No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Saturday, November 29, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

You Don’t Need To Be Ethan Hunt To Break Into A Building

by TheAdviserMagazine
6 months ago
in Market Analysis
Reading Time: 3 mins read
A A
You Don’t Need To Be Ethan Hunt To Break Into A Building
Share on FacebookShare on TwitterShare on LInkedIn


From a cybersecurity perspective, when you bring up the need to protect your organization’s endpoints, most people will think of computer assets: laptops, desktops, servers, and maybe smartphones and tablets. Today, these endpoints include devices within your buildings and campuses like security cameras, door locks, HVAC, elevators, solar arrays, and a host of other IoT/industrial IoT (IIoT) or building management system (BMS) devices.

The threats targeting the traditional endpoints of desktops, servers, and mobile devices are after your business data, either to steal it for resale to other malicious actors — or even data brokers who will resell it again — or to prevent you from accessing it and holding that access for ransom. The goal is money. When it comes to IoT/IIoT/BMS devices, the goals of the attackers are different, mainly because these devices rarely have enough business data on them to make an attack worthwhile. But if we go past that first level of reasoning, we uncover a few motives why attacking these devices is still valuable for skilled hackers or nation-state advanced persistent threats (APTs).

The most obvious effect from attacking weaknesses within BMSes like HVAC or elevators is the ability to take them offline. A data center that is not properly cooled and ventilated may have to shut down immediately or risk damaging the boards inside the computers. Shutting down the movement of employees can cripple your teams and customers and create a host of operational issues. Modern battery or generator backup units are also IoT/IIoT devices and can be exposed to cyberthreats. Disrupting the power to your building or campus while your power backup is compromised means your ability to operate is in the hands of the threat actor. Multiple stories and research have shown that the power grid is susceptible to cyberattacks, but this also includes other power delivery systems like solar arrays. But that’s just one level beyond data theft. Let’s keep going deeper.

When it comes to security systems like cameras, door locks, or motion sensors, these internet-connected devices within most buildings today allow for centralized control and incorporate cloud orchestration solutions and AI engines to provide analytics to the business on the overall state of your physical security infrastructure. A simple attack would be to take the devices offline, but a more sophisticated attack against cameras is to mirror the feed, sending it to the malicious actor so they can monitor the movements within the building, possibly targeting individuals or look for those weakness in monitoring so they can recreate “Mission: Impossible” and dangle from the ceiling on a wire. They could manipulate physical access control systems to expand the access to sensitive areas for a fraudulent access card. They could increase the sensitivity of motion sensors so they regularly trip alarms, creating “alert fatigue”; security operations analysts can get so desensitized to the endless flood of low-priority or false-positive alerts from particular desktops that they start ignoring that endpoint, which can mean a truly malicious action is missed — giving a physical attacker access to unauthorized areas. And still, the rabbit hole goes deeper.

Another threat to the business from IoT/IIoT/BMS devices is not what can happen on the device itself, but the access that device has to other parts of your IT or operational technology (OT) infrastructure. Controlling the device allows an attacker to leverage device vulnerabilities to access the device’s OS or firmware. But often, because security of these devices can be compromised, an attacker can use the device as a network probe and look for other IT endpoints that this IoT/IIoT/BMS device may have access to. If enough resources are available like memory and CPU, the attacker can start scanning those other endpoints for vulnerabilities. This lateral movement is how attackers move from an uninteresting target like a fish tank thermometer into a database server to extract the information of high rollers at a casino.

This all sounds terrible, and we should shut off all computer systems and head for the forests, right? Sounds peaceful until you realize how nice it is to have AC, lights, and power. Instead, we should apply the same principles that we apply to IT and ensure we’re following the least privileged access ideal that is core to the Zero Trust model. And as we utilize endpoint security solutions for our common IT endpoints in our infrastructure, we should utilize IoT security solutions for those IoT/IIoT/BMS endpoints in our infrastructure and across our buildings.

Forrester clients who want to discuss how best to secure these IoT/IIoT/BMS devices within their facilities and across their campuses should schedule an inquiry or guidance session with me where we can dive deeper into this topic.



Source link

Tags: BreakBuildingDontEthanhunt
ShareTweetShare
Previous Post

Retail Sales Miss, US Indices Slip from Highs as Risk Sentiment Weakens

Next Post

Sonol warns on fuel supply disruptions

Related Posts

edit post
Bitcoin’s Recovery: Short-Term Reaction to Fed Dovishness or a True Trend Change?

Bitcoin’s Recovery: Short-Term Reaction to Fed Dovishness or a True Trend Change?

by TheAdviserMagazine
November 28, 2025
0

The week was characterized by an intense flow of news, both in terms of global macro pricing and the internal...

edit post
8 Undervalued Small Caps Positioned to Lead as the Russell 2000 Breaks Out

8 Undervalued Small Caps Positioned to Lead as the Russell 2000 Breaks Out

by TheAdviserMagazine
November 27, 2025
0

The Russel 2000 Index, a major US small-cap benchmark, has moved higher over the last four trading sessions. It gained...

edit post
A CIO’s Roadmap To Compliance And Competitive Advantage

A CIO’s Roadmap To Compliance And Competitive Advantage

by TheAdviserMagazine
November 27, 2025
0

November 2025 marks a turning point for India’s digital economy. With the notification of the Digital Personal Data Protection Rules,...

edit post
3 Mag 7 Stocks Offering Attractive Entry Points After Strong Q3 Results

3 Mag 7 Stocks Offering Attractive Entry Points After Strong Q3 Results

by TheAdviserMagazine
November 27, 2025
0

With NVIDIA’s (NASDAQ:NVDA) released last week, we now have a clearer picture of the performance of the so-called Magnificent Seven...

edit post
Palo Alto Networks’ Acquisition Of Chronosphere

Palo Alto Networks’ Acquisition Of Chronosphere

by TheAdviserMagazine
November 26, 2025
0

Cybersecurity behemoth Palo Alto Networks (PANW) recently announced the acquisition of observability vendor Chronosphere for $3.35 billion. The acquisition is...

edit post
What it Means for UK Consumers

What it Means for UK Consumers

by TheAdviserMagazine
November 26, 2025
0

Balancing the Books After announcing one of British politics’ biggest ever increases in taxation with her first Budget a year...

Next Post
edit post
Sonol warns on fuel supply disruptions

Sonol warns on fuel supply disruptions

edit post
Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

Investing in Student Engagement: University of Georgia Equips Faculty and Students with Free Access to Top Hat

  • Trending
  • Comments
  • Latest
edit post
7 States That Are Quietly Taxing the Middle Class Into Extinction

7 States That Are Quietly Taxing the Middle Class Into Extinction

November 8, 2025
edit post
How to Make a Valid Will in North Carolina

How to Make a Valid Will in North Carolina

November 20, 2025
edit post
8 Places To Get A Free Turkey for Thanksgiving

8 Places To Get A Free Turkey for Thanksgiving

November 21, 2025
edit post
Data centers in Nvidia’s hometown stand empty awaiting power

Data centers in Nvidia’s hometown stand empty awaiting power

November 10, 2025
edit post
Could He Face Even More Charges Under California Law?

Could He Face Even More Charges Under California Law?

November 27, 2025
edit post
8 States Offering Special Cash Rebates for Residents Over 65

8 States Offering Special Cash Rebates for Residents Over 65

November 9, 2025
edit post
IEEPA Tariffs Are Down from April Threats

IEEPA Tariffs Are Down from April Threats

0
edit post
Wall Street posts best Thanksgiving week performance since 2008 (SP500)

Wall Street posts best Thanksgiving week performance since 2008 (SP500)

0
edit post
Stock market outlook: analysts see the S&P 500 hitting 8000 next year

Stock market outlook: analysts see the S&P 500 hitting 8000 next year

0
edit post
Are young college graduates losing an edge in the job market?

Are young college graduates losing an edge in the job market?

0
edit post
Key metrics from Nio’s (NIO) Q3 2025 earnings results

Key metrics from Nio’s (NIO) Q3 2025 earnings results

0
edit post
The Anti-Capitalist Mentality of the Estado Novo

The Anti-Capitalist Mentality of the Estado Novo

0
edit post
Wall Street posts best Thanksgiving week performance since 2008 (SP500)

Wall Street posts best Thanksgiving week performance since 2008 (SP500)

November 29, 2025
edit post
Stock market outlook: analysts see the S&P 500 hitting 8000 next year

Stock market outlook: analysts see the S&P 500 hitting 8000 next year

November 29, 2025
edit post
Republicans are hating on Trump’s 50-year mortgage idea. Here’s why some think it will ‘ultimately reward the banks’

Republicans are hating on Trump’s 50-year mortgage idea. Here’s why some think it will ‘ultimately reward the banks’

November 29, 2025
edit post
*HOT* Wrangler Men’s Jeans and Workwear Hoodies only !

*HOT* Wrangler Men’s Jeans and Workwear Hoodies only $13!

November 29, 2025
edit post
Key deals this week: CAE, Sinclair, Bed Bath & Beyond, NatWest, and more (NWG:NYSE)

Key deals this week: CAE, Sinclair, Bed Bath & Beyond, NatWest, and more (NWG:NYSE)

November 29, 2025
edit post
What The Latest Cardano Treasury Move Means For Investors

What The Latest Cardano Treasury Move Means For Investors

November 29, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Wall Street posts best Thanksgiving week performance since 2008 (SP500)
  • Stock market outlook: analysts see the S&P 500 hitting 8000 next year
  • Republicans are hating on Trump’s 50-year mortgage idea. Here’s why some think it will ‘ultimately reward the banks’
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.