“Celebrity” vulnerabilities like BlueKeep attract the attention and resources of security teams, often hogging the spotlight, allowing other, less visible, but just as dangerous, weaknesses that could be exploited by bad actors to go unnoticed. IoT devices are a perfect case in point.
Last week, Infosecurity Magazine reported on the discovery of a series of new zero-day vulnerabilities, dubbed “Ripple20”, that puts hundreds of millions of IoT devices at risk. Found in power grids, data centers, small businesses, and Fortune 500 companies, the flaws could lead to data theft from printers, tampering with medical devices, or the forced malfunction of industrial control systems devices.
To protect their digital assets, organizations must act quickly to mitigate the risks posed to their IoT devices. Below are several measures to consider.
Achieve visibility into cyber risk across the digital ecosystem
To mitigate against the risk of Ripple20 and other vulnerabilities that can open the doors to a breach, organizations must have broad and continuous visibility into their expanding digital footprint.
Bitsight for Security Performance Management addresses this need by enabling organizations to gain additional context into everything that’s connecting to their network, including older or forgotten IoT devices. Through the Bitsight platform, organizations can continuously monitor for and identify gaps in cybersecurity controls — such as misconfigurations, vulnerabilities, and unpatched systems — in the cloud; on-premise; and across geographies, subsidiaries, and their remote workforce. With this visibility, security teams can quickly prioritize remediation and allocate resources more effectively.
These insights can also inform where network segmentation strategies should be deployed, allowing teams to isolate key networks based on their potential for risk. Segmentation is particularly effective at mitigating vulnerabilities like Ripple20 that take advantage of connected devices that have yet to be, or cannot be, patched.
Despite its effectiveness, segmentation can be quite an undertaking and organizations need to make informed decisions about when and where to implement it. As such, it’s critical that they have a good understanding of their organization’s overall cybersecurity risk posture.
Understand cyber risk in the supply chain
The JSOF research lab, which detected Ripple20, named it as such to reflect the widespread impact or “ripple effect” of the vulnerabilities as a natural consequence of the supply chain. "A single vulnerable component, though it may be relatively small in and of itself, can ripple outward to impact a wide range of industries, applications, companies, and people," wrote the researchers.