Protecting critical infrastructure in an IoT world

Attacks on critical national infrastructure such as power grids, communication networks and the banking sector have massive implications for any country. Disruption to public services, hits to the economy and even loss of life are all potential scenarios.
For this reason, governments and private-sector organisations are increasingly focused on finding ways to ensure such infrastructure is secure and able to withstand cyber attacks. Taking a reactive stance is simply not an option.
To make the challenge even larger, there is a new and complex area being targeted and utilised by cyber criminals. Dubbed the Internet of Things (IoT) it comprises the growing range of connected items that are already touching many facets of daily life.
IoT devices range from web cams and home automation devices to drones and driverless cars. They also include sensors that monitor everything from power station operations to the integrity of dam walls. Any attacks that cause these devices to malfunction could have dire implications, and they have also been utilised by threat actors to perform DDoS attacks.
The battle has already begun
It might be easy to regard the IoT as a futuristic world that’s still on the planning board, but nothing could be further from the truth. There are already billions of connected devices and the number is growing exponentially.
The security challenge they bring was highlighted in late 2016 when criminals disrupted US domain name system provider Dyn. The attack caused disruption to major websites such as Amazon.com, Netflix, Visa and Starbucks.
Security experts discovered the disruptions were caused by a distributed denial of service (DDoS) attack mounted using large numbers of IoT devices including baby monitors, residential gateways and web cameras.
The incident brought into sharp focus the implications of IoT on critical infrastructure security. As the number of devices grows, the potential for attack and disruption can only increase.
It’s likely that IoT-based attacks will follow a similar path to cyber attacks against more traditional IT systems. Criminals tend to begin by using a botnet comprising large numbers of devices which is then used to disrupt a specific target.
The second step is usually the theft of personal or financial information that can be used for profit.


