IoT security survey reveals alarming challenges and costs

security system locks data computer safety Image by vecstock on Freepik

Keyfactor and Vanson Bourne have released findings from an independent survey and analysis that examines the state of IoT security for both manufacturers and end users. The report, “Digital Trust in a Connected World: Navigating the State of IoT Security,” reveals concerns and challenges modern businesses face when establishing digital trust in today’s connected world, and shows nearly all organisations (97%) are struggling to secure their Internet of Things (IoT) and connected products to some degree. The research survey also found that 98% of organisations experienced certificate outages in the last 12 months, costing an average of over US $2.25 million. 

“Organisations worldwide are under mounting pressure to ensure their IoT and connected devices are protected while navigating an increasingly complex digital landscape that requires complete trust,” said Ellen Boehm, senior vice president, IoT strategies and operations at Keyfactor. “The results of this survey demonstrate the importance of identity-first security for those who manufacture IoT devices and those who deploy and operate them in their environment to establish digital trust at scale. Most organisations implement public key infrastructure (PKI) solutions in their IoT security strategy, which is a huge step in the right direction. However, it’s clear that with 97% of organisations facing IoT security challenges, security teams are struggling to leverage their tools efficiently. Ensuring that IoT device security is managed throughout its lifecycle will go a long way in both eliminating costly certificate outages and enhancing the long-term viability of IoT within the enterprise.”  

The costly outages organisations have faced in the past year are not the only expense of inefficient IoT security. The report found that 89% of respondents’ organisations that operate and use IoT and connected products have been hit by cyber-attacks at an average cost of $250K. In the past three years, 69% of organisations have seen an increase in cyber-attacks on their IoT devices. The March attack on Amazon’s Ring that exfiltrated sensitive customer data such as recorded footage and credit card numbers is an example of the increase in IoT attacks.  

“Many IoT security strategies fail to prevent and protect against IoT-targeted cyber-attacks because organisations lack the proper education and support needed to fully understand the task at hand,” said Boehm. “Over half of respondents agree that their organisation doesn’t have the proper awareness and expertise to prepare for IoT device cyber-attacks, spotlighting the need for more guidance to fully secure their devices. Organisations can’t protect against what they cannot understand.” 

Other key themes and findings from the report include:  

Proliferating growth of IoT devices and connected products in organisations

In the past three years, respondents reported a 20% average increase in the number of IoT and connected products used by organisations.

IT professionals are not fully confident in the security of their IoT and connected devices

Most organisations (88%) agree that improvements are needed in the security of IoT and connected products in use within their organisation, with over a third (37%) of respondents reporting that significant improvement is needed and 60% reporting that some improvement is needed. When it comes to specific strategies, 4 in 10 organisations report that they strongly agree they would benefit from using a PKI to issue digital identities on the IoT and Industrial Internet of Things (IIoT) devices in their environment. 

IoT security budgets are increasing but are being used to cover staggering costs from certificate outages

While budgets for IoT device security are increasing year over year, with an anticipated increase of 45% in the next five years, half (52%) of that budget is at risk of being diverted to cover the cost of successful cyber breaches on IoT and connected products. 

Organisations and manufacturers are split on who is responsible for IoT security

Of the respondents surveyed, 48% believed that the manufacturer of IoT or connected devices should be at least mostly responsible for cyber breaches on their products. 

The study was conducted by Vanson Bourne on behalf of Keyfactor with responses from 1,200 IoT and connected product professionals across North America, EMEA, and APAC. All respondents had some responsibility or knowledge of IoT or connected products within their organisation, and included original equipment manufacturers (OEMs) and those who are using and operating connected devices within their organisation.

Comment on this article below or via Twitter: @IoTNow_

RECENT ARTICLES

Carson City upgrades to Iteris’ advanced Vantage Apex sensors

Posted on: April 26, 2024

Iteris has announced that Carson City, Nevada has chosen to upgrade the city’s intersection detection sensors to Iteris’ Vantage Apex hybrid sensors.

Read more

Make the Intelligent Choice: Embed X103 in Smart City Outdoor Devices

Posted on: April 25, 2024

The adage “less is more” is the current state of digital transformation, starting with existing technology that has already proven successful – and then further adapting and streamlining. The “smart

Read more
FEATURED IoT STORIES

What is IoT? A Beginner’s Guide

Posted on: April 5, 2023

What is IoT? IoT, or the Internet of Things, refers to the connection of everyday objects, or “things,” to the internet, allowing them to collect, transmit, and share data. This

Read more

The IoT Adoption Boom – Everything You Need to Know

Posted on: September 28, 2022

In an age when we seem to go through technology boom after technology boom, it’s hard to imagine one sticking out. However, IoT adoption, or the Internet of Things adoption,

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into

Read more