{"id":14945,"date":"2021-10-11T13:00:00","date_gmt":"2021-10-11T17:00:00","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=14945"},"modified":"2023-04-10T15:53:06","modified_gmt":"2023-04-10T19:53:06","slug":"what-is-iot-security-insights-tips-from-iot-experts","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-iot-security-insights-tips-from-iot-experts\/","title":{"rendered":"What Is IoT Security? Insights &#038; Tips from 11 IoT Experts"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-smart-devices-and-other-connected-internet-of-things-iot-technologies-can-be-found-in-homes-and-workplaces-globally-but-just-how-secure-are-the-technologies-that-we-entrust-our-work-environments-sensitive-data-to-11-experts-weigh-in-as-we-take-an-in-depth-look-at-internet-of-things-security-for-businesses\">Smart devices and other connected internet of things (IoT) technologies can be found in homes and workplaces globally. But just how secure are the technologies that we entrust our work environments &amp; sensitive data to? 11 experts weigh in as we take an in-depth look at internet of things security for businesses&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The more technologically \u201cconnected\u201d our personal lives and businesses become, the more IoT security matters. <a href=\"https:\/\/www.globenewswire.com\/en\/news-release\/2021\/04\/08\/2206579\/0\/en\/Global-IoT-Market-to-be-Worth-USD-1-463-19-Billion-by-2027-at-24-9-CAGR-Demand-for-Real-time-Insights-to-Spur-Growth-says-Fortune-Business-Insights.html\">Data from Fortune Business Insights<\/a> shows that the IoT market is projected to top 1.4 trillion devices by 2027 with nearly a 25% compound annual growth rate (CAGR)!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, we\u2019re not going to inundate you with all of the IoT security statistics we\u2019ve seen \u2014 you can read more of those on your own in our <a href=\"https:\/\/www.thesslstore.com\/blog\/20-surprising-iot-statistics-you-dont-already-know\/\">IoT statistics<\/a> article. But the point here is that IoT devices are here to stay, and it\u2019s up to companies to decide how they\u2019ll be used \u2014 whether they\u2019re useful and secure assets or vulnerable targets for attackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The so-called internet of things (IoT) includes many devices found in homes and businesses across all industries. It includes network-connected devices as well as those that use other connectivity protocols (such as RFID and Bluetooth). But what does this growing reliance on connected technologies mean for businesses in terms of IoT security? We\u2019ve asked 11 security executives, developers, and other IT experts to help us answer that and other IoT and security-related questions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we\u2019ll answer the question \u201cwhat is IoT security?\u201d and explore what internet of things security entails, why it\u2019s historically been an issue to achieve, and what companies and governments are doing to address IoT security issues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-iot-security-what-it-means-to-secure-these-emerging-technologies\">What Is IoT Security? What It Means to Secure These Emerging Technologies<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/iot-market-growth-fortune-business-insights.png\" alt=\"IoT security device market growth by 2027. Data source: Fortune Business Insights.\" class=\"wp-image-14949\" width=\"478\" height=\"327\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/iot-market-growth-fortune-business-insights.png 743w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/iot-market-growth-fortune-business-insights-300x205.png 300w\" sizes=\"auto, (max-width: 478px) 100vw, 478px\" \/><figcaption class=\"wp-element-caption\">Data source: Fortune Business Insights.<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Internet of things security is a sector of information technology that focuses on securing endpoint devices, networks, and data relating to the internet of things (i.e., connected devices that aren\u2019t computers, smartphones or tablets). Basically, IoT security is a broad term encompassing the security strategies, policies, processes, and technologies that companies use to protect their IoT devices (everything from smart refrigerators and security cameras to monitors on jet engines or automobiles) and their associated data, applications and networks from being hacked or otherwise compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But why is IoT security necessary? After all, \u201csmart\u201d technologies have smart in the name, so that means they should also be secure, right? We wish. Unfortunately, that assumption about IoT security is often far from the truth as many IoT devices aren\u2019t as secure as you might think.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Mike Nelson, Vice President of IoT Security at <a href=\"https:\/\/www.digicert.com\/\">DigiCert<\/a>, says it well:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cAt its core, the IoT is about connecting things to create new, actionable data. &nbsp;Anytime connectivity is introduced into a system, cyber risks go up. If left unsecured, this connectivity can open backdoors into the organization\u2019s network.&nbsp;In addition, with growing connectivity, the new data being generated and transmitted creates additional risks.&nbsp;Whenever this data contains sensitive business or personal information it must be handled in a confidential way.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The more devices you add to your network (i.e., the more connections and entry points you create), the less secure your network becomes. If even just one of those devices has an unpatched vulnerability that an attacker exploits, then your data is at risk of exfiltration and compromise. And with so many devices in the market \u2014 and more being added daily \u2014 IoT represents a rapidly growing attack surface that bad guys can use to target your organization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-why-iot-security-matters\">Why IoT Security Matters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When users and companies buy IoT devices, there\u2019s an understandable expectation that those devices are secure. However, regardless of what any salesperson tells you, no technology or software is 100% secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IoT devices are designed and programmed by people, and people make mistakes and miss things. In some cases, a seemingly insignificant mistake can become a major exploit down the road. Of course, the significance and impact vary and may increase based on the target organization\u2019s industry and the attacker\u2019s goals. To put this another way, although a vulnerability in a smart refrigerator can result in data theft, a vulnerability in a smart medical device can result in significant harm or death to an individual. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Niko Sagiadinos, a developer and owner of the digital signage company <a href=\"https:\/\/smil-control.com\/\">SmilControl<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cIoT devices can be used as gateway to the company\u2019s or country\u2019s digital infrastructure. Trojan horses for espionage, malware for sabotage and ransomware for blackmail fraud.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, IoT devices currently lack universal certifications and standards. They\u2019re not like root of trust devices such as <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-tpm-security-trusted-platform-modules-explained\/\">trusted platform modules<\/a> (TPMs), which have vendor-neutral standards that developers and manufacturers must meet. And without those go-to trusted standards for device manufacturers and end-users to abide by, IoT is still a bit of a Wild West.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-your-iot-devices-and-network-are-only-as-secure-as-your-smallest-vulnerability\">Your IoT Devices and Network Are Only As Secure as Your Smallest Vulnerability\u2026<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019ve read any of the major headlines in recent years, it should be apparent how and why IoT security is critical. Let\u2019s consider the <a href=\"https:\/\/www.thesslstore.com\/blog\/wannacry-ransom-total\/\">WannaCry ransomware attacks<\/a> of 2017. To quickly summarize, that global security event involved attackers leveraging a security vulnerability in legacy Microsoft Windows operating systems. Prior to the attack, Microsoft released a patch to fix the issue \u2014 but many companies failed to apply the patch to their systems, leaving their systems vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same concept applies to IoT security. These devices also have known and unknown vulnerabilities that attackers can exploit in the future (if they haven\u2019t already done so). In fact, the Dyn attack, which Forbes says was responsible for <a href=\"https:\/\/www.forbes.com\/sites\/davelewis\/2017\/10\/23\/the-ddos-attack-against-dyn-one-year-later\/\">knocking out thousands of prominent websites<\/a>, relied on a <a href=\"https:\/\/www.thesslstore.com\/blog\/hacking-iot-devices-create-botnet-refrigerators\/\">botnet of hacked and compromised IoT devices<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/outreach.eclipse.foundation\/iot-edge-commercial-survey\">Eclipse Foundation<\/a> says that nearly half of their respondents (47%) currently deploy IoT solutions connected to their networks, and another 39% plan to follow suit within the next 12-24 months. And considering that every new IoT device represents a new entry point to your network, this means that the more endpoint devices you have, the more exposed your network becomes. &nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Harriet Chan, co-founder of the software development company <a href=\"https:\/\/cocofinder.com\/\">CocoFinder<\/a>, emphasizes the importance of protecting every device on your network. Companies must make the effort to secure every endpoint device regardless of how innocuous they may seem:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cIf hacked, even a printer could provide company information to unauthorized personnel. Botnets are mainly used for DDoS Attacks and pose a significant risk if a cybercriminal gains access to connected devices.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-and-why-businesses-globally-use-iot-within-their-environments\">How and Why Businesses Globally Use IoT Within Their Environments<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Wondering why companies are increasingly relying on these technologies if they pose such big cyber security risks? It\u2019s a fair question, and there\u2019s no single answer. However, many companies either already use or plan to use connected technologies because of their benefits. IoT devices have been known to help organizations in many ways, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Streamlining processes that increase productivity and agility,<\/li>\n\n\n\n<li>Improving operational efficiencies, and<\/li>\n\n\n\n<li>Reducing overall operational costs.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Connected devices have many potential applications within organizational environments \u2014 their specific usages often depend on the company\u2019s industry. For example, you\u2019ll often find IoT devices in use as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Wireless printers, smart thermostats, and even break room refrigerators in corporate environments.<\/li>\n\n\n\n<li>Robots and inventory tracking and management systems in manufacturing and industrial settings.<\/li>\n\n\n\n<li>Medical devices (such as pacemakers) and monitoring equipment in hospitals and other healthcare facilities.<\/li>\n\n\n\n<li>Geolocation trackers, sensors, and cameras in transportation-related industries (trucking, shipping, traffic management, etc.).<\/li>\n\n\n\n<li>Monitoring devices and smart grids for critical infrastructures such as utilities.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-enterprise-iot-is-a-vulnerable-and-growing-attack-surface\">Why Enterprise IoT Is a Vulnerable (and Growing) Attack Surface<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/enterprise-iot-deployment-examples.png\" alt=\"\" class=\"wp-image-14954\" width=\"453\" height=\"336\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/enterprise-iot-deployment-examples.png 741w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/enterprise-iot-deployment-examples-300x222.png 300w\" sizes=\"auto, (max-width: 453px) 100vw, 453px\" \/><figcaption class=\"wp-element-caption\">An illustrative example of some of the ways that organizations use IoT devices within their environments.<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Internet of Things technologies are becoming increasingly common within business environments. Research from the <a href=\"https:\/\/www.globenewswire.com\/news-release\/2021\/06\/08\/2243423\/0\/en\/The-Eclipse-Foundation-Releases-2021-IoT-and-Edge-Commercial-Adoption-Survey-Results.html\">Eclipse Foundation\u2019s 2021 IoT and Edge Commercial Adoption Survey<\/a> shows that 47% of the 300 IoT and edge professionals who participated currently use IoT within their organizations. Another 39% indicate that they plan to do so within the next 24 months.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, as is common in other areas of cybersecurity, IoT security often gets neglected by the companies who create the devices and the organizations that use them. But for IoT cyber security to be effective, it needs to be a collaborative approach with all parties taking steps to make devices and their uses more secure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Developers and manufacturers need to design and build secure devices and platforms, and<\/li>\n\n\n\n<li>End user enterprises (i.e., companies that are deploying, managing and using the devices within their environments) need to take steps to keep the IoT systems secure.<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:116.8555px;--tl-form-height-t:116.8555px;--tl-form-height-d:116.8555px;\" class=\"tl-placeholder-f-type-shortcode_16560 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-where-oems-fall-short-regarding-iot-security\">Where OEMs Fall Short Regarding IoT Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Developers and manufacturers often wear blinders, focusing their attention and efforts primarily on convenience and UX. And we get it \u2014 customers don\u2019t want to buy products that make their jobs harder and are frustrating to use. But with such a narrow DevOps focus, OEMs often wind up sacrificing security in their pursuit of creating the perfect experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why companies should be adopting a SecDevOps or DevSecOps approach for internet of things security. Basically, the idea here is that cyber security should be a key component of those initial planning, development, and testing processes rather than an afterthought.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-why-end-user-companies-efforts-are-often-lacking\">Why End User Companies\u2019 Efforts Are Often Lacking<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are many reasons why companies don\u2019t have strong IoT security defenses. In some cases, it can be a lack of labor, cyber security budgets, and other resources. Other times, it results from a lack of visibility \u2014 you know, the old \u201cout-of-sight, out-of-mind\u201d issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Too often, poor IoT security boils down to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A lack of understanding common IoT security risks,<\/li>\n\n\n\n<li>Reliance on bad or ineffective security practices (such as performing irregular updates and patch management) to mitigate those risks, or<\/li>\n\n\n\n<li>A combination of these two issues.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, simply understanding the reasons or explanations as to why companies aren\u2019t doing what they\u2019re supposed to doesn\u2019t negate or mitigate their damaging effects. Poor IoT security results in everything from non-compliance penalties and lawsuits and lost business and reputational damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If companies aren\u2019t investing the time and resources to secure those assets, it creates a substantial attack surface for bad guys to target. This creates the IT and data security equivalent of a buffet for bad guys \u2014 but instead of tasty foods, attackers have a selection of vulnerable devices that provide access to your network and other systems that connect to it, as well as all the sensitive data they contain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-iot-security-regulations-and-laws-historically-have-been-virtually-non-existent\">IoT Security Regulations and Laws Historically Have Been Virtually Non-Existent<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet of Things industry is still relatively new as far as cyber security standards, policies, and regulatory requirements are concerned. But IoT security is an issue that has historically been treated like the proverbial redheaded stepchild \u2014 IT teams and regulators alike have ignored the issues for as long as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is another factor that has likely had a huge impact on the rise in IoT security threats. It\u2019s also likely why several organizations took the initiative and stepped up to create their own IoT security guidelines:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.iotsecurityfoundation.org\/\">IoT Security Foundation<\/a> has many valuable <a href=\"https:\/\/www.iotsecurityfoundation.org\/best-practice-guidelines\/\">resources and guides<\/a> on their website, including their \u201cIoT Security Compliance Framework\u201d and \u201cSecure Design Best Practice Guides.\u201d<\/li>\n\n\n\n<li>NIST has an <a href=\"https:\/\/www.nist.gov\/programs-projects\/nist-cybersecurity-iot-program\">IoT for Cyber Security Program<\/a> that aims to improve the cybersecurity of connected devices and the environments that they\u2019re deployed in. They also published their <a href=\"https:\/\/www.nist.gov\/cyberframework\">Cybersecurity Framework<\/a> to help organizations protect their data and physical IT infrastructures against \u2014 as well as respond to and recover from \u2014 DDoS attacks. <em>(Note: the framework was created with critical infrastructure entities in mind [i.e., healthcare, energy and financial institutions] but also applies to organizations across virtually all sectors.)<\/em><\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-u-s-introduced-the-first-iot-security-law-in-2020\">The U.S. Introduced the First IoT Security Law in 2020<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Thankfully, this \u201cI\u2019m just going to ignore it\u201d mindset demonstrated by governments is slowly starting to change. One of the biggest examples of this evolution can be seen with the passage of the U.S.\u2019s federal IoT security law and the creation of IoT security-related policies and guidelines for federal agencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet of Things Cybersecurity Improvement Act of 2020 (<a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/1668\">H.R. 1668<\/a>) was officially signed into law on Dec. 4, 2020. This legislation requires the Office of Management and Budget (OMB) and the National Institute of Standards and Technology (NIST) to create security policies, standards and guidelines that all U.S. federal agencies (including government departments, contractors and subcontractors) that use IoT devices must adhere to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although this law technically only applies to those specified agencies, the guidelines and policies NIST and OMB set forth \u2014 such as NIST\u2019s IR 8259 \u2014 can also serve as resources for private sector organizations and businesses as well. However, there\u2019s no denying that there\u2019s still a <em>long<\/em> way to go in terms of improving IoT cybersecurity as a whole \u2014 particularly with relation to the private sector.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But Jesse&nbsp;Th\u00e9, President &amp; CEO of the B2B SaaS video conferencing solution&nbsp;<a href=\"https:\/\/tauria.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tauria<\/a>, says there\u2019s no time like the present to start working on your organization\u2019s IoT security policies.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cEven though a more all-encompassing IoT security policy is awaited, service providers and manufacturers of IoT devices must not wait to start adopting security policies. Rather companies must be enthusiastic about setting standards of market security and IoT compliance. This will help them build brand reputation, ensure consumer safety as well as align product development with emerging standards and get a head start as security standards are implemented.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-examples-of-iot-security-risks\">Examples of IoT Security Risks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The long-standing lack of industry standards and poor IoT security practices makes your network easy prey for cybercriminals. This is great for them but gut-wrenching news for you and your customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Speaking of easy prey \u2014 Chris Parker, host of the <a href=\"https:\/\/www.easyprey.com\/\">Easy Prey cybersecurity podcast<\/a> and owner of <a href=\"https:\/\/whatismyipaddress.com\/\">WhatIsMyIPAddress.com<\/a>, says that IoT security risks relating to widespread device adoption across your network typically are tied to the following:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\">\n<li>Bad guys can get access to your data and deliver malicious payloads by exploiting device vulnerabilities, and<\/li>\n\n\n\n<li>IoT devices can fail, leaving you with \u201cbricked\u201d (useless) devices without any fallbacks or fail-safes in place.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"> Adam Kohnke, Information Security Manager at <a href=\"http:\/\/www.infosecinstitute.com\/\">Infosec Institute<\/a>, shares the following concern:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>&#8220;The network interface provided by IoT devices may provide external internet connectivity to would-be attackers. IoT device manufacturers also typically leave default access credentials in place for the devices they ship. These two conditions together leave enterprises vulnerable and prone to unauthorized remote access attacks.&#8221;&nbsp;<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Once a bad guy compromises a connected device, they can use that access to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Move laterally across your network.<\/strong> This gives them the ability to discover other vulnerable connected devices, servers, and IT systems that they can gain access to.<\/li>\n\n\n\n<li><strong>Exfiltrate data.<\/strong> They can use their access to steal your sensitive data (such as intellectual property or your customers\u2019 personal information) from your systems. They can then use, sell, or post this information online to cause additional harm.<\/li>\n\n\n\n<li><strong>Install ransomware and other types of malware.<\/strong> They can use their access to install malicious software that enables them to:\n<ul class=\"wp-block-list\">\n<li>Lock your device so you no longer have access to it.<\/li>\n\n\n\n<li>Encrypt your data and demand ransom payments.<\/li>\n\n\n\n<li>Control your IoT device, making it a drone the attacker controls as part of a larger botnet.<\/li>\n\n\n\n<li>Use that botnet of compromised devices to attack you and other companies via DDoS, brute force, and credential stuffing attacks.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-one-of-the-biggest-issues-in-iot-security-complacency\">One of the Biggest Issues in IoT Security? Complacency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The impact of such attacks and IoT security compromises are devastating. But how is it that these attacks occur? Ryan Nichols, Chief Information Security Officer (CISO) at the payment processing and SaaS company <a href=\"https:\/\/curbstone.com\/\">Curbstone<\/a>, says that IoT security often gets overlooked for the sake of convenience.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cWhen it comes to the Internet of Things, out-of-the-box security is often overlooked for convenience. If left unmanaged, IoT devices can present a significant vulnerability to businesses and their data. These devices can be manipulated in a variety of ways, and the vulnerability and risk really [depend] on the device and the deployment.\u201d<\/em> <\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll take a more in-depth look at IoT security issues, risks and challenges in another IoT-related article. Be sure to check back with Hashed Out over the next few weeks to see when content becomes available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the meantime, let\u2019s explore ways you can effectively manage your network\u2019s IoT security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Managing IoT Security: Determine What Your Needs Are &amp; How Best to Meet Them<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Parker says the effectiveness of IoT security management is finding ways to meet your organization\u2019s safety and performance needs within the confines of your financial limitations. Ask yourself important questions: Do you have the in-house skills, knowledge, and tools to meet these network and IoT security needs on your own? Or would it be more beneficial to explore the option of outsourcing network management to an MSP?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For people who want to handle this responsibility on their own, Nelson says that using an IoT management platform can help:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cIoT management platforms are a great way to maintain control of a growing IoT environment.&nbsp;Management platforms should have the ability to manage and push out device updates, identity vulnerabilities, have device level visibility, generate reports on devices, and help with the overall lifecycle management of a device.\u201d&nbsp;<\/em><\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">Centralized vs Decentralized IoT Security: Which Approach Is \u201cBetter\u201d and Why?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When choosing how you want to manage internet of things security and access across your network, one of the biggest decisions you\u2019ll need to make is whether to use a centralized or decentralized approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are some advantages to using a centralized approach to IoT security management \u2014 one being that it\u2019s safer overall. Another advantage is that using a centralized management tool is that you have greater visibility of all your networks\u2019 devices so your devices don\u2019t fall between the cracks and become forgotten. However, there are also some advantages of using a decentralized system as well \u2014 improving performance by distributing processes and eliminating single points of failure that you may find in some centralized systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alex Feiszli, CEO of the next-gen cloud solutions startup <a href=\"https:\/\/gravitl.com\/\">GRAVITL<\/a>, approaches the topic from a different perspective. He says that using both approaches is ideal for IoT security management:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe array of IoT devices has become so large and complex that a centralized approach is extremely difficult to implement effectively. Still, centralized tools are necessary to help to pinpoint threats in real time. Decentralized approaches like zero-trust networking make sure all devices start with the minimal possible permissions. If you have to choose just one, go with decentralized. But don\u2019t do that, do both.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Regardless of which approach you implement, DigiCert\u2019s Nelson says to make sure it\u2019s the right one for your business:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThe answer to whether a centralized or decentralized approach is best comes down to the business needs and requirements.&nbsp;Both approaches can work and be effectively deployed \u2013 organizations need to make the decision that is best for them.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But in addition to using an IoT management platform, what else can businesses do to secure their IoT devices and their connected network environments?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-10-steps-businesses-can-take-to-increase-their-iot-security\">10 Steps Businesses Can Take to Increase Their IoT Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"h-our-group-of-experts-contributed-to-the-following-list-of-practical-steps-businesses-and-other-organizations-can-take-to-secure-their-iot-devices-networks-and-data\">Our group of experts contributed to the following list of practical steps businesses and other organizations can take to secure their IoT devices, networks, and data:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Only Use IoT Products from Reliable Vendors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It seems like everyone and their brother are coming out with their own smart technology products. This saturation of devices in the market doesn\u2019t mean that the companies are putting in the time and effort to make their devices as secure as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kohnke says that effective IoT management requires due diligence and research up front.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cIoT Device management starts with a thorough review and vendor analysis for any third party that may supply IoT devices to the enterprise, which also includes a review, to the extent possible, of the components used on the devices themselves. If a vendor review passes and devices are purchased, a security assessment should be conducted against each device to change default usernames, passwords or other default configurations to the most secure settings possible.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Part of this entails verifying that a manufacturer integrates adequate security measures into their IoT products and provides ongoing updates and support. But if there\u2019s something you don\u2019t like or seems inadequate, Kohnke emphasizes the following: <em>\u201cDon\u2019t be afraid to leave unsecure or shady vendors. If they cannot explain or provide easy to understand security processes to help perpetuate security, find someone who can.\u201d<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Implement Cyber Security Frameworks and Follow IoT Security Best Practices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We mentioned some cyber security and IoT security-related frameworks earlier that you can adopt or adapt for use within your organization. However, implementing certain security best practices is critical to securing your networks and the devices that connect to them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a few best practices that you can implement right away to make your IoT network more secure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Change factory-default device passwords to unique, strong passphrases.<\/strong> Original equipment manufacturers (OEMs) typically assign default passwords to their products. Not changing your devices\u2019 default passwords when you add them to your network leaves them vulnerable to compromise.<\/li>\n\n\n\n<li><strong>Avoid using passwords altogether<\/strong>. A great alternative to traditional password-base security is PKI authentication. This process involves installing a digital certificate on your device that enables you to securely login and authenticate without having to remember or type in cumbersome passwords.<\/li>\n\n\n\n<li><strong>Have the right people in place (in-house or outsourced) who have the right skills<\/strong>. Have developers and IT security team members who van shore up your IoT security vulnerabilities and take steps to secure your networks, applications and data.<\/li>\n\n\n\n<li><strong>Use endpoint and network detection and security tools.<\/strong> Just like having the right people in place is important, having the right security measures also matters. We\u2019ll speak more about some of those momentarily in list item #5.<\/li>\n\n\n\n<li><strong>Implement access controls to restrict or limit access to devices.<\/strong> We\u2019ve written about the importance of access controls previously and will speak more about them more in section No. 6 below: \u201cLimit Who Has Access to Your Network and Devices.\u201d<\/li>\n\n\n\n<li><strong>Encrypt all of your organization\u2019s sensitive data<\/strong>. Although some IoT technologies use encryption, it\u2019s not the case for all IoT devices. This means that any video, audio, or other data that your IoT devices collect may be vulnerable to theft or modifications by attackers. But there is good news: you can use digital certificates to secure the data that transmits across your network from your IoT devices to your applications.<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:768.375px;--tl-form-height-t:594.781px;--tl-form-height-d:594.781px;\" class=\"tl-placeholder-f-type-shortcode_13255 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\">3. Document and Enforce Internal IoT and Cyber Security Policies and Procedures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">All organizations, small businesses and large enterprises alike, should have documented cyber security policies and procedures in place. But what good do those policies and procedural guides do if you never bother to enforce them?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Chan says that enforcing these internal IoT and cyber security regulations with infractions is necessary to get users to take the initiatives seriously. After all, if users don\u2019t have any skin in the game or they know that they won\u2019t face repercussions for violating your security policies, then your security rules are like having a guard dog with no teeth.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Prepare for When Things Go Wrong<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Having documented policies and procedures in place includes having plans and procedures for your organization\u2019s business continuity and disaster recovery initiatives. It also means being ready when other types of unforeseen situations occur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to this, Tom Van de Wiele, Principal Security Consultant at the cyber security vendor <a href=\"https:\/\/www.f-secure.com\/gb-en\">F-Secure<\/a>, brings up another important point to consider:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cMake sure your business has the contingencies in place to operate without the IoT service. Not just when it comes to the availability of the service, or lack thereof, but also when it comes to the health of the supplier. \u2018Life time support\u2019 of the device and services doesn\u2019t deal with your life, or the product\u2019s life; it is the life of the company offering the technology or services\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">4. Use Dedicated Networks for Access By Different Devices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the best ways to mitigate the risks associated with having connected devices on your main network is to not have them on there at all. Sound counterintuitive? Not really \u2014 you can isolate your IoT devices from your critical business networks and applications by simply connecting them to a separate, dedicated network. This is something that the overwhelming majority of our experts recommend.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Van de Wiele shares the following about the broad attack surfaces IoT represents for many businesses:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cWhen considering IoT technologies used in the workplace, the biggest risks are not adequately separating the IoT technology from business-critical networks \u2014 and, thus, adding to the general attack surface, e.g., shared networks and infrastructure. [\u2026]<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Most IoT compromises that have been published have caught the attention of the media because, far too often, critical business networks end up in the blast radius of a compromised remote management service or hacked IoT technology stack.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/portland\/news\/press-releases\/tech-tuesday-internet-of-things-iot\">FBI recommends<\/a> using a Wi-Fi network for connected devices that\u2019s separate from your other endpoints and critical IT infrastructure. This helps limit your potential exposure should one of your devices become compromised due to an unknown or unpatched vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what about segregating devices that connect to your network in general \u2014 what\u2019s a good way to do that? Feiszli, suggests using a guest network for untrusted devices and a zero-trust virtual network for trusted devices for network segregation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, be sure to secure that network with a unique, strong passphrase to keep unintended users from connecting to that network.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Increase Your Network Visibility So You Know What Devices Are Where &amp; How They\u2019re Used<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Another critical step, according to Chan, is taking inventory of your IoT devices and network environment as a whole. Performing regular audits keeps you informed about:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which people, applications, and devices connect to your networks,<\/li>\n\n\n\n<li>What versions of software your users have installed on their devices,<\/li>\n\n\n\n<li>How recently devices and their software have been updated,<\/li>\n\n\n\n<li>How often the devices are being used, and<\/li>\n\n\n\n<li>If they\u2019re current devices or legacy systems that should be removed.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Data is a valuable resource for managing IoT security. Boris Shiklo, Chief Technology Officer at <a href=\"https:\/\/www.scnsoft.com\/experts\/boris-shiklo\">ScienceSoft<\/a>, says that monitoring and analyzing command logs helps you better understand your network and connected devices are being used (and by whom).<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cTo manage the IoT system security, the organization should log, store and analyze the commands sent by control applications to the IoT devices, monitor the actions of users. If some commands seem strange or come in huge numbers, it may be evidence of a security breach. Continuous security monitoring will help identify such potential security breaches at an early stage.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a few ways that you can increase the security of your network and connected devices:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Use antivirus and anti-malware tools.<\/strong> Using a combination of antivirus and anti-malware systems helps to protect you from traditional malware and viruses as well as more advanced threats.<\/li>\n\n\n\n<li><strong>Use perimeter network firewalls.<\/strong> Network firewalls are great tools that enable you to keep an eye on traffic as it enters and leaves your network. Essentially, they serve as gatekeepers to prevent unauthorized users from accessing your network and inside users from using your network for nefarious purposes.<\/li>\n\n\n\n<li><strong>Implement intrusion detection\/intrusion protection systems (IDS\/IPS).<\/strong> This powerful combination of tools is great for detecting and responding to unusual activity and anomalies on your network.<\/li>\n\n\n\n<li><strong>Use a vendor-agnostic IoT management platform.<\/strong> It should be pretty obvious at this point why you need to know how many devices you have on your network and where you can find them. However, this same concept applies to staying on top of your IoT-related public key infrastructure assets as well. If even one of those keys becomes compromised, it\u2019s \u201cgame over\u201d in terms of your IoT data security. This type of platform helps you discover and manage the digital certificates and keys for those individual endpoint devices.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6. Limit Who Has Access to Your Network and Devices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Identity and access management are integral to IoT security management as well as your organization\u2019s cyber defenses as a whole. Implementing strict access management practices and policies keeps you in-the-know about who is authorized to access systems and gives you a way to verify that only legitimate users are doing so. This helps to mitigate IT security risks and limits potential exposure due to credential compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some of the things you can do to improve your organization\u2019s access management:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create user profiles based on documented authorization policies and practices.<\/li>\n\n\n\n<li>Maintain a current list of current authorized users. If someone leaves, have policies in place to ensure their access is disabled immediately.<\/li>\n\n\n\n<li>Set user permissions and access privileges following those outlined procedures.<\/li>\n\n\n\n<li>Log all access and event logs for those devices.<\/li>\n\n\n\n<li>Enable single sign-on (SSO) or use passwordless authentication (such as PKI certificate-based or multi-factor authentication methods) to make your authentication processes more secure.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7. Check Your Physical Devices Regularly for Alterations or Other Evidence of Compromise<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019re not downplaying the importance of cybersecurity protections for connected devices because they clearly matter. However, it\u2019s also vital that you remember to focus on IoT security in terms of physical security as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Physical devices that exist on-premises are vulnerable to tampering and other related security threats. For example, you can compromise IoT systems by physically removing the devices or tampering with them. Unfortunately, some IoT devices aren\u2019t built to withstand physical compromises or to notify you when they occur. This leaves them \u2014 and your data \u2014 vulnerable to anyone who has physical access to them. Such security threats include everyone from malicious employees and contractors to anyone else who comes onto your property.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. Perform Regular Penetration Tests and Vulnerability Scans<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Performing cyber security without penetration testing and vulnerability scans is like trying to stop a leak without first inspecting your pipes. You can\u2019t effectively secure your network if you don\u2019t know where or how it\u2019s vulnerable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Parker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cAnyone in a position of power at an enterprise business making a major move into the IoT should invest in penetration testing. This will see a security expert probe all connected systems for weaknesses and report on where the problems lie. Remember just how complex modern computing systems are \u2014 assuming that you can fully grasp their implications without expert help is perhaps the biggest mistake you can make.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Penetration tests involve having pentesters (i.e., ethical hackers) poke and prod your cyber security defenses repeatedly in search of weaknesses to exploit. These practices vary and can involve everything from carrying out logic-based attacks and phishing attempts to testing your organization\u2019s physical security measures. Vulnerability scans, on the other hand, are automated scans that look for and report vulnerabilities that exist within your IT infrastructure (endpoints, networks, etc.).&nbsp; &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you have the in-house resources to handle this, great. But if not, you can always hire third-party experts to handle these tasks for you. The takeaway here is to use every tool at your disposal to try to figure out how every potential way that an attacker can try to compromise your systems and data before they do.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">9. Apply Patches and Updates Regularly to All Systems\u2019 Software and Firmware<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No matter how many security tools and measures you have in place, you\u2019re still at risk if any of them have unpatched vulnerabilities. This is true for cyber security as a whole as well as for IoT security specifically. Whenever manufacturers release updates, apply them to your devices and systems as soon as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Michael Miller, CEO of <a href=\"https:\/\/vpnonline.com\/\">VPN Online<\/a>, says automating updates can help with this task:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cTo secure your IoT devices, you need to keep its software and firmware updated all the time. With an updated firmware, you\u2019ll have the latest security patches that will make your devices invulnerable to cyber attacks. By simply turning on \u2018automatically check for updates,\u2019 you\u2019re already safeguarding your IoT devices.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re a manufacturer that releases updates and patches for your products, be sure to digitally sign your code. This provides added security and integrity assurance to your customers that the updates are legitimate and came from your company.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10. Educate Your Employees About IoT Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to device and patch management, there\u2019s a key final element to consider when it comes to improving IoT security: people. Ensure that each of your employees and network users \u2014 no matter whether they\u2019re a c-suite exec or an intern \u2014 has a strong understanding of cybersecurity best practices. This education should cover common cyber threats and attack methods, security policies, expectations, and penalties for violations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kohnke says that user education should also cover the use of IoT devices.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cDevices are simply purchased, installed and released for use without due diligence processes being executed. On top of device management, user education is also highly important as each business use case for every IoT device should be communicated in user awareness security training or in an acceptable use policy. People remain the largest security risk due to their autonomous nature. If they do not understand the security ramification of improper use of an IoT device, they are exposing the enterprise to unnecessary risk.\u201d&nbsp;<\/em><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Smart devices and other connected internet of things (IoT) technologies can be found in homes and workplaces globally. But just how secure are the technologies that we entrust our work&#8230;<\/p>\n","protected":false},"author":17,"featured_media":14947,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[13135,3802,13134],"class_list":["post-14945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-internet-of-things","tag-iot","tag-iot-security","post-with-tags"],"views":13972,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/08\/iot-security-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/14945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=14945"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/14945\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/14947"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=14945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=14945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=14945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}