe there's other priorities that should have been ahead of them. It's it's hard, you know, I mean as we deploy more automation as we allow more AI capabilities to share the workload with the humans that that operate security operations in in organizations. Maybe we'll get the the bandwidth where we can start to take it back to them.
But the the current bandwidth priorities You know, it's a it's it's a tough race. I have a lot of respect for you know, again the practitioners in this community because it's it's it's a challenge that really overwhelms many organizations to that. All right, folks, we may be on the cusp of something here.
How about this? Maybe we give as good as we get that's a new thought and a new idea John. Thanks being on the show.
No, sure money this great talking to you. All right. And back to you guys in the studio.