Connected devices continue to pose a major risk to organizations

(Image credit: Shutterstock)

New research for Forescout has revealed that connected devices continue to pose considerable and wide-reaching security risks to organizations across all sectors as many of these devices are still susceptible to both known and older vulnerabilities.

To compile the first edition of its new Enterprise of Things Security Report, the firm assessed the risk posture of over 8m devices across financial services, government, healthcare, manufacturing and retail. By meticulously auditing applications and industries which rely on IoT devices, Forescout was able to identify points of risk inherent to device types, industry sectors and cybersecurity policies.

Cybercriminals continue to innovate at a rapid pace when it comes to gaining access to and exploiting connected devices. At the same time though, the attack surface of organizations have continued to expand as they add more IoT devices to their networks. Regional director of UK&I at Forescout, Richard Orange provided further insight on the report's findings, saying:

"Windows devices have always had a reputation for being susceptible to cyber attacks. But after analysing millions of connected devices for our inaugural Enterprise of Things Security Report, seeing the true scale of the problem is still surprising, to say the least. Many critical devices - be that HVAC systems, power supply appliances or medical devices like infusion pumps - across all sectors can still be easily compromised using known vulnerabilities.”

Riskiest connected devices

By analyzing data from its Device Cloud, Forescout discovered that the riskiest device groups include smart buildings, medical devices, networking equipment and VoIP phones. IoT devices now exist in every vertical and they present a significant risk to modern organizations as both entry points into vulnerable networks or as final targets of specialized malware.

When it came to device types, Forescout found that devices within physical access control systems pose the highest level of risk. These devices not only open doors to the physical world but are also ubiquitous. According to Forescout's data sample, physical access control solutions are at the highest risk because of the presence of many critical open ports, abundant connectivity with other risky devices and the presence of known vulnerabilities.

Older vulnerabilities also continue to pose a risk to connected devices. Of the Windows devices used in financial services, one in four (28%) are still susceptible to the BlueKeep vulnerability more than a year after it was first discovered. Additionally, 21 percent of Windows devices in government could be compromised using the Curveball vulnerability.

Forescout also found that medical devices have an enormous potential impact if compromised and many of these devices have critical open ports that expose dangerous services on the network. In the healthcare industry alone, more than 35 percent of Windows devices are running outdated versions of Microsoft's operating system and solely rely on the thin layer of protection provided by the company's Extended Security Update program.

Connected devices have the potential to change the world but to do so, they first must be protected with the right safeguards and regularly updated.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
Klipsch Klipschorn AK7 in a room with lots of dark wood furniture and a bare brick wall
Klipsch just updated two of its most iconic stereo speaker designs, keeping these beautiful retro icons on your most-wanted list
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?