Consumers Lack Confidence in IoT Security
In an increasingly breach-shy, but connected world, 90% of consumers lack confidence in Internet of Things security; and some two-thirds of consumers and almost 80% of organizations support government-set IoT guidelines.
Amsterdam-based digital-security firm Gemalto revealed in a report, “The State of IoT Security” that both consumers and businesses have serious concerns around IoT security and little confidence that IoT service providers and device manufacturers can protect IoT devices and more importantly the integrity of the data created, stored and transmitted by these devices.”
“With legislation like GDPR showing that governments are beginning to recognize the threats and long-lasting damage cyberattacks can have on everyday lives, they now need to step up when it comes to IoT security. Until there is confidence in IoT amongst businesses and consumers, it won’t see mainstream adoption,” Jason Hart, CTO, Data Protection at Gemalto said.
• Most organizations (96%) and consumers (90%) believe there is a need for IoT security regulations, and want government involvement.
• A hacker controlling IoT devices is the most common concern for consumers (65%), while six in ten (60%) worry about theft of their data.
• More than two-thirds (67%) of businesses encrypt all data captured or stored via IoT devices.
Consumers’ main fear (cited by two thirds of respondents) is hackers taking control of their device. this was more concerning than leaked data (60%) and hackers accessing their personal information (54%). Despite 54% of consumers owning an IoT device (on average two), just 14% believe that they are extremely knowledgeable when it comes to the security of these devices.
In terms of the level of investment in security, the survey found that IoT device manufacturers and service providers spend just 11% of their IoT budget on securing their IoT devices. The study found that these companies do recognize the importance of protecting devices and the data they generate or transfer with 50% of companies adopting a security by design approach. Two-thirds of organizations report encryption as their main method of securing IoT assets with 62% encrypting the data as soon as it reaches their IoT device, while 59% as it leaves the device. Ninety two percent of companies also see an increase in sales or product usage after implementing IoT security measures.
According to the survey, businesses favor regulations to make it clear who is responsible for securing IoT devices and data at each stage of its journey (61%) and the implications of non-compliance (55%). Almost every organization (96%) and consumer (90%) is looking for government-enforced IoT security regulation.
Businesses are realizing they need support in understanding IoT technology and are turning to partners to help, with cloud service providers (52%) and IoT service providers (50%) the favored options. When asked why, the top reason was a lack of expertise and skills (47%), followed by help in facilitating and speeding up their IoT deployment (46%).
While these partnerships may benefit businesses in adopting IoT, organizations admitted they don’t have complete control over the data that IoT products or services collect as it moves from partner to partner, potentially leaving it unprotected.
“The lack of knowledge among both the business and consumer worlds is quite worrying and it’s leading to gaps in the IoT ecosystem that hackers will exploit,” Hart continued. “Within this ecosystem, there are four groups involved – consumers, manufacturers, cloud service providers and third parties – all of which have a responsibility to protect the data. ‘Security by design’ is the most effective approach to mitigate against a breach. Furthermore, IoT devices are a portal to the wider network and failing to protect them is like leaving your door wide open for hackers to walk in. Until both sides increase their knowledge of how to protect themselves and adopt industry standard approaches, IoT will continue to be a treasure trove of opportunity for hackers.”
In other news Gemalto and hardware wallet provider Ledger are pooling their efforts to create a new secure storage solution for financial institutions working with cryptocurrency. The new partnership will apply Ledger's hardware wallet operating system, BOLOS, with Gemalto's cryptographic key storage system to create a device geared towards the management of crypto-assets.