No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Tuesday, November 4, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

You Don’t Need To Be Ethan Hunt To Break Into A Building

by TheAdviserMagazine
5 months ago
in Market Analysis
Reading Time: 3 mins read
A A
You Don’t Need To Be Ethan Hunt To Break Into A Building
Share on FacebookShare on TwitterShare on LInkedIn


From a cybersecurity perspective, when you bring up the need to protect your organization’s endpoints, most people will think of computer assets: laptops, desktops, servers, and maybe smartphones and tablets. Today, these endpoints include devices within your buildings and campuses like security cameras, door locks, HVAC, elevators, solar arrays, and a host of other IoT/industrial IoT (IIoT) or building management system (BMS) devices.

The threats targeting the traditional endpoints of desktops, servers, and mobile devices are after your business data, either to steal it for resale to other malicious actors — or even data brokers who will resell it again — or to prevent you from accessing it and holding that access for ransom. The goal is money. When it comes to IoT/IIoT/BMS devices, the goals of the attackers are different, mainly because these devices rarely have enough business data on them to make an attack worthwhile. But if we go past that first level of reasoning, we uncover a few motives why attacking these devices is still valuable for skilled hackers or nation-state advanced persistent threats (APTs).

The most obvious effect from attacking weaknesses within BMSes like HVAC or elevators is the ability to take them offline. A data center that is not properly cooled and ventilated may have to shut down immediately or risk damaging the boards inside the computers. Shutting down the movement of employees can cripple your teams and customers and create a host of operational issues. Modern battery or generator backup units are also IoT/IIoT devices and can be exposed to cyberthreats. Disrupting the power to your building or campus while your power backup is compromised means your ability to operate is in the hands of the threat actor. Multiple stories and research have shown that the power grid is susceptible to cyberattacks, but this also includes other power delivery systems like solar arrays. But that’s just one level beyond data theft. Let’s keep going deeper.

When it comes to security systems like cameras, door locks, or motion sensors, these internet-connected devices within most buildings today allow for centralized control and incorporate cloud orchestration solutions and AI engines to provide analytics to the business on the overall state of your physical security infrastructure. A simple attack would be to take the devices offline, but a more sophisticated attack against cameras is to mirror the feed, sending it to the malicious actor so they can monitor the movements within the building, possibly targeting individuals or look for those weakness in monitoring so they can recreate “Mission: Impossible” and dangle from the ceiling on a wire. They could manipulate physical access control systems to expand the access to sensitive areas for a fraudulent access card. They could increase the sensitivity of motion sensors so they regularly trip alarms, creating “alert fatigue”; security operations analysts can get so desensitized to the endless flood of low-priority or false-positive alerts from particular desktops that they start ignoring that endpoint, which can mean a truly malicious action is missed — giving a physical attacker access to unauthorized areas. And still, the rabbit hole goes deeper.

Another threat to the business from IoT/IIoT/BMS devices is not what can happen on the device itself, but the access that device has to other parts of your IT or operational technology (OT) infrastructure. Controlling the device allows an attacker to leverage device vulnerabilities to access the device’s OS or firmware. But often, because security of these devices can be compromised, an attacker can use the device as a network probe and look for other IT endpoints that this IoT/IIoT/BMS device may have access to. If enough resources are available like memory and CPU, the attacker can start scanning those other endpoints for vulnerabilities. This lateral movement is how attackers move from an uninteresting target like a fish tank thermometer into a database server to extract the information of high rollers at a casino.

This all sounds terrible, and we should shut off all computer systems and head for the forests, right? Sounds peaceful until you realize how nice it is to have AC, lights, and power. Instead, we should apply the same principles that we apply to IT and ensure we’re following the least privileged access ideal that is core to the Zero Trust model. And as we utilize endpoint security solutions for our common IT endpoints in our infrastructure, we should utilize IoT security solutions for those IoT/IIoT/BMS endpoints in our infrastructure and across our buildings.

Forrester clients who want to discuss how best to secure these IoT/IIoT/BMS devices within their facilities and across their campuses should schedule an inquiry or guidance session with me where we can dive deeper into this topic.



Source link

Tags: BreakBuildingDontEthanhunt
ShareTweetShare
Previous Post

Retail Sales Miss, US Indices Slip from Highs as Risk Sentiment Weakens

Next Post

Sonol warns on fuel supply disruptions

Related Posts

edit post
An Evolving Legacy Shaping The Future Of Banking Key Insights From Finacle Conclave 2025

An Evolving Legacy Shaping The Future Of Banking Key Insights From Finacle Conclave 2025

by TheAdviserMagazine
November 4, 2025
0

Set against the timeless backdrop of Athens, Greece, Finacle Conclave 2025 convened global banking leaders, technology partners, transformation executives, and...

edit post
10 Analyst-Favorite Oil Stocks Poised for Up to 83% Upside

10 Analyst-Favorite Oil Stocks Poised for Up to 83% Upside

by TheAdviserMagazine
November 4, 2025
0

WTI crude prices held steady on Monday, but a series of positive developments has lifted hopes for a rebound in...

edit post
EUR/USD: US Dollar Strength, Political Gridlock Set to Keep Pair Under Pressure

EUR/USD: US Dollar Strength, Political Gridlock Set to Keep Pair Under Pressure

by TheAdviserMagazine
November 4, 2025
0

The pair has been moving lower at a steady pace since mid-September, forming part of a broader sideways trend. The...

edit post
Is Microsoft Eating GitHub, Or Is It The Other Way Around?

Is Microsoft Eating GitHub, Or Is It The Other Way Around?

by TheAdviserMagazine
November 3, 2025
0

With only a few months since GitHub’s formal transition from individual subsidiary to part of Microsoft’s CoreAI division, we were...

edit post
Pricing Agreements

Pricing Agreements

by TheAdviserMagazine
November 3, 2025
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

edit post
US Dollar: Weekly Close Above 101.6 Could Redefine Greenback’s Path for Year Ahead

US Dollar: Weekly Close Above 101.6 Could Redefine Greenback’s Path for Year Ahead

by TheAdviserMagazine
November 3, 2025
0

The recent rise in the US Dollar may seem linked to the , but it also signals a broader shift...

Next Post
edit post
Sonol warns on fuel supply disruptions

Sonol warns on fuel supply disruptions

edit post
Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

  • Trending
  • Comments
  • Latest
edit post
77-year-old popular furniture retailer closes store locations

77-year-old popular furniture retailer closes store locations

October 18, 2025
edit post
Pennsylvania House of Representatives Rejects Update to Child Custody Laws

Pennsylvania House of Representatives Rejects Update to Child Custody Laws

October 7, 2025
edit post
What to Do When a Loved One Dies in North Carolina

What to Do When a Loved One Dies in North Carolina

October 8, 2025
edit post
Another Violent Outburst – Democrats Inciting Civil Unrest

Another Violent Outburst – Democrats Inciting Civil Unrest

October 24, 2025
edit post
Probate vs. Non-Probate Assets: What’s the Difference?

Probate vs. Non-Probate Assets: What’s the Difference?

October 17, 2025
edit post
California Attorney Pleads Guilty For Role In 2M Ponzi Scheme

California Attorney Pleads Guilty For Role In $912M Ponzi Scheme

October 15, 2025
edit post
Should You Buy NAVN Stock After the Navan IPO?

Should You Buy NAVN Stock After the Navan IPO?

0
edit post
Coffee Break: Armed Madhouse – The Poseidon Problem

Coffee Break: Armed Madhouse – The Poseidon Problem

0
edit post
Franklin Templeton updates XRP ETF filing, aiming for launch this month

Franklin Templeton updates XRP ETF filing, aiming for launch this month

0
edit post
5 Credit History Repair Tips Young Adults Usually Skip

5 Credit History Repair Tips Young Adults Usually Skip

0
edit post
Trump administration announces 16th deadly strike on an alleged drug boat

Trump administration announces 16th deadly strike on an alleged drug boat

0
edit post
AMD reports higher Q3 2025 revenue and earnings; results beat estimates

AMD reports higher Q3 2025 revenue and earnings; results beat estimates

0
edit post
Trump administration announces 16th deadly strike on an alleged drug boat

Trump administration announces 16th deadly strike on an alleged drug boat

November 4, 2025
edit post
Zeta Global outlines 21% organic revenue growth target for 2026 with Athena AI launch and Marigold acquisition pending (NYSE:ZETA)

Zeta Global outlines 21% organic revenue growth target for 2026 with Athena AI launch and Marigold acquisition pending (NYSE:ZETA)

November 4, 2025
edit post
Bitcoin Experten reden Tacheles: Saylor und Kiyosaki geben ihre Jahresprognosen ab

Bitcoin Experten reden Tacheles: Saylor und Kiyosaki geben ihre Jahresprognosen ab

November 4, 2025
edit post
How to Qualify for Free Vision Exams Without Switching Insurance

How to Qualify for Free Vision Exams Without Switching Insurance

November 4, 2025
edit post
Palantir’s ‘anti-woke’ playbook and ‘cultus’ winning strategy, after yet another earnings beat

Palantir’s ‘anti-woke’ playbook and ‘cultus’ winning strategy, after yet another earnings beat

November 4, 2025
edit post
AI is here, but how should advisors best implement it?

AI is here, but how should advisors best implement it?

November 4, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Trump administration announces 16th deadly strike on an alleged drug boat
  • Zeta Global outlines 21% organic revenue growth target for 2026 with Athena AI launch and Marigold acquisition pending (NYSE:ZETA)
  • Bitcoin Experten reden Tacheles: Saylor und Kiyosaki geben ihre Jahresprognosen ab
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.