European survey finds 65% of enterprises lack view and control of IoT devices on their network
ForeScout Technologies Inc, a provider in agentless cybersecurity, has announced the findings of its new European Perceptions, Preparedness and Strategies for IoT Security survey.
The research revealed that while the majority of respondents acknowledge the business opportunity presented by the Internet of Things (“IoT”), and the growing number of IoT devices connected to their enterprise networks, their organisations lack understanding of how to properly secure them.
“The staggering growth of IoT is creating both value and risks for enterprise organisations,” said Jan Hof, International Marketing director, ForeScout Technologies. “While IoT is recognised by many as an opportunity to improve and streamline business processes, there are associated security risks that need to be addressed – first and foremost through visibility of devices as soon as they connect to the network. You cannot secure what you cannot see.”
Commissioned by ForeScout and conducted by a non-affiliated third party, Quocirca, the survey of 201 senior IT decision makers in the UK and German speaking regions of Germany, Austria and Switzerland (‘DACH’) assessed their organisations’ IoT security practices.
Key findings from the survey include:
- Increased size and diversity of attack surface: The average business expects to be dealing with 7,000 IoT devices over the next 18 months. Even smaller businesses expect the numbers to be hundreds or thousands; far more than they are used to securing when it comes to traditional user endpoints.
- Healthcare lagging in IoT readiness: One third of respondents say the IoT is already having a major impact on their organisation and a further third expect it to soon. IT and telecoms are the most advanced industries in terms of IoT readiness with healthcare, which many think stands to benefit significantly from the IoT, lagging behind.
- Uncertainty over identification and control: 65% of respondents have ‘quite’, ‘little’ or ‘no’ confidence in terms of being able to identify and control all IoT devices on their network. This uncertainty is substantiated by the fact that many IoT operating systems are open source and can therefore be adapted by device manufacturers, leading to many variants.
- Agentless approach is the only way: Being able to discover and classify IoT devices without the use of agents (most of which will only support popular operations systems such as Windows, Android, iOS and OS X) was perceived by 64% of respondents as ‘extremely important’ or ‘quite important’, with this figure increasing to 73% within the healthcare sector, which has the most unusual range of devices including CT scanners, diabetic pumps and heart monitors.
- Biggest IoT security challenge? IT functions working together: Getting the various IT functions (networking, security, DevOps, etc.) at an organisation to work together was perceived by 83% of respondents as one of the top IoT security challenges. A minority of survey participants considered lack of personnel to be problem, but well over half worry about budgets and the availability of appropriate products.
Bob Tarzey, analyst and director at Quocirca (who conducted the survey), said, “IoT deployments already involve millions of devices in businesses across Europe. Many will have limited processing power and require low power usage. Others will have unusual operating systems and, in certain cases, the Things involved will be unknown to IT security teams when they first request network access. All of this requires tools that can manage and understand the security status of all network attached devices, without the need to install agents.”
ForeScout commissioned Quocirca to conduct the “European Perceptions, Preparedness and Strategies for IoT Security” survey from August – September 2016. The survey of 201 senior IT decision makers in the UK and German speaking regions of Germany, Austria and Switzerland (‘DACH’) analysed and assessed respondents’ views on their organisation’s IoT devices, security policies, approaches and tools.
The research covered a range of industry sectors and businesses with as few as 10 employees, up to large enterprises with more than 10,000 employees. The research follows on from an earlier survey carried out in the U.S. by Webtorials in March – April 2016. To download the full European report, please go here.
Comment on this article below or via Twitter: @IoTNow_ OR @jcIoTnow