Smart cities will help both the private and public sector excel in many areas, but as helpful they are, they also come with many security risks. PERRY HUTTON, Regional Vice President – Africa at Fortinet, outlines five security areas CIOs need to watch out for.
Car navigation systems that can predict where and when traffic jams might occur, by siphoning data from sensors in roads and other vehicles. Cameras that can spot litter in public places and call in the cleaning crew. Self-adjusting street lamps.
These are just a few of the scenarios that could become commonplace as smart cities take hold over the next few years. Driven by rising urbanisation and fuelled by technologies such as the Internet of Things (IoT) and data analytics, smart cities are on the cusp of explosive growth. Glasgow, Barcelona, Nice, New York City, London and Singapore have already embarked on the trek. The smart city technology market could be worth US$27.5 billion annually by 2023, according to Navigant Research.
Smart city initiatives are driven by public sector initiatives. However, they will have a big impact on businesses. CIOs will have to learn how to tap on the new connected city infrastructure for their business. Smart city technologies like IoT and data analytics are expected to drive innovative business ideas in the future.
But the new wave of smart city services and technologies are also expected to create new security vulnerabilities. Here are five areas CIOs should watch out for.
1. A further fragmentation of IT
The last few years saw a rapid proliferation of cloud services and mobile device adoption in the workplace. The trend has transformed business productivity. But it has also wrecked the tight-fisted control that CIOs used to be able to exert on their IT systems.
CIOs now have to grapple with the idea of employees using unsanctioned cloud services via unsecured phones to hook up to corporate servers and accessing sensitive business data. The expected explosion of IoT devices − researchers estimate that by 2020, the number of active wireless connected devices will exceed 40 billion worldwide − will result in a further fragmentation of IT in businesses.
Instead of fighting the losing battle of trying to lock down devices and services, CIOs should look at protecting the data. Look for IoT devices that offer device-to-device encryption. Consider implementing − as well as bolstering − comprehensive encryption schemes to protect data in networks, cloud services and endpoint devices.
2. Device vulnerabilities
In the past year, security researchers have exposed holes in Wi-Fi-enabled Barbie dolls, Jeep Cherokee cars, fitness trackers and other new-fangled connected devices. Fortinet’s FortiGuard Labs already see IoT based attacks on the radar and happening in real time around the world. This shows the risks that are coming as toys, wearables, cars and power grids get attached to sensors that are linked to a common network and the Web.
IoT will bring forth a larger surface attack. Hackers will eye IoT devices as a launching pad for ‘land-and-expand’ attacks. One scenario: hackers take advantage of vulnerabilities in connected consumer devices to get a foothold within the corporate networks and hardware to which they connect.
So how do CIOs protect against the risks of connected devices and their own IoT implementations? Short of physically separating such devices from all other network systems, they can consider deploying network-based protection schemes. Internal segmentation firewalls, or ISFWs, for instance, can mitigate the proliferation of threats inside the business network. They also need to employ an IoT network security solution which is capable of mitigating exploits against this growing and vulnerable attack surface. IoT vendors need to harden their products and develop proper product security (PSIRT) teams.
3. IoT gateways can be exploited
In a typical IoT deployment, the majority of connected devices will be always connected and always on. Unlike mobile phones and laptops, such devices are likely to go through only a one-time authentication process across multiple sessions. This will make them attractive to hackers looking to infiltrate into company networks, as it allows easy control and sniffing of traffic. Shoring up the security of the gateways that connect IoT devices is therefore a must. CIOs should map out where these gateways are and where they are linked to − they can reside internally or externally, and even be connected to IoT device manufacturers. There must also be a sound plan for updating security patches on these gateways, as well as the IoT devices.
4. Big data, more risks
If there is a constant in smart city deployments, it is that more data will be generated, processed and stored. Connected devices will generate huge data repositories. Businesses that adopt big data systems will see an even larger data deluge. Unfortunately, such data will also become attractive targets for corporate hackers. To protect huge amounts of data with large inflows and outflows, the bandwidth capabilities of security appliances will come to the fore. And when dealing with data analytics, it often isn’t just a single data set, but multiple repositories of data that may be combined and analyzed together by different groups of people. For instance, a pharmaceutical company’s research efforts may be open to employees, contractors and interns. This means individual access and auditing rights.
5. A new can of worms
New worms designed to attach to IoT devices will emerge − and they could wreak more havoc given the extended reach of the new converged networks. Conficker is an example of a worm that spread on PC’s in 2008 and is still persistent and prevalent in 2016. Likewise, worms and viruses that can propagate from device to device can be expected to emerge – particularly with mobile and the Android operating system. Embedded worms will spread by leveraging and exploiting vulnerabilities in the growing IoT and mobile attack surface. The largest botnet FortiGuard labs has witnessed is in the range of 15 million PC’s. Thanks to the internet of things, this can easily reach in excess of 50 million if the spread of IoT worms is not properly mitigated. Patch management, and network based security inspection – particularly intrusion prevention systems or IPS – that can block IoT worms is a must.
Win a Poster Heater with Gadget and Takealot.com
This winter Gadget and Takealot.com are giving away three Poster Heaters, which look like posters but become heaters when you plug them in.
Three Gadget readers will each win a unit, valued at R550 each. To enter, follow @GadgetZA and @Takealot on Twitter and tell us on the @GadgetZA account how many Watts the heater consumes.
What’s the big deal about these heaters? Many of us are struggling to keep the balance between soaring electricity costs and the need to keep warm this winter.
However, the recently launched Poster Heater by EasyHeat and distributed in South Africa by Takealot.com is not only one of the most cost effective electric heaters currently on the market, it is also easy to setup and use.
As the name indicates, it is a poster similar to one you would hang on a wall. But, plug it in and it turns into a 300 Watt heater. The Poster Heater isn’t designed to heat hallways or large rooms, but rather smaller ones like a bedroom or a baby’s nursery or a dressing room.
It uses radiant heating, which means that it heats up in a couple of minutes and the heat is directed at the objects or people around it, quickly taking the chill out of the air and providing a comfortable ambient temperature.
The other advantage of radiant heating is that it doesn’t dry out the air like infrared or gas heaters. Users also don’t have to worry about their children or pets getting too close to it because, even though it gets hot, it can be touched.
To enter the competition follow the steps below:
Competition entry details:
3. The competition closes on 31 July 2018.
4. Winners will be notified via Twitter on 1 August and Takealot.com will be in touch to organise delivery.
5. The competition is only open to South African residents.
Deezer to host Hotstix’s Mandela tribute playlist
Deezer is celebrating Nelson Mandela on the centenary of his birthday by hosting a tribute playlist created by music legend Sipho “Hotstix” Mabuse.
Mabuse, a legendary figure in African music, first rose to prominence in the 1970s with his band Harari and later developed a name for himself as a solo artist. One of his best known songs was the global hit BurnOut in the 1980s.
The playlist takes the listener on a captivating musical journey through the life of Nelson Mandela. It was compiled by Mabuse, who consulted with Mandela’s family and friends to ensure that the music would be relevant and accurate. The playlist also features commentary by Mabuse, which was recorded in his Soweto home.
“I have tried to tell the story of the music that Madiba loved,” says Mabuse. “The Playlist excludes the time in prison obviously, as Madiba would not have had exposure to music in that time. We have focused on the music we know he loved before and after that period. This recording was really an emotional journey for me, but an incredible opportunity to document these memories.”
The playlist features the music the young Mandela loved, such as The Manhattan Brothers, Solomon Linda, Brenda Fassie and Miriam Makeba. It includes struggle songs from Chicco, Johnny Clegg, Hugh Masekela and Yvonne Chaka Chaka. The playlist also includes Mandela by Zahara, one of the younger artists who caught Madiba’s ear.
Mabuse also offers stories of his own songs, such as Shikisha, a song greatly beloved by the former President.
“I was delighted to share my thoughts and hope the listeners enjoyed the musical journey,” says Mabuse. “Madiba did enjoy music immensely and we all have a purpose wherever we are in the world to celebrate culture and to learn from different cultures and music forms and styles.”
This playlist was inspired by the Nelson Mandela 100 campaign, calling on corporates and individuals to act as sources of inspiration and engage in conversation and action.