Security industry 'has failed' to raise awareness of IoT safety

Symantec urges security pros to work with IoT manufacturers

The cyber security industry has "fundamentally failed" to educate consumers about the risks of IoT hacking, and is not doing enough to ensure devices built with security in mind.

That's according to Darren Thomson, EMEA CTO and VP of technology at Symantec, who believes that the industry's approach to IoT security is outdated, reflective of an bygone era when it was deemed enough to simply respond to threats.

"In the next decade we will see a whole new level of threat, that means we are going to really need to raise our game," said Thomson, speaking at London's Infosecurity Europe event today.

"For the last 30 or 40 years, we have been fundamentally designing insecure systems," explained Thomson, a process that meant companies like Symantec could come along and patch those holes when required. "When were talking about cities or rail networks, that benefit of the retrofit no longer exists."

The IoT has increasingly been seen as a 'wild west', a series of networks that is proving to be incredibly susceptible to remote hacking. As connected technology has become more popular, security has become an afterthought for many manufacturers, either too difficult or too expensive to build in, according to Thomson.

Security as a result often falls back on the customer, where they are expected to carry out technical tasks beyond their capabilities.

"If [we] think sending non-technical people to websites to tick security boxes is enough, we're kidding ourselves," said Thomson. "This industry has failed its users in regards to education and awareness. As an industry we're not meeting enough with manufacturers... everyone in the room is a tech person."

This issue will be solved when the security industry makes an effort to become more "predictive", according to Thomson. An example of this would be the formation of an "ingredients list" for the IoT, giving users exact information as to what to expect from a newly acquired smart home. This list, much like the dietary requirements on a food packet, would be a reference point for spotting unusual activity.

"Its about time that everyone in this industry starts to think about the unintended consequences. We have tried and failed to make people security experts. It doesn't work."

Featured Resources

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Simplify cluster security at scale

Centralised secrets management across hybrid, multi-cloud environments

Download now

The endpoint as a key element of your security infrastructure

Threats to endpoints in a world of remote working

Download now

2021 state of IT asset management report

The role of IT asset management for maximising technology investments

Download now

Recommended

What is DevSecOps and why is it important?
Security

What is DevSecOps and why is it important?

30 Oct 2020
Weekly threat roundup: NHS COVID-19 app, Nvidia, and Oracle
Security

Weekly threat roundup: NHS COVID-19 app, Nvidia, and Oracle

30 Oct 2020
Ryuk behind a third of all ransomware attacks in 2020
Security

Ryuk behind a third of all ransomware attacks in 2020

29 Oct 2020
REvil hacking group says it has made more than $100m in a year
Security

REvil hacking group says it has made more than $100m in a year

29 Oct 2020

Most Popular

Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

21 Oct 2020
What is Neuralink?
Technology

What is Neuralink?

24 Oct 2020
Hackers demand ransom from therapy patients after clinic data breach
Security

Hackers demand ransom from therapy patients after clinic data breach

27 Oct 2020