sb-au logo
Story image

Top tips to minimise security risks from your IoT devices

27 Feb 2019

Article by Trend Micro APAC consumer senior director Tim Falinksi

Homes are more connected now than ever before.

The average household now has 27 smart devices, and many tech-savvy users now send out the directive ‘Hey Google’ or ‘Hey Alexa’ multiple times a day, maximising this technology for everything from watching TV, adjusting the home lights or opening a garage door.

As more and more homes adopt these new devices, the relatively limited security on them has made them an attractive target for cybercriminals.

With little in place to prevent unauthorised access, many criminals see them as an easy way to gain access to home networks.

Globally, Trend Micro saw almost one billion possible attacks on home networks (879,306,356) in 2018.

Possible attacks are high-risk events that are closely related to threat activity, and can include potentially unwanted programs such as adware or grayware, inbound and outbound attacks. This means attacks going from home to Internet, or Internet to home, were seen in huge quantities throughout the year.

Passwords and cryptomining topped the list of possible attacks, with cybercriminals making the most of devices that are often running in the background to cash in on the cryptomining boom. Locally, iPhones topped the list of targeted devices, along with the usual targets – PCs, Macbooks and Androids.

While common household devices like routers and printers weren’t as common targets, making up eight per cent combined, they’re evidence of an increasing trend towards less-obvious points of entry.

Here are some steps for how users can minimise these risks while continuing to embrace smart devices:

  1. Rename your network

Many people don’t rename their Wifi network once it’s up and running, but if you’ve got a distinguishing feature in it – like ‘The Smiths’ Wifi’, then now is the time to choose something different. Selecting an obscure name makes it harder to be identified.

  1. Change the default

Devices such as routers and printers often come with a default password that many don’t realise need to be changed. Update all of these passwords since cybercriminals often use them as an easy point-of-entry into a network. Ensure these are strong passwords, with a unique mix of letters, numbers and characters.

  1. Stay up-to-date

Keep your software up-to-date on all devices – no more pressing ‘Remind me later’. The latest updates will include patches that fix common bugs, preventing cybercriminals from exploiting these to get access to your devices. Most companies stop providing support for dated versions of iOS, so it pays to ensure an operating system is still fully supported with regular updates.

  1. IoT audit

Conduct an audit of all the IoT devices that are connected to the network. How long have they been used? Are they still fully supported by the manufacturer? If they’re outdated models and no longer functioning as well as they should be, consider upgrading the devices to a newer model.

Story image
Organisations investing significant time modifying web application firewalls to keep ahead of cybersecurity threats
"The sheer amount of traffic and potential threats can ensnare resources and impact the ability to introduce greater precision to those key systems."More
Story image
Cybercriminals take bold steps forward as confidence soars - CrowdStrike report
Criminals are especially interested in targeting the supply chain as it enables them to go after multiple targets from a single intrusion point.More
Story image
Millions of email attacks missed by organisations’ cyber security protection
"While organisations have invested in protection against email threats, many of these attacks slip through gateways, landing in users inboxes."More
Story image
Kaseya acquires RocketCyber to bring SOC solutions to more businesses
"With this acquisition, we've doubled down on our security investments to provide our customers with access to experts who can continuously monitoring their IT environments without the cost and complexity of disparate tools.”More
Story image
CISOs, don't underestimate the importance of soft skills
There is increasing importance on Chief Information Security Officers (CISOs) having and developing the skill of emotional intelligence, a new report states.More
Story image
Three security essentials for financial services
Financial services organisations must provide the best possible customer experience in terms of mobile and online application availability, performance and security, writes Gigamon country manager for A/NZ George Tsoukas.More