As I progress through my Cyber Security degree, I am learning more and more that approaching security the right way means identifying the risk something poses and determining how you want to address that risk. There are essentially three things that make up a risk: a resource or asset that the risk will harm, a vulnerability that makes the risk possible, and a threat that carries out the risk. An every-day example of this is the risk of getting into a car accident: you, people with you, and the car are the assets, bad traction is one vulnerability, and slick roads and/or ditsy drivers are related threats. For each risk, we have to decide how to reduce the risk to a tolerable level. This can be done by reducing the risk's probability or impact or by being willing to stomach it when it happens.
What does this have to do with the IoT, though? Previous posts have focused on the risk surrounding the IoT--hackers stealing private data, disabling your car, watching you through your security cameras, and so on. The vulnerability and threat there are easy to identify: the vulnerability is IoT insecurity and the threat is the hacker. What is the asset, though? You.Your family. Privacy. Convenience. And so on--anything that could be damaged by a hacker breaking into your IoT stuff.
So there's a risk that needs to be resolved. Two other factors need to be included, though: How big of a deal is it for the risk to happen, and how likely is it for the risk to happen? In many people's minds, privacy is not a big deal--their whole life is plastered on social media, they don't care what the EULA of their new game says, and they are atrociously insecure in their digital habits to start with. Thus, they probably don't see an IoT hack as a big deal. Also, most people don't think it is terribly likely they will be hacked; who wants to kill average Joe's car while he's on the highway and obliterate him, after all? Or who would want to spy on his living room?
The Internet of Things threatens privacy and personal information, but most people are conditioned to treat those things as low-value anyway. Also, the likelihood of the risk happening is rather small (or so people believe). These thought patterns have affected IoT security: by considering the risk as unlikely and by living as if their personal info isn't worth a whole lot, people are signing off on IoT insecurity. In other words, we have decided to stomach the risk the IoT brings; it costs more trouble than it's worth to reduce that risk, in most people's opinion, so they address IoT risk by accepting it. Is that a bad thing? I don't know; that's a choice for individuals. It is worth noting, however, that as the IoT gets more popular, attacks on the IoT will increase in frequency, scope, and impact. How long are you willing to manage your IoT risk by simply stomaching it? That is a question we all need to answer.
No comments:
Post a Comment