No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Monday, November 3, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

You Don’t Need To Be Ethan Hunt To Break Into A Building

by TheAdviserMagazine
5 months ago
in Market Analysis
Reading Time: 3 mins read
A A
You Don’t Need To Be Ethan Hunt To Break Into A Building
Share on FacebookShare on TwitterShare on LInkedIn


From a cybersecurity perspective, when you bring up the need to protect your organization’s endpoints, most people will think of computer assets: laptops, desktops, servers, and maybe smartphones and tablets. Today, these endpoints include devices within your buildings and campuses like security cameras, door locks, HVAC, elevators, solar arrays, and a host of other IoT/industrial IoT (IIoT) or building management system (BMS) devices.

The threats targeting the traditional endpoints of desktops, servers, and mobile devices are after your business data, either to steal it for resale to other malicious actors — or even data brokers who will resell it again — or to prevent you from accessing it and holding that access for ransom. The goal is money. When it comes to IoT/IIoT/BMS devices, the goals of the attackers are different, mainly because these devices rarely have enough business data on them to make an attack worthwhile. But if we go past that first level of reasoning, we uncover a few motives why attacking these devices is still valuable for skilled hackers or nation-state advanced persistent threats (APTs).

The most obvious effect from attacking weaknesses within BMSes like HVAC or elevators is the ability to take them offline. A data center that is not properly cooled and ventilated may have to shut down immediately or risk damaging the boards inside the computers. Shutting down the movement of employees can cripple your teams and customers and create a host of operational issues. Modern battery or generator backup units are also IoT/IIoT devices and can be exposed to cyberthreats. Disrupting the power to your building or campus while your power backup is compromised means your ability to operate is in the hands of the threat actor. Multiple stories and research have shown that the power grid is susceptible to cyberattacks, but this also includes other power delivery systems like solar arrays. But that’s just one level beyond data theft. Let’s keep going deeper.

When it comes to security systems like cameras, door locks, or motion sensors, these internet-connected devices within most buildings today allow for centralized control and incorporate cloud orchestration solutions and AI engines to provide analytics to the business on the overall state of your physical security infrastructure. A simple attack would be to take the devices offline, but a more sophisticated attack against cameras is to mirror the feed, sending it to the malicious actor so they can monitor the movements within the building, possibly targeting individuals or look for those weakness in monitoring so they can recreate “Mission: Impossible” and dangle from the ceiling on a wire. They could manipulate physical access control systems to expand the access to sensitive areas for a fraudulent access card. They could increase the sensitivity of motion sensors so they regularly trip alarms, creating “alert fatigue”; security operations analysts can get so desensitized to the endless flood of low-priority or false-positive alerts from particular desktops that they start ignoring that endpoint, which can mean a truly malicious action is missed — giving a physical attacker access to unauthorized areas. And still, the rabbit hole goes deeper.

Another threat to the business from IoT/IIoT/BMS devices is not what can happen on the device itself, but the access that device has to other parts of your IT or operational technology (OT) infrastructure. Controlling the device allows an attacker to leverage device vulnerabilities to access the device’s OS or firmware. But often, because security of these devices can be compromised, an attacker can use the device as a network probe and look for other IT endpoints that this IoT/IIoT/BMS device may have access to. If enough resources are available like memory and CPU, the attacker can start scanning those other endpoints for vulnerabilities. This lateral movement is how attackers move from an uninteresting target like a fish tank thermometer into a database server to extract the information of high rollers at a casino.

This all sounds terrible, and we should shut off all computer systems and head for the forests, right? Sounds peaceful until you realize how nice it is to have AC, lights, and power. Instead, we should apply the same principles that we apply to IT and ensure we’re following the least privileged access ideal that is core to the Zero Trust model. And as we utilize endpoint security solutions for our common IT endpoints in our infrastructure, we should utilize IoT security solutions for those IoT/IIoT/BMS endpoints in our infrastructure and across our buildings.

Forrester clients who want to discuss how best to secure these IoT/IIoT/BMS devices within their facilities and across their campuses should schedule an inquiry or guidance session with me where we can dive deeper into this topic.



Source link

Tags: BreakBuildingDontEthanhunt
ShareTweetShare
Previous Post

Retail Sales Miss, US Indices Slip from Highs as Risk Sentiment Weakens

Next Post

Sonol warns on fuel supply disruptions

Related Posts

edit post
How is Farm ERP Market Transforming the Future of Digital Agriculture?

How is Farm ERP Market Transforming the Future of Digital Agriculture?

by TheAdviserMagazine
November 3, 2025
0

The Farm ERP market is rapidly gaining traction as agriculture operators shift from manual and fragmented farm management systems to...

edit post
1 Stock to Buy, 1 Stock to Sell This Week: Palantir, Pfizer

1 Stock to Buy, 1 Stock to Sell This Week: Palantir, Pfizer

by TheAdviserMagazine
November 2, 2025
0

ADP jobs report, ISM PMI surveys, and more AI-linked tech earnings will be in focus this week. Palantir is expected...

edit post
5 Undervalued Stocks Under  Poised for Double-Digit Rebounds

5 Undervalued Stocks Under $10 Poised for Double-Digit Rebounds

by TheAdviserMagazine
October 31, 2025
0

Investing in stocks priced under $10 can offer significant opportunities for investors seeking high-growth potential at a low entry point....

edit post
Forrester’s Consumer Predictions For 2026

Forrester’s Consumer Predictions For 2026

by TheAdviserMagazine
October 31, 2025
0

I wrote the theme to this year’s consumer predictions to the beat of Rihanna’s “We Found Love,” with the lyric...

edit post
The Year AI Tests The Heart Of Healthcare

The Year AI Tests The Heart Of Healthcare

by TheAdviserMagazine
October 31, 2025
0

In 2025, the healthcare industry experienced significant shake-ups: the uncertain future of premium tax credits; the fracturing of vaccine policy;...

edit post
The Customer Is “Neo,” Not You

The Customer Is “Neo,” Not You

by TheAdviserMagazine
October 31, 2025
0

You need to deliver value to customers, right? Wrong! Myth: Your Organization Can “Deliver” Value To Customers If you believe...

Next Post
edit post
Sonol warns on fuel supply disruptions

Sonol warns on fuel supply disruptions

edit post
Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

  • Trending
  • Comments
  • Latest
edit post
77-year-old popular furniture retailer closes store locations

77-year-old popular furniture retailer closes store locations

October 18, 2025
edit post
Pennsylvania House of Representatives Rejects Update to Child Custody Laws

Pennsylvania House of Representatives Rejects Update to Child Custody Laws

October 7, 2025
edit post
What to Do When a Loved One Dies in North Carolina

What to Do When a Loved One Dies in North Carolina

October 8, 2025
edit post
Another Violent Outburst – Democrats Inciting Civil Unrest

Another Violent Outburst – Democrats Inciting Civil Unrest

October 24, 2025
edit post
Probate vs. Non-Probate Assets: What’s the Difference?

Probate vs. Non-Probate Assets: What’s the Difference?

October 17, 2025
edit post
California Attorney Pleads Guilty For Role In 2M Ponzi Scheme

California Attorney Pleads Guilty For Role In $912M Ponzi Scheme

October 15, 2025
edit post
Hapoalim’s Bit app to pay 4% annual interest on deposits

Hapoalim’s Bit app to pay 4% annual interest on deposits

0
edit post
Big Funds, Small Gains: Rethinking the Endowment Playbook

Big Funds, Small Gains: Rethinking the Endowment Playbook

0
edit post
Links 11/3/2025 | naked capitalism

Links 11/3/2025 | naked capitalism

0
edit post
Pfizer hits Novo Nordisk and Metsera with lawsuit amid bidding war

Pfizer hits Novo Nordisk and Metsera with lawsuit amid bidding war

0
edit post
Colgate-Palmolive (CL) Q3 2025 Earnings: Key financials and quarterly highlights

Colgate-Palmolive (CL) Q3 2025 Earnings: Key financials and quarterly highlights

0
edit post
Hong Kong Pushes Tokenisation as Regulators Ease Rules on Crypto Assets

Hong Kong Pushes Tokenisation as Regulators Ease Rules on Crypto Assets

0
edit post
Hapoalim’s Bit app to pay 4% annual interest on deposits

Hapoalim’s Bit app to pay 4% annual interest on deposits

November 3, 2025
edit post
Pfizer hits Novo Nordisk and Metsera with lawsuit amid bidding war

Pfizer hits Novo Nordisk and Metsera with lawsuit amid bidding war

November 3, 2025
edit post
Links 11/3/2025 | naked capitalism

Links 11/3/2025 | naked capitalism

November 3, 2025
edit post
How is Farm ERP Market Transforming the Future of Digital Agriculture?

How is Farm ERP Market Transforming the Future of Digital Agriculture?

November 3, 2025
edit post
Orchestra BioMed files secondary offering of ~8M shares (OBIO:NASDAQ)

Orchestra BioMed files secondary offering of ~8M shares (OBIO:NASDAQ)

November 3, 2025
edit post
1.8 Million Older Americans Die Like This Every Year. What Can You Do to Survive the 8 Top Causes of Death?

1.8 Million Older Americans Die Like This Every Year. What Can You Do to Survive the 8 Top Causes of Death?

November 3, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Hapoalim’s Bit app to pay 4% annual interest on deposits
  • Pfizer hits Novo Nordisk and Metsera with lawsuit amid bidding war
  • Links 11/3/2025 | naked capitalism
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.