No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Saturday, January 10, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

You Don’t Need To Be Ethan Hunt To Break Into A Building

by TheAdviserMagazine
7 months ago
in Market Analysis
Reading Time: 3 mins read
A A
You Don’t Need To Be Ethan Hunt To Break Into A Building
Share on FacebookShare on TwitterShare on LInkedIn


From a cybersecurity perspective, when you bring up the need to protect your organization’s endpoints, most people will think of computer assets: laptops, desktops, servers, and maybe smartphones and tablets. Today, these endpoints include devices within your buildings and campuses like security cameras, door locks, HVAC, elevators, solar arrays, and a host of other IoT/industrial IoT (IIoT) or building management system (BMS) devices.

The threats targeting the traditional endpoints of desktops, servers, and mobile devices are after your business data, either to steal it for resale to other malicious actors — or even data brokers who will resell it again — or to prevent you from accessing it and holding that access for ransom. The goal is money. When it comes to IoT/IIoT/BMS devices, the goals of the attackers are different, mainly because these devices rarely have enough business data on them to make an attack worthwhile. But if we go past that first level of reasoning, we uncover a few motives why attacking these devices is still valuable for skilled hackers or nation-state advanced persistent threats (APTs).

The most obvious effect from attacking weaknesses within BMSes like HVAC or elevators is the ability to take them offline. A data center that is not properly cooled and ventilated may have to shut down immediately or risk damaging the boards inside the computers. Shutting down the movement of employees can cripple your teams and customers and create a host of operational issues. Modern battery or generator backup units are also IoT/IIoT devices and can be exposed to cyberthreats. Disrupting the power to your building or campus while your power backup is compromised means your ability to operate is in the hands of the threat actor. Multiple stories and research have shown that the power grid is susceptible to cyberattacks, but this also includes other power delivery systems like solar arrays. But that’s just one level beyond data theft. Let’s keep going deeper.

When it comes to security systems like cameras, door locks, or motion sensors, these internet-connected devices within most buildings today allow for centralized control and incorporate cloud orchestration solutions and AI engines to provide analytics to the business on the overall state of your physical security infrastructure. A simple attack would be to take the devices offline, but a more sophisticated attack against cameras is to mirror the feed, sending it to the malicious actor so they can monitor the movements within the building, possibly targeting individuals or look for those weakness in monitoring so they can recreate “Mission: Impossible” and dangle from the ceiling on a wire. They could manipulate physical access control systems to expand the access to sensitive areas for a fraudulent access card. They could increase the sensitivity of motion sensors so they regularly trip alarms, creating “alert fatigue”; security operations analysts can get so desensitized to the endless flood of low-priority or false-positive alerts from particular desktops that they start ignoring that endpoint, which can mean a truly malicious action is missed — giving a physical attacker access to unauthorized areas. And still, the rabbit hole goes deeper.

Another threat to the business from IoT/IIoT/BMS devices is not what can happen on the device itself, but the access that device has to other parts of your IT or operational technology (OT) infrastructure. Controlling the device allows an attacker to leverage device vulnerabilities to access the device’s OS or firmware. But often, because security of these devices can be compromised, an attacker can use the device as a network probe and look for other IT endpoints that this IoT/IIoT/BMS device may have access to. If enough resources are available like memory and CPU, the attacker can start scanning those other endpoints for vulnerabilities. This lateral movement is how attackers move from an uninteresting target like a fish tank thermometer into a database server to extract the information of high rollers at a casino.

This all sounds terrible, and we should shut off all computer systems and head for the forests, right? Sounds peaceful until you realize how nice it is to have AC, lights, and power. Instead, we should apply the same principles that we apply to IT and ensure we’re following the least privileged access ideal that is core to the Zero Trust model. And as we utilize endpoint security solutions for our common IT endpoints in our infrastructure, we should utilize IoT security solutions for those IoT/IIoT/BMS endpoints in our infrastructure and across our buildings.

Forrester clients who want to discuss how best to secure these IoT/IIoT/BMS devices within their facilities and across their campuses should schedule an inquiry or guidance session with me where we can dive deeper into this topic.



Source link

Tags: BreakBuildingDontEthanhunt
ShareTweetShare
Previous Post

Retail Sales Miss, US Indices Slip from Highs as Risk Sentiment Weakens

Next Post

Sonol warns on fuel supply disruptions

Related Posts

edit post
The Hidden Culture Risks Of Rapid Growth And How Leaders Can Counter Them

The Hidden Culture Risks Of Rapid Growth And How Leaders Can Counter Them

by TheAdviserMagazine
January 9, 2026
0

Rapid growth — of a team, department, or company — is often coupled with an underestimation of the cultural implications....

edit post
Why Platforms Must Evolve For AI Agents

Why Platforms Must Evolve For AI Agents

by TheAdviserMagazine
January 9, 2026
0

We are seeing a great pivot underway as technology companies paddle out to catch the next big AI wave. Domain-specific...

edit post
Three Strategic Imperatives For Tech Leaders

Three Strategic Imperatives For Tech Leaders

by TheAdviserMagazine
January 9, 2026
0

Hg Capital’s agreement to acquire OneStream for $6.4 billion marks a pivotal moment in the enterprise performance management landscape. This...

edit post
OpenAI And b.well Promise Greater Patient Empowerment (With Some Caveats)

OpenAI And b.well Promise Greater Patient Empowerment (With Some Caveats)

by TheAdviserMagazine
January 9, 2026
0

OpenAI’s recent partnership with b.well marks a pivotal moment in healthcare technology. With ChatGPT Health, OpenAI is integrating consumer medical records...

edit post
Q4 Earnings Preview: Wall Street’s Make-or-Break Moment as Reporting Season Looms

Q4 Earnings Preview: Wall Street’s Make-or-Break Moment as Reporting Season Looms

by TheAdviserMagazine
January 9, 2026
0

Wall Street’s Q4 2025 earnings season begins next week, with major banks like JPMorgan Chase (NYSE:), Citigroup (NYSE:), and Wells...

edit post
Manufacturing And Automotive Giants Continue Their Shift From Grease To Code At CES 2026

Manufacturing And Automotive Giants Continue Their Shift From Grease To Code At CES 2026

by TheAdviserMagazine
January 9, 2026
0

I cover smart manufacturing at Forrester, which includes esoteric topics like digital twins, digital product passports, physical or embodied AI...

Next Post
edit post
Sonol warns on fuel supply disruptions

Sonol warns on fuel supply disruptions

edit post
Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

  • Trending
  • Comments
  • Latest
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
edit post
80-year-old Home Depot rival shuts down location, no bankruptcy

80-year-old Home Depot rival shuts down location, no bankruptcy

January 4, 2026
edit post
Tennessee theater professor reinstated, with 0,000 settlement, after losing his job over a Charlie Kirk-related social media post

Tennessee theater professor reinstated, with $500,000 settlement, after losing his job over a Charlie Kirk-related social media post

January 8, 2026
edit post
Utility Shutoff Policies Are Changing in Several Midwestern States

Utility Shutoff Policies Are Changing in Several Midwestern States

January 9, 2026
edit post
In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

December 14, 2025
edit post
Democrats Insist On Taxing Tips        

Democrats Insist On Taxing Tips        

December 15, 2025
edit post
Venezuela slow-walks prisoner releases with 11 freed while over 800 remain locked up

Venezuela slow-walks prisoner releases with 11 freed while over 800 remain locked up

0
edit post
“Say My Name, Say My Name”: Why Learning Names Improves Student Success – Faculty Focus

“Say My Name, Say My Name”: Why Learning Names Improves Student Success – Faculty Focus

0
edit post
The Endowment Syndrome: Why Elite Funds Are Falling Behind

The Endowment Syndrome: Why Elite Funds Are Falling Behind

0
edit post
How to Get Free Samples

How to Get Free Samples

0
edit post
Polygon Climbs Nearly 20% After Unveiling New Strategic Framework

Polygon Climbs Nearly 20% After Unveiling New Strategic Framework

0
edit post
Abel’s  million Berkshire paycheck is in the same league as other S&P 500 CEOs

Abel’s $25 million Berkshire paycheck is in the same league as other S&P 500 CEOs

0
edit post
Venezuela slow-walks prisoner releases with 11 freed while over 800 remain locked up

Venezuela slow-walks prisoner releases with 11 freed while over 800 remain locked up

January 10, 2026
edit post
How to Get Free Samples

How to Get Free Samples

January 10, 2026
edit post
10 things introverts notice about people in the first five minutes that extroverts miss entirely

10 things introverts notice about people in the first five minutes that extroverts miss entirely

January 10, 2026
edit post
The ‘Holy Grail of comic books’ once owned by Nicolas Cage sells at auction for a record  million

The ‘Holy Grail of comic books’ once owned by Nicolas Cage sells at auction for a record $15 million

January 10, 2026
edit post
Professor’s Lawsuit, “Focused on Discrimination Related to Positionality Across Multiple Marginalized and Vulnerable Communities,” Fizzles

Professor’s Lawsuit, “Focused on Discrimination Related to Positionality Across Multiple Marginalized and Vulnerable Communities,” Fizzles

January 10, 2026
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Venezuela slow-walks prisoner releases with 11 freed while over 800 remain locked up
  • How to Get Free Samples
  • 10 things introverts notice about people in the first five minutes that extroverts miss entirely
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.