Report | IDC IoT Security 2023 Challenges and Solutions, 2023
Discover how IoT is transforming industries while introducing new security risks. This report examines critical threats, including ransomware and healthcare vulnerabilities, and highlights strategies to safeguard against evolving cyber challenges. Download now to explore key insights and solutions.

SPOTLIGHT Sponsored by: Check Point
IoT Security 2023: Challenges and Solutions August 2023
Written by: Frank Dickson, Group Vice President, Security and Trust
Introduction Despite its name, the Internet of Things (IoT) is not a single monolithic structure but an umbrella category of thousands of digitally transformed solutions that create value by connecting "things" that were once not connected. The ability to connect these devices is the first step to unleashing or revealing new business models. Distributed technical architectures that combine sensors, intelligent systems, connectivity, platforms, and analytical capabilities are evolving into fully formed use cases for remote health monitoring, autonomous vehicles, and smart utilities, among others, which are poised to deliver great value and create new markets.
IDC defines an IoT solution as "a network of uniquely identifiable endpoints (or things) that autonomously connect bidirectionally using IP connectivity. IoT brings meaning to the concept of ubiquitous connectivity for businesses, governments, and consumers with its innate management, monitoring, and analytics."
The scope of the definition is not limited to traditional consumer devices but encompasses an almost unlimited number of use cases within the enterprise, operational technology (OT), industrial IoT (IIoT), and Internet of Medical Things (IoMT). IoT technologies promise to deliver great value, but the adoption and proliferation of IoT capabilities also bear new risks. Security is paramount to many organizations as they realize how usage scenarios may be affected by compromises to the control, availability, integrity, and confidentiality (CAIC) of devices and data.
The IoT Threat Landscape The security threat is very real. Proof-of-concept exploits and real-world compromises highlight some of these risks. Recent disclosures from the Cybersecurity and Infrastructure Security Agency (CISA) and other agencies around Cuba ransomware and Hive show that threat actors have a substantial monetary and functional impact on critical infrastructure globally. Cuba ransomware has compromised over 100 entities globally, resulting in the loss of $60 million by these entities, and Hive has compromised over 1,300 entities globally, causing them to lose over $100 million. These
As the IoT and OT begin to deliver value, the adoption and proliferation of IoT capabilities also bring new risks. Security is paramount to many organizations as they realize how usage scenarios may be affected by compromises to the control and availability of devices and data integrity.
KEY TAKEAWAYS » Recent cyberattacks against IoT systems
have demonstrated serious real-world consequences.
» To deliver IoT security and trust, organizations must focus on connectivity, hardware, software, and the environment.
» IoT security may be required in various parts of the ecosystem based on the technical architecture and particular use cases.
»Not all device manufacturers or their users will accommodate agent installations. Alternative approaches will be required.
AT A GLANCE
Page 2 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
two ransomware groups only make up a small sample of the threat at hand, but they have been focused on critical infrastructure and show that real-world impacts and consequences are felt daily.
The disclosure of details regarding Cuba ransomware and Hive may in part be a result of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), which is yet to legally be enforced (current disclosures are voluntary until rules are finalized), and likely only the beginning of the discovery phase for cyberthreats facing critical infrastructure. This highlights the importance of CISA and the initiatives that it started in 2022, which aim to drive awareness of and influence protection against the threats facing critical infrastructure. However, these disclosures are still in their infancy, and hard lessons may pave the road ahead as critical ecosystems struggle to modernize and harden against a growing threat landscape.
In addition, the security of medical facilities and devices has been a growing concern after the COVID-19 pandemic raised their level of priority among bad actors and resulted in the first human death from ransomware-related effects on healthcare systems in 2021. These types of attacks are high profile, and hospitals are often unique among critical infrastructure market verticals owing to their higher obligation to disclose attacks because of their direct impact on patient health and human safety. This has accelerated medical security as a priority while CIRCIA attempts to uncover the severity and scope of ransomware and other attacks impacting more industrial-critical infrastructure verticals. Cybersecurity vendors have recognized the burden facing the medical industry and responded appropriately.
Medical cybersecurity may be a sign of things to come, as other critical infrastructure verticals uncover and disclose cyberattacks that have previously gone unreported. The foundation for security improvements in critical infrastructure is already being paved, since the infrastructure law, passed on November 15, 2021, includes $1 billion in funding for cybersecurity, which will be allocated to state, local, and territorial governments in the United States. With $185 million available in 2022, IDC expects the spending pace to increase in 2023, which will enable critical infrastructure security improvements simultaneously as the Cyber Incident and Reporting Act unveils the scope and severity of attacks currently taking place.
The race to outpace new and existing threats in 2023 is already on. 2022 was a significant year for critical infrastructure cybersecurity news and announcements, including CISA's creation of operation Shields Up and CIRCIA, an advisory from the president of the United States, and new malware for industrial control systems (INCONTROLLER and INDUSTROYER.V2) discovered throughout the year. However, 2023 promises to increase the stakes as geopolitical tensions continue to rise, the proliferation of ransomware is expected to accelerate, and CISA's Shields Up and the Cyber Incident and Reporting Act begin to have a more material effect.
Finally, IoT can be susceptible to a variety of attacks, including botnets, distributed denial of service, crypto miners, Mirai, and ransomware. IoT devices, such as speakers and IP cameras, have become increasingly common in remote work and learning environments, providing cybercriminals with a wealth of potential entry points.
Consider this scenario: An unknown IoT device is placed into an enterprise network behind perimeter defenses, such as firewalls, intrusion prevention systems (IPSs), and other IT infrastructure, so that the device has unfettered access to all corporate network resources. A web server is embedded into the device to maximize its functionality. All the ports are set to "open" by default and enable as much as a gigabit of Ethernet connectivity, which makes the device accessible. The device has a rich operating system (OS), such as Linux, to maximize functionality. The device will not be examined on an
Page 3 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
ongoing basis using the enterprise's vulnerability scanner because the embedded web server will likely light up the organization's security information and event management tools like a Christmas tree with false positives. The vulnerability scanner will be configured to ignore the device, meaning that it will not be updated, maintained, or patched over the device's 5- or, sometimes, 10-year useful life. Device protection will consist of a default password, and unvetted third parties will maintain the device. It will be core to organizational productivity, so there will be 1 device for every 10 employees. Some might call this a nightmare; others might call it a printer.
IoT and OT Security Objectives The practice of protecting any set of computing assets — information or data, executable software, and physical devices — must begin with a set of objectives. In IT risk management, the standard is the confidentiality, integrity, and availability triangle. However, IoT spans both the digital world and the physical world, with OT systems being perfect examples. IT security is primarily concerned with protecting enterprise data and digital assets, whereas OT security is concerned with protecting physical assets and the data flow. The proliferation of computing resources in the form of devices that provide process control or functions other than processing information requires a broader and reordered set of objectives, namely CAIC:
» Control: Maintaining control of all physical assets is necessary to ensure safe operation.
» Availability: The systems need to be available and work as designed and expected (in some instances, 24 x 7 x 365).
» Integrity: The transmitted data must be trustworthy and accurate so that devices make the right decisions or take the right actions to support safety and availability.
» Confidentiality: Confidentiality is far less of a concern for OT data than it is for IT data, but there are instances, such as security video data, where it is important that only the appropriate parties can access it.
As we look to implement controls, as stated previously, IoT is not a single monolithic structure but an umbrella category of thousands of digitally transformed solutions that create value by connecting things that were once not connected. Different use cases create different concerns and priorities. Every business needs to look at concerns that are relevant to its industry (see Figure 1).
Page 4 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
FIGURE 1: Industry-Level Nuances in Device Security Concerns Are Important for IoT Solution Design, Deployment, and Go-to-Market Planning Q Which three aspects of your organization's IoT deployment concern you the most from a device
management/security perspective?
n = 1,792
Notes:
Rank 1 = most chosen response among the top 3; rank 7 = least chosen response among the top 3.
Ranks are assigned the same number in instances where percentage of responses are equal.
Values in bold represent the top 3 choices.
Source: IDC's U.S. IoT Decision Maker Survey, July 2021
Looking at IoT Security Trends for 2023 and Beyond The turning of the calendar page does not mark an end to the old trends, which will continue into 2023 and mature. The growing number of devices will be a key trend. The benefits of connected devices will lead to their increased dependency, and they will replace retired, non-connected devices.
The maturation of the threat landscape forces an advancement of the IoT security agenda, moving from inventory and visibility to prioritization and prevention, from siloed to holistic, from reactive to proactive, from severity focused to risk centric, from manual to automated, and from intermittent to continuous. Third-party risks will be top of mind, as software supply chains are likely to be a leading target for IoT attackers for the next several years. This is increasing the interest in incorporating upcoming software bills of material (SBOMs) into asset inventory, risk assessment, and vulnerability management for IoT, OT, IIoT, and IoMT. Finally, there will be a growing interest in and maturation of IoT security for edge and 5G networks as they begin to be used within enterprises.
Rankings by Industry Overall Total
Financial Services
Government Health Life Science Manufacturing Retail/
Wholesale Energy/ Utilities
Hospitality Transportation
Concerns about who can access data generated from IoT devices
1 1 1 1 1 1 3 1 3 2
Concerns about protecting IoT data in movement and data at rest
2 2 2 1 2 2 6 6 1 1
Lack of security tools designed for operational technology environments
3 4 3 3 3 3 2 2 2 3
Lack of visibility into the security status of the endpoints on our network
4 6 3 4 5 4 5 4 4 5
Inability to run security software on compute-constrained devices
5 5 5 4 4 5 1 3 6 6
Inability to do reliable software updates for IoT devices
6 3 6 6 7 5 4 4 7 7
Lack of visibility into what IoT endpoints are on our network
7 7 7 7 5 7 7 7 5 4
Page 5 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
CISOs are looking to bring maturity to IoT security to extend zero trust to IoT/OT/IoMT. Migration to the cloud results in direct IoT-to-cloud interactions, and applying zero trust principles to IoT/OT/IoMT devices/networks will increase their security posture but will likely require new access policies, practices, solutions, and devices. Although new devices are expected to be more secure, legacy devices are inherently insecure and can have very long life cycles. Secure onboarding and life-cycle management are needed because of the breadth of the very different types of devices to be handled.
Network segmentation is a challenge for many organizations because it relies on precise asset inventory, a dynamic understanding of network communications, and the ability to control this communication for all devices on the network. Micro-segmentation continues to be a difficult and time-consuming strategy to operationalize because of the difficulty of creating and validating device profiles and justified risk aversion around breaking device functionality.
Many IoT solutions are still too focused on patching and do not provide enough guidance on the mitigation of vulnerabilities when patches are not available. The time from vulnerability disclosure to remediation must be shortened. Because no organization can effectively manage and deploy security policies at the scale that most require, automation is critical. Automating manual processes to build an accurate IoT asset inventory complete with vulnerability data will reduce resource requirements. Most security and network automation solutions are rarely up to the task of covering IoT infrastructure without a great deal of customization and effort. The choice of automation platform is a strategic decision that is typically driven by the IT/cloud infrastructure team rather than the operational side of the organization.
Expect to see tighter integrations of IoT/OT/IIoT/IoMT security offerings with existing and complementary IT security services and products, including zero trust; security orchestration, automation, and response; extended detection and response; a configuration management database; and attack surface management. The goal is to quickly detect any IoT breaches, make smart decisions on how to contain and minimize their impacts, and then patch, mitigate, or remediate the problems. Tighter integration could come from enhanced product offerings via vendor partnerships or acquisitions or from using managed security service providers. IoT/OT/IoMT-specific playbooks by vertical industries are needed so that safety and availability of industry-specific devices and systems are not compromised. Automation tools have the potential to reduce the number of resources required.
Check Point IoT and OT Security Solution Check Point Software Technologies provides governments and enterprises with cybersecurity solutions that are designed to protect them against cyberattacks such as malware, ransomware, and phishing. The solutions span network security, IoT security, endpoint security, cloud security, mobile security, data security, and security management. The company focuses on the following IoT sectors:
» Enterprise smart offices and smart buildings
» Medical devices
» Industrial devices
» IoT device manufacturers
Page 6 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
Check Point's Quantum IoT Protect provides automatic zero trust protection, innovative threat prevention, firmware scanning, and on-device runtime protection for enterprises. The security solution is built on multiple tenets:
» IoT discovery and risk analysis: Check Point's Quantum IoT Protect can identify, classify, and analyze IoT devices, providing identity details, such as device type, vendor, model operating system, and OS version. In addition, it analyzes the risk that the device poses in the network based on indicators such as known vulnerabilities and connection types. It also offers a powerful API that ensures secure and reliable integration within the IoT ecosystem. Check Point's strategic partnerships with leading IoT discovery vendors enable the delivery of advanced discovery capabilities tailored to specific market sectors, such as healthcare, industrial, and critical infrastructure. This collaboration enables Quantum IoT Protect to stay at the forefront of providing state-of-the-art security solutions for diverse IoT devices.
» Autonomous IoT zero trust network access: The solution offers robust protection for IoT devices, preventing unauthorized internet access and communication. It reduces the attack surface by applying zero trust policies based on device attributes and risk profiles. Real-time enforcement ensures that IoT devices cannot compromise other assets or communicate with malicious sites. The solution incorporates patented technology that automatically creates and enforces zero trust network profiles on Quantum Security Gateways, safeguarding the organization from unauthorized access and potential damage. These autonomous zero trust network profiles leverage advanced AI technologies, research, and behavior analytics to extend zero trust practices to IoT assets. The solution's ability to adapt in real time addresses the dynamic nature of IoT and OT environments.
» IoT threat prevention: The solution leverages its IPS to provide real-time blocking of attempts to exploit known IoT vulnerabilities. With over 10,000 protections for IT and IoT vulnerabilities, including hundreds specifically designed for industrial control systems, the solution offers comprehensive defense. These protections can be applied as virtual patches, which is invaluable considering the challenges associated with patching IoT devices. Factors such as device location, mission-critical runtime, and complex protocols make traditional patching difficult. By utilizing virtual patching and real-time IoT threat intelligence from Check Point's ThreatCloud, the solution effectively blocks both known and zero-day attacks. This powerful combination incorporates the latest AI technologies and utilizes big data threat intelligence shared across a vast network of 100 million endpoints, gateways, and IoT devices worldwide to aid in accurate prevention.
» Unified policy events and management: Quantum IoT Protect seamlessly integrates with Check Point's Infinity security management architecture, providing unified access control policies and simplified threat investigation through a single console. The cloud assist feature enables autonomous monitoring of IoT logs and data using behavior-based AI and ML tools, which automatically update on-premises security management IoT access control and threat prevention policies. With Quantum IoT Protect, organizations can leverage end-to-end solutions and comprehensive functionality through a unified management console. This integration is facilitated by the new Quantum Cyber Security Platform "Titan" release (R81.20), offering streamlined access control policy definition and threat investigation in a single pane of glass.
Enterprises typically begin IoT projects with the need for discovery capabilities to map at-risk devices in their environments. For IoT risk analysis, Check Point's Quantum IoT Protect discovers devices, assigning each one to a
Page 7 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
descriptive category (e.g., device type and manufacturer) and mapping its current relationship in the customer's environment.
Check Point's Quantum IoT Protect capabilities are actively evolving as the solution utilizes visibility, network behavior, and segmentation data from many of the company's customers to drive the efficiency and effectiveness of policy creation and enforcement.
Check Point IoT Device Security for Manufacturers
Quantum IoT Protect combines firmware scanning for vulnerabilities and real-time threat blocking to provide robust IoT device security. The solution ensures continuous security updates by monitoring the device's firmware. With Quantum IoT Protect, device manufacturers can develop connected IoT devices with embedded firmware security, thanks to Check Point's Nano Agent. Installed on the IoT device, this agent works alongside the device manufacturer to monitor its state and detect anomalies, allowing for the identification and remediation of zero-day attacks. Check Point emphasizes the importance of conducting IoT threat prevention within devices and during runtime. To achieve this, a Nano Agent, customized for each specific device, is utilized. Collaborating with device manufacturers, the Check Point Nano Agent can be integrated during the device manufacturing process or added later as a software update. Once deployed, the Nano Agent collects device information, which is sent to the Check Point Cloud Services. In return, a tailored application for each device is sent from the Cloud Services and installed alongside the device's firmware, providing customized threat prevention capabilities.
Challenges
Many IoT devices have limited processing power, memory, and battery life. Security solutions need to be optimized to work within these constraints. Consequently, alternative approaches, such as network-level security, will be required. Such approaches could add to the cost and complexity of designing and managing IoT security and subsequently restrain market demand. Granted, Check Point has both IoT network security and on-device IoT security to compensate. Network-based solutions may be limited in some remote use cases.
Finally, there are challenges that will be faced in implementing with most IoT security vendors, including Check Point. The lack of standardized security measures across IoT devices can complicate the implementation of security solutions. Check Point's IoT security might face difficulties in accommodating the diverse security practices implemented by different manufacturers. IoT devices can collect and process sensitive data, raising privacy concerns. The security of IoT devices can be compromised due to user errors, such as weak passwords or misconfigurations.
Conclusion Although IoT and OT technologies deliver great value, and the adoption and proliferation of IoT capabilities continue to accelerate, these developments come with additional security risks. Prevention and proactive defense are two guiding principles for the coming years. Transition to risk management, not just vulnerability patching. If IT and OT/IIoT/IoMT are managed by separate teams within your organization, help them reach the common goal of maintaining network security. IoT/OT/IIoT/IoMT require their own playbooks, so ensure these playbooks are in place before an incident and test them regularly.
Page 8 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
Raise the priority of cybersecurity for IoT/OT/IIoT/IoMT to the C-suite or board level. Financial, safety, compliance, and reputational risks continue to increase. Ransomware attacks are growing and causing devastating damage to companies of all sizes. One breach of an undersecured IoT device is all it takes for an attacker to gain access to an IT network. If you are in an affected industry, investigate what new regulations are underway to understand what the requirements will be for compliance.
Most companies cannot do it all themselves. Demand more secure devices from your vendors and ask for their processes and procedures for updates and patches. Even though requirements and procedures are still in development, ask about the SBOM. As IoT scenarios and use cases play out, IDC believes that the market for IoT security will continue to grow in importance.
To the extent that Check Point can address the challenges described in this paper, the company has a significant opportunity for success, as more unique security needs arise based on changing threat models.
About the Analyst
Frank Dickson, Group Vice President, Security and Trust
Frank Dickson is the group vice president for IDC's Security and Trust research practice and leads the team that delivers compelling research in the areas of security services; information and data security; endpoint security; trust; governance, risk, and compliance; identity and digital trust; IoT security; network security; privacy and legal tech; security analytics; video surveillance; and application security and fraud. Topically, Frank provides thought leadership and guidance for clients on a wide range of security topics, including ransomware and emerging products designed to protect transforming architectures and business models.
Page 9 #US51150823
SPOTLIGHT IoT Security 2023: Challenges and Solutions
MESSAGE FROM THE SPONSOR
About Check Point Software Technologies Ltd.
Check Point Software Technologies Ltd. (www.checkpoint.com) is a leading provider of cyber security solutions to corporate enterprises and governments globally. Check Point Infinity's portfolio of solutions protects enterprises and public organizations from 5th generation cyber-attacks with an industry-leading catch rate of malware, ransomware, and other threats. Infinity comprises four core pillars delivering uncompromised security and generation V threat prevention across enterprise environments: Check Point Harmony, for remote users; Check Point CloudGuard, to automatically secure clouds; Check Point Quantum, to protect network perimeters and datacenters, all controlled by the industry's most comprehensive, intuitive unified security management; and Check Point Horizon, a prevention-first security operations suite. Check Point protects over 100,000 organizations of all sizes. Determine your IoT security risk through a Free IoT Security Check Up and Device Firmware assessment. Sign up today at: https://www.checkpoint.com/quantum/iot-protect/.
The content in this paper was adapted from existing IDC research published on www.idc.com.
IDC Research, Inc.
140 Kendrick Street
Building B
Needham, MA 02494, USA
T 508.872.8200
F 508.935.4015
Twitter @IDC
idc-insights-community.com
www.idc.com
This publication was produced by IDC Custom Solutions. The opinion, analysis, and research results presented herein are drawn from
more detailed research and analysis independently conducted and published by IDC, unless specific vendor sponsorship is noted. IDC
Custom Solutions makes IDC content available in a wide range of formats for distribution by various companies. A license to distribute
IDC content does not imply endorsement of or opinion about the licensee.
External publication of IDC information and data — Any IDC information that is to be used in advertising, press releases, or promotional
materials requires prior written approval from the appropriate IDC vice president or country manager. A draft of the proposed document
should accompany any such request. IDC reserves the right to deny approval of external usage for any reason.
Copyright 2023 IDC. Reproduction without written permission is completely forbidden.