Two Self-Imposed Obstacles in the Way of the Internet of Things The variety of devices comprising the Internet of Things world is staggering, and standardization of security protocols across that universe lacking. As a result, each manufacturer has historically taken its own approach to securing devices.

And unlike the texting, word processing and video-call-making multifunctional smartphones that administrators are used to managing, many Internet of Things devices continue to be designed and deployed for rather specific duties. But standardizing IoT security may bring with it an unexpected downside: Between point-to-point networks where every device has a voice, and the hub-and-spoke models that minimize the number of connections in favor of a central provisioning point, there are plenty of benefits and downsides to go around.

And that may be a good thing, at least for now. A small sampling of security protocols in use today could provide a template for advancement and wider commonality across the industry. But Blaisdell said many administrators have even bigger problems. The sheer scale of the Internet of Things justifiably causes angst in the hearts of network administrators, but it dovetails with another issue that complicates security efforts even further.

There are different uses, different vendors, different generations and different capabilities, and these all make security more difficult. Knowing where vulnerabilities exist across a handful of smartphone OS varieties pales in comparison to keeping pace with the status of thousands of different sensors, cameras, meters, controllers and other machines.

What administrators can do to improve IoT security Conventional approaches to network security will likely need to be rethought before an enterprise deploys IoT to any significant degree. Instead, become familiar with gateway solutions that incorporate protocol filters, policy capabilities and other functionalities directed at the security challenges specific to IoT.

Because many firewalls may not control Internet of Things traffic as effectively as other types of network flows, a different approach needs to be considered.

It may be a somewhat extreme data protection measure, but if highly sensitive information is hanging around, the organization should conduct a risk assessment to see what level of network separation is appropriate.

Staying up to date with evolving vulnerability assessments and advancements in security solutions will also be crucial. With an understanding of the IoT security landscape, administrators are better equipped to be part of the decision-making process when it comes to deploying connected devices.

Data exfiltration and other anomalies will need to be spotted quickly, and preventing problems in real time may be key to stemming suspicious activity.

