The world around you is brimming with Internet of things (IoT) devices. Sure, devices like our computers or smartphones have always relied on Internet access, but now the network is expanding. Think smart watches, security cameras, medical sensors, smart refrigerators… The list could go on and on.
The Internet is connected to countless devices, promoting convenience and efficiency for consumers globally, but also for businesses. The digital trend is not predicted to stop any time soon, with the number of connected devices expected to more than double from 14 billion units in 2021 to 31 billion by 2025.
Do IoT devices matter to businesses?
IoT devices might mainly be considered consumer goods, but businesses also are relying on them to ease workloads and get a leg up in their supply chains (say, with energy efficient smart thermostats and lights in the office or warehouses). Employee-owned IoT devices may also connect to an organization's network, whether remotely or during on-site work, expanding the attack surface of the business piece by piece.
But an employee’s smartwatch shouldn’t pose a cybersecurity risk to your organization, right?
Traditionally, prioritizing monitoring and analysis of cyber risk meant managing high-stakes vendors like a cloud service provider or HR tool with extra care, because they hold information that bad actors want the most. New research has revealed that seemingly benign IoT devices hold hidden risk previously unimaginable.
A harsh reality – IoT devices can wreak havoc on consumers and organizations
Bitsight recently discovered six severe vulnerabilities in a popular vehicle GPS tracker. The technology behind the IoT device is the MiCODUS MV720, but based on the research into the initial threat, we believe there could be other vulnerable models.
To break it down a little, the research reveals a vulnerability that, if acted on, would allow hackers to track individuals in their vehicles without their knowledge. With control of the GPS device, bad actors can also disable the vehicles.