With the FTC’s 2015 report “Internet of Things: Privacy & Security in a Connected World” (“Report”) the idea that more than just computers and phones are able to connect to the Internet. In fact, the Report states that the “IoT explosion is already around us.” This is true, and the Report goes on to describe some of the more interesting things that can be connected to the Internet which most of us don’t think about (e.g. smart health trackers, smoke detectors, and light bulbs). However, how vast is the actual IoT? And what does that mean to businesses?

As security professionals will tell you, if it has an IP address, it is a potential access point to your network. As such, it is a potential place where a hacker can find a way into your network and then “elevate permissions” into more sensitive parts of a network. This seemed to the be way that several recent large hacks occurred. Thus, the internet of things represents a potential security hole if one doesn’t consider all the different devices which can be hacked.

So – what is out there which has the ability to acquire an IP address (and thus is a hacking risk)?

These we know about:

  • Desktop Computers
  • Laptops
  • Tablets
  • Smartphones

But what about:

  • Copy machines
  • Printers
  • Fax machines
  • VoIP enabled Phones
  • Televisions
  • Bluetooth headsets
  • cash registers (Point-of-Sale terminals generally)
  • Handheld barcode readers
  • Smart thermostats Keycard readers (for doors)
  • Security cameras
  • Light bulbs
  • Environmental control panels
  • Lab equipment
  • Medical diagnostic equipment
  • Warehouse inventory scanners
  • The fridge in the break room
  • Personal fitness monitors
  • Wristwatches (iWatch)
  • Armbands 
  • Glasses

And maybe even…

Shirts and other clothes.

As each one of these neat bits of technology start to take hold companies which allow them into the physical range to connect with the corporate network will need to have a strategy to manage the security risks inherent in all of them.

It’s not going to get any easier…