US authorities dismantle several large IoT botnets
US authorities have dismantled several of the world's largest IoT botnets, responsible for some of the most powerful denial-of-service attacks on record. The networks were built from compromised devices and used both directly and as for-hire infrastructure for other criminals. The operation illustrates the scale of modern botnets and the continued abuse of poorly secured IoT devices.
What this means for your organisation
Norwegian organisations are affected in two directions. Externally, denial-of-service attacks can hit customer portals, payment services and anything else that must stay available. Internally, your own cameras, sensors, printers and network equipment may be the devices inside such networks, often with no clear owner after deployment. Availability and resilience are explicit parts of the NIS2 security requirements.
Berigo recommends
- Inventory IoT and network equipment, and remove or segment devices with no update support.
- Replace default passwords and close management interfaces facing the internet.
- Confirm with your network and hosting provider what denial-of-service protection is actually contracted.
- Rehearse a scenario where a public-facing service is unavailable for several hours, with defined customer communication.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch