Real-time Monitoring of IoT devices for CRA - yes or no?

My background is hardware and telco originally, semiconductors for 10-15 years then the last 10-12 years in IoT. Security has been a problem I've been working on for most of that semiconductor time and it still nags me today in IoT.

A little context : After the Fairlife news last month and the protracted JLR case I revisited something I've been working on for a while. Are these cyber-security events purely at an IT level, or are IoT devices and systems a growing part of the problem? The Verizon DBIR has said for years that they are, so I went back through some of the old Verizon Data Breach Incident Reports and this case stood out.

A university had around 5,000 of its own IoT devices (vending machines, lighting, sensors) quietly pulled into a botnet. Nobody spotted it at a device level. They only caught it because the network suddenly started firing thousands of odd DNS requests. The devices were the weakness, but the traffic is what actually gave it away. Or should have, a lot sooner than it did.

What I'm curious about is how people here run things day to day especially with CRA compliance in mind. So much of the IoT security conversation is about hardening at build time (firmware, credentials, segmentation) and hardly any of it is about monitoring what the fleet actually does once it's out in the world. So, a few questions please...

* If you run real fleets, do you baseline normal device behaviour and alert on anomalies (odd domains, data spikes, strange SIM/traffic patterns), or is it mostly guard our perimeter and hope?
* Where does your anomaly detection sit: on-device, gateway, network, or the carrier/connectivity side? Pick more than one if you need to.
* Does the monitoring just drown you in noise, or does it catch real incidents?

Is behavioural monitoring standard practice now, or still a nice-to-have that most IoT "estate managers" quietly skip?

reddit.com
u/Seahawker-One-2599 — 3 days ago

Is VAR spoiling football/sport?

Despite the title of this podcast they don’t really address the question. They do spend a couple of minutes reliving the disgraceful VAR intervention which robbed Hearts of the SFPL title.

This is Financial Times so of course it’s about money. In fact, Hawkeye and other tech is all about sport betting. Listen to this and tell me it isn’t horrific.

Despite what fans think and the utter incompetence of Scottish referees, VAR is here to stay.

https://open.spotify.com/episode/7r2UIBLPD1oD3CghUXQWPO

u/Seahawker-One-2599 — 5 days ago
▲ 4 r/IOT

Are product/device designers seeing demand from their Enterprise customers and/or management for cyber-resilience measures?

Background here is CRA, NIS2 but also bloating cyber-insurance premiums. Insurers are now asking for continuous evidence of cyber-resilience, not a one-off assessment.

Is this rippling down to device or procurement specs?

This Transforma piece rightly forecasts the rise of Anomaly & Threat Detection (ATD) which performs real-time monitoring, early detection and corrective action. https://www.linkedin.com/pulse/iot-network-anomaly-threat-detection-atd-solutions-n3yde

So a follow on question about those ATD tools. How useful would automated compliance reporting be?

Compliance reports are audit-ready logs you can hand to regulators, customers or insurers on demand.

u/Seahawker-One-2599 — 8 days ago
▲ 160 r/golf

What are five things NOT worth the money in golf?

Pinched this from X but was fun. I expect LIV and ProV1 to feature. Go on, hit me.

reddit.com
u/Seahawker-One-2599 — 13 days ago
▲ 10 r/IOT+1 crossposts

Anyone here dealing with EU CRA compliance for their connected devices? Tell me, how are things going for you?

I read several subreddits, some are just starting work on CRA compliance, some are already ready and want to hear how you're doing.

reddit.com
u/Pitiful_Signature264 — 20 days ago
▲ 3 r/IOT

Opinions please - what are the most important benefits of eSIM for IoT

Most IoT industry analysts will highlight the following key eSIM benefits for IoT.

  1. security - unlike SIM cards, embedded/chip SIMs cannot be removed (so easily)
  2. reliability - embedded/chip SIMs are more electro-mechanically robust
  3. vendor lock-in - eSIM means I can switch providers easily
  4. regulation-proof - different carriers and telco regulators have different policies or commercials around roaming
  5. single SKU - OEMs designing in a single SIM which can be provisioned and re-provisioned OTA to suit deployment needs. Cost and logistics benefits.

They poll businesses so I don't doubt them at all but I'm curious if developers, tech consultants, ODMs (for example) have other views please?

reddit.com
u/Seahawker-One-2599 — 22 days ago

Real-time Monitoring of IoT devices - yes or no?

My background is hardware and telco originally, semiconductors for 10-15 years then the last 10-12 years in IoT. Security has been a problem I've been working on for most of that semiconductor time and it still nags me today in IoT.

After the Fairlife news this month and the protracted JLR case I revisited something I've been working on for a while. Are these cyber-security events purely at an IT level, or are IoT devices and systems a growing part of the problem? The Verizon DBIR has said for years that they are, so I went back through some of the old Verizon Data Breach Incident Reports and this case stood out.

A university had around 5,000 of its own IoT devices (vending machines, lighting, sensors) quietly pulled into a botnet. Nobody spotted it at a device level. They only caught it because the network suddenly started firing thousands of odd DNS requests. The devices were the weakness, but the traffic is what actually gave it away. Or should have, a lot sooner than it did.

What I'm curious about is how people here run things day to day. So much of the IoT security conversation is about hardening at build time (firmware, credentials, segmentation) and hardly any of it is about monitoring what the fleet actually does once it's out in the world. So, a few questions please...

  • If you run real fleets, do you baseline normal device behaviour and alert on anomalies (odd domains, data spikes, strange SIM/traffic patterns), or is it mostly guard our perimeter and hope?
  • Where does your anomaly detection sit: on-device, gateway, network, or the carrier/connectivity side? Pick more than one if you need to.
  • Does the monitoring just drown you in noise, or does it catch real incidents?

Is behavioural monitoring standard practice now, or still a nice-to-have that most IoT "estate managers" quietly skip?

reddit.com
u/Seahawker-One-2599 — 29 days ago
▲ 2 r/Information_Security+1 crossposts

A university once got DDoS'd by its own vending machines. How much are people here actually monitoring IoT device behaviour vs just securing the endpoint or guarding the perimeter?

[removed]

reddit.com
u/Seahawker-One-2599 — 30 days ago