Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data / Password Recovery
        • File Integrity Management
        • Data Loss Prevention
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Developer Tools
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, DeviceTotal Blog

Are You Sitting on an Enterprise Device Security Time Bomb? | ArcusTeam

Are You Sitting on an Enterprise Device Security Time Bomb?

This article was originally published by LOGON’s partner ArcusTeam. Click here to view the original article.

Enterprises regularly face the challenge of securing conventional IT assets, such as computers and phones. However, their threat landscape has extended beyond traditional IT assets and into the domain of connected devices. For example, IP cameras, printers, and just about any device that has the potential to connect to the network.

This growing domain poses a significant challenge for enterprises. The main reason for this is that as the number of connected devices continues to grow, so too does the attack surface that accompanies them. Despite the plethora of benefits connected devices offer across industries, their innovation comes at a potentially high cost to your enterprise’s security.

Palo Alto Networks 2020 Unit 42 IoT Threat Report sheds light on the declining security posture of IoT devices, the current challenges enterprises face with securing threats originating from these IoT devices, and which IoT devices are the most susceptible to attacks. In this blog post, we’ll be discussing what we perceive as the main takeaways from this report and what we think enterprises need to focus on to secure networks and assets.

A Growing Field, a Growing Problem

The IoT device industry has been growing exponentially over the past couple of years and is a trend that has no end in sight. In 2020, there were 9.9 billion IoT devices installed and this number is predicted to reach 21.5 billion by the year 2025! Today, IoT devices make up for more than 30% of the network-connected endpoints at the average enterprise, leaving enterprises with a significant enterprise device security problem.

According to Palo Alto’s report, 98% of IoT traffic is unencrypted, allowing hackers that successfully bypassed an enterprise’s first layer of security and established command and control to easily listen to unencrypted network traffic. This means that sensitive and confidential information on the network will be readily available to hackers to use and exploit. Even more worrisome is that 57% of IoT devices are vulnerable to medium or high severity attacks, which gives attackers an easy opportunity to make your enterprise the victim of the next large scale attack.

 

 

Enterprise Device Security Challenges in the Realm of IoT Security

Enterprises face a few major challenges when it comes to their enterprise device security. One of those challenges is that their currently deployed tools do not support IoT devices. Frequently, enterprises turn to agents for their endpoint protection systems. However, most IoT devices run on obsolete operating systems that do not support running an agent. Without this ability, enterprise device security teams are unaware of their IoT devices’ risks, leaving them open for exploitation.

A second challenge is that enterprises cannot correctly identify all IoT devices in their network. Without proper identification of these devices, security teams cannot accurately secure them (they cannot protect what they cannot see) and risk jeopardizing their enterprise network security

 

 

A Device Security Time Bomb

Connected devices all have the potential to serve as entry points for attackers to gain access to your enterprise’s network. These devices are often overlooked as security threats; for example, security cameras and printers were mentioned in the report as the source of significant security threats. While security cameras only accounted for 5% of an enterprise’s IoT devices, they made up 33% of their security issues! With their lack of built-in security and vulnerabilities in their browser interfaces, printers have the potential to serve as the perfect entry point for a cyber hack and grant access to other computers on the network.

IoT Threat Trends

Exploitable Vulnerabilities

Without the proper enterprise device security methods in place, IoT devices’ vulnerabilities are easily exploited. According to the report, 41% of attacks that take place occur through device vulnerabilities. To make matters worse, most hackers don’t stop at the device level but can then leverage this vulnerability to gain access to other systems in the network to attack.

 

Faulty Passwords Leading to Attack

Hackers often carry out password-related attacks using weak or default passwords used by manufacturers and the poor security practices surrounding them.

 

Unsupported Software and Operating Systems

Security systems heavily rely on patching through security updates to keep their enterprise security up to par and protect their systems and networks from attack. IoT devices often run on unsupported software and operating systems reaching their end-of-life (EOL), which makes patching the devices impossible because security updates are no longer available.
For the IoT devices running on EOL operating systems, they are vulnerable to old and well-known exploits because they cannot receive security updates against them. Scarily, 83% of medical imaging devices have this very problem of EOL and unsupported operating systems.

Zero-Day Vulnerabilities go Undiscovered

One of the major challenges CISOs face is their current vulnerability management solutions‘ inability to identify zero-day vulnerabilities. If these vulnerabilities go undetected, enterprises’ corporate networks are open to a whole array of unknown attacks. That’s what happened when two zero-day vulnerabilities were discovered in Cisco routers, allowing hackers to remotely gain access to the devices and crash its security processes. This type of attack can have serious repercussions on an enterprise.

Even more worrisome is that known vulnerabilities are slipping between the cracks, because of the incompatibility of connected devices with existing vulnerability management solutions. Oftentimes, these implemented solutions require connected devices to undergo a client or agent installation to ensure connected device security. However, the overwhelming majority of connected devices are unable to undergo these installations, leaving known vulnerabilities undetected.

 

No Prioritization of Connected Devices to Secure

Most vulnerability management solutions provide CISOs and security teams with long lists of network vulnerabilities. Unfortunately, the list does not prioritize vulnerabilities based on their location in the network or their importance to business processes.

Without this crucial information, CISOs have no way to differentiate between critical devices that are crucial to business operations and need immediate mitigation, and those that are rated as critical but are actually of lower importance to business processes and do not require immediate mitigation.

 

Mitigation of Connected Device Vulnerabilities

CISOs receive an exhausting list of vulnerabilities, and their security teams spend a grueling amount of time manually implementing mitigation measures for found vulnerabilities. Without an automated solution, security teams cannot possibly mitigate all critical vulnerabilities in a timely manner, leaving their enterprise’s networks open to attack and their connected device security ineffective in the long-term.

Multiple Tools for Connected Device Security

There currently is no one tool that can support all types of connected devices, which leaves CISOs juggling multiple tools to stay on top of the security issues of all of their connected devices. Using multiple tools for connected device security is not only inefficient and expensive, but also allows for certain devices to slip between the cracks.

Reactive Solutions

Current market solutions only identify attacks taking place after an attacker has managed to infiltrate the corporate network. These attacks can go undetected for months, resulting in vast damages to the corporation. With reactive solutions, CISOs are struggling to stay ahead of attacks, and desperately need a predictive solution that enables them to avoid future ones.

ArcusTeam’s Take on it all

Book a Demo with our specialist

With the growing threat of connected devices, enterprises need a centralized solution now more than ever to help them safeguard their networks from attacks and effectively manage device vulnerabilities.

ArcusTeam’s DeviceTotal platform offers enterprises a proactive approach to their enterprise device security. In a single platform, DeviceTotal continuously predicts, identifies, assesses, prioritizes, and mitigates any potential cyber threats – before they threaten your connected networks. With DeviceTotal, your enterprise can get all the benefits from your connected devices, but without all the risk.

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form