Control systems with a multitude of microprocessors and networking components are at the heart of every smart lighting network. A cyber compromise of any one of these control system elements could have serious consequences, including operational disruptions and safety incidents. As lighting control becomes ubiquitous, the cyber threats go well beyond controlling lights themselves such as changing stoplights or cutting out airport runway lights or causing a city’s streets to go dark which are life-threatening situations. The other risks are that hackers could use the potential billions of devices connected to lighting networks to wreak havoc by: Penetrating peripheral enterprise databases to steal intellectual property or valuable data;
- Hijack connected systems such as security or life-safety systems gain entry, restrict entry (see recent ransomware attacks), or even cost lives during emergency situations.
- Launch massive DDOS attacks that cripple the web.
- Exploit smart lighting networks connection to BEMS to penetrate smart grid distribution networks.
- Pool buildings together to manipulate demand response/load-shedding applications in scale to trigger blackouts or drain available energy storage reserves, etc.
Recent developments in IT, automation, and business processes are increasing the likelihood that these events can occur if the market moves forward without addressing security weaknesses. A new survey
report exposes a frightening lack of security for mobile and particularly IoT applications. The report was sponsored by IBM and Arxan Technologies. The following excerpt is taken from this report:
"On average …
20 percent of IoT apps are tested for vulnerabilities. An average …
38 percent of IoT apps tested contain significant vulnerabilities."
At our recent industry forum in Orlando, I had a chance to talk about these findings with Constance Matthews from
Securicon, which specializes in application security services that span the entire application life-cycle (design evaluations, vulnerability and penetration assessments, remediation, and education on secure design principles). Her assessment of this reports findings is that it significantly underestimates the security threats. To the best of her knowledge, Securicon has yet to encounter an application that did not have vulnerabilities.
IIoT Disrupts System Designs and Cybersecurity Methodologies
Organizations must understand that IIoT will change their operations and create new cybersecurity challenges. Many assume that this will only involve installing additional sensors in facilities and enabling external access to the associated data. But the most popular IIoT use cases require integrating multiple technology developments with traditional control systems. These include mobility, ubiquitous connectivity, cloud computing, and smart (IoT-enabled) devices. Each of these developments represent new challenges for cybersecurity teams and IoT-enabled lighting solutions must be assessed from an IIoT cybersecurity perspective based on a new model.
While security concerns will be acknowledged, history suggests that they will not be enough to limit this explosion in connectivity. Owners/operators will support this need for boundary-less access and smart lighting vendors will enable ubiquitous connectivity in their products to support remote service strategies. Once connectivity is built in, system designers will freely use it to integrate remote systems, devices, and applications. From an industrial cybersecurity perspective, these developments will increase the attack surface exponentially, along with number of threats that must be managed. This will also reduce the effectiveness of traditional strategies for managing vulnerabilities and intrusions.
The cybersecurity paradigm has changed, the ability to offer safe and secure products and systems is paramount to success; Security is a key differentiator which will eventually become a requirement for market competitiveness. ARC Advisory Group’s long-running research into industrial control systems (ICS) and ICS cybersecurity provides a unique vantage point for assessing the cybersecurity implications of the emerging Industrial Internet of Things (IIoT). We have closely monitored the development and adoption of ICS cybersecurity standards and best practices and believe they are having a significant impact on the security of connected systems. ARC recognizes the fear that exists in exposing critical infrastructure, but lights are ubiquitous and using lights as an IoT platform means it must be treated as critical infrastructure. A few newsworthy attacks will raise awareness and present strong headwinds for IoT-enabled smart lighting solutions, delaying a transformational platform from achieving rapid market adoption. IIoT is disrupting traditional security practices, and addressing the new requirements of IoT architectures from a cybersecurity perspective will be a crucial component of success in a digital world.