Devices, Industrial IoT

Armis Identifies the Riskiest Medical and IoT Devices in Clinical Environments

Businesswire | April 18, 2023 | Read time : 02:00 min

Armis Identifies the Riskiest

Armis, the leading asset visibility and security company, today released new research identifying the top connected medical and IoT devices that are exposed to malicious activity in clinical environments. Data analyzed from the Armis Asset Intelligence and Security Platform, which tracks over three billion assets, found nurse call systems to be the riskiest* IoMT device, followed by infusion pumps and medication dispensing systems. When looking at IoT devices, IP cameras, printers and Voice Over Internet Protocol (VoIP) devices are topping the list.

By 2026, smart hospitals are expected to deploy over 7 million IoMT devices, doubling the amount from 2021. Medical and non-medical devices are increasingly connected, automatically feeding patient data from monitoring devices into electronic records. These connections and communications within a medical environment help improve patient care but also make it increasingly vulnerable to cyberattacks, which could result in the interruption of patient care.

Upon a comprehensive analysis of the data from all connected medical and IoT devices on the Armis Asset Intelligence and Security Platform, several noteworthy conclusions can be drawn

  • Nurse call systems are the riskiest connected medical device, with 39% of them having critical severity unpatched Common Vulnerabilities and Exposures (CVEs) and almost half (48%) having unpatched CVEs.
  • Infusion pumps are second, with 27% having critical severity unpatched CVEs and 30% having unpatched CVEs.
  • Medication dispensing systems are in third place, with 4% having critical severity unpatched CVEs, but 86% having unpatched CVEs. Moreover, 32% run on unsupported Windows versions.
  • Almost 1 in 5 (19%) connected medical devices are running unsupported OS versions.
  • More than half of IP cameras we monitored in clinical environments have critical severity unpatched CVEs (56%) and unpatched CVEs (59%), making it the riskiest IoT device.
  • Printers are the second riskiest IoT device in clinical environments, with 37% having unpatched CVEs, and 30% having critical severity unpatched CVEs.
  • VoIP devices are in third place. Although 53% of them have unpatched CVEs, only 2% have critical severityunpatched CVEs.

“These numbers are a strong indicator of the challenges faced by healthcare organizations globally. Advances in technology are essential to improve the speed and quality of care delivery as the industry is challenged with a shortage of care providers, but with increasingly connected care comes a bigger attack surface,” said Mohammad Waqas, Principal Solutions Architect for Healthcare at Armis. “Protecting every type of connected device, medical, IoT, even the building management systems, with full visibility and continuous contextualized monitoring is a key element to ensuring patient safety.”

Armis secures all medical assets and patient care environments in some of the largest healthcare delivery organizations around the world:

“Armis appeared to be a good alternative for us because it immediately provided us with visibility into what devices were plugging into the network. It shows us how they are interacting with each other, creates alerts based on observed behavior and enforces firewall rules based on those alerts,” said Brian Schultz, Director of Network Operations and Security, Burke Rehabilitation Hospital.

“Metrics and accountability are key to understanding how to protect the hospital’s network, and Armis has a major role in making the relevant data available to us in an easy-to-access manner. It has definitely filled in the gaps in our security arsenal by uncovering risks we never knew about previously. At first, I thought Armis was a nice-to-have, but now it’s become an integral part of our cyber defense,” said Dr. Michael Connolly, Chief Information Officer (CIO), Mater Misericordiae University Hospital.

KLAS Research recently named Armis a top performer at the 2023 Best in KLAS Software & Services Report for Healthcare IoT Security. To learn more about how Armis enables healthcare organizations to identify and secure IoMT, IoT, OT and IT assets

Armis is attending HIMSS April 17-21, 2023 in Chicago, IL with a speaking session taking place on Wednesday, April 19, 2023 from 3:45pm - 4:05pm CT titled: Hackers Rush in Where Agents Fear to Tread. To meet with Armis at HIMSS, please visit booth 2276 or Kiosk 4309-48 in the Cyber Command Center.

About Armis

Armis, the leading asset visibility and security company, provides the industry’s first unified asset intelligence platform designed to address the new extended attack surface that connected assets create. Fortune 100 companies trust our real-time and continuous protection to see with full context all managed, unmanaged assets across IT, cloud, IoT devices, medical devices (IoMT), operational technology (OT), industrial control systems (ICS), and 5G. Armis provides passive cyber asset management, risk management, and automated enforcement. Armis is a privately held company and headquartered in California.

Spotlight

According to Counterpoint Research, the 5G+Wi-Fi 7 market will see cumulative shipments of over 7 billion devices through 2027 and grow at more than 100% annually between now and 2027 driven by leading applications including smartphones, gateways and routers, and the automotive sector.

Spotlight

According to Counterpoint Research, the 5G+Wi-Fi 7 market will see cumulative shipments of over 7 billion devices through 2027 and grow at more than 100% annually between now and 2027 driven by leading applications including smartphones, gateways and routers, and the automotive sector.

Related News

Industrial IoT

Forescout Joins MISA and Announces Integration with Microsoft Sentinel to Provide Automated Threat Management Across the Extended Enterprise

businesswire | August 24, 2023

Forescout, a global cybersecurity leader, today announced integrations with Microsoft Sentinel as part of a broader initiative to support the Microsoft Security portfolio. These integrations will deliver real-time visibility, threat management, and incident response across the extended enterprise: campus, datacenter, remote workers, cloud, mobile, IoT, OT and IoMT endpoints. The continued rise in severity, sophistication, and number of cyberattacks has shown that many organizations’ current disparate cybersecurity frameworks and tools are insufficient. Understaffed security operations centers (SOCs), a proliferation of unmanaged devices, and newly discovered and exploitable vulnerabilities on legacy systems compound and exacerbate the risk and likelihood of a breach. Sophisticated adversaries are targeting increasingly complex, heterogenous compute environments while security teams are inundated by false positives, and threats that get missed, aren’t properly prioritized, or aren’t responded to appropriately. Forescout helps enterprises continuously identify and classify every connected asset type – IT, OT, IoT and IoMT, managed, unmanaged or un-agentable – and enable the automated enforcement of appropriate security and compliance measures to reduce risk. "We’re proud to join the Microsoft Intelligent Security Association (MISA) through our integration with Microsoft Sentinel, to provide customers with a comprehensive and holistic approach to cybersecurity,” said Barry Mainz, CEO of Forescout. “With this integration, Forescout helps security teams more deeply understand the risks within their network, helps mitigate cyber-attacks, and most crucially, helps them respond rapidly and accurately if one does occur." Microsoft’s Sentinel platform adds a crucial layer of automated intelligence by delivering an impactful and automated way to drastically improve the signal to noise ratio security teams are grappling with daily. Forescout’s new comprehensive integration with Microsoft Sentinel along with long standing touch points to Microsoft’s broad Enterprise suite of solutions provides joint customers with real-time device context, risk insights, and automated mitigation and remediation capabilities that will improve overall security response times to incidents and events. This enables customers to remove complexity from the incident response process by leveraging Forescout’s automation and AI to quickly make contextual decisions to improve security or mitigate a cyber-incident. The benefits of the Forescout integration with Microsoft include: Faster mean time to respond (MTTR): Enables orchestration of host-based remediation through Microsoft Defender, via integrations with Microsoft Sentinel along with network-based response via Forescout, to accelerate mean-time-to-respond for the SOC. Comprehensive, real-time asset discovery and inventory:Provides a holistic 360-degree view of their enterprise environment. This includes valuable device context such as logical and physical network location, risk exposure, device identity, and taxonomy. Asset Lifecycle Management:Automatically assess posture and enforce compliance, identify known vulnerabilities and indicators of compromise, quarantine at-risk devices, remediate problems, and allow endpoints back onto the network with appropriate network segmentation policies, all enforced from a single platform. An ideal set of capabilities to supplement “comply to connect” initiatives with a proven ability to never lose asset context at any stage of the process. Attack Surface and Automated Threat Management:Real-time risk assessment and remediation of endpoint posture to harden devices, segmentation policies to enforce least-privilege network connectivity, automated detection and quarantine controls that together enable a true Zero Trust architecture. “Microsoft Sentinel brings together data, intelligent analytics, and workflows to unify and accelerate threat detection and response across the enterprise. With Microsoft Sentinel Content hub customers gain access to robust built-in and partner published content and solutions with the click of a button. We are thrilled to collaborate with partners like Forescout, to develop valuable and innovative content for our users,” said Rob Lefferts, Corporate Vice President, Modern Protection and SOC. About Forescout Forescout Technologies, Inc., a global cybersecurity leader, continuously identifies, protects and helps ensure the compliance of all managed and unmanaged connected cyber assets – IT, IoT, IoMT and OT. For more than 20 years, Fortune 100 organizations and government agencies have trusted Forescout to provide vendor-agnostic, automated cybersecurity at scale. The Forescout® Platform delivers comprehensive capabilities for network security, risk and exposure management, and extended detection and response. With seamless context sharing and workflow orchestration via ecosystem partners, it enables customers to more effectively manage cyber risk and mitigate threats

Read More

Industrial IoT, Investment and Business

Semtech Collaborates with UnaBiz to integrate Sigfox 0G Technology on Market-Leading LoRa® Platforms

businesswire | July 28, 2023

Semtech Corporation (Nasdaq: SMTC), a high-performance semiconductor, IoT systems and cloud connectivity service provider, today announced it is collaborating with Massive IoT service provider and integrator UnaBiz, to enable Sigfox 0G technology on Semtech’s LoRa Edge™ and the next generation LoRa Connect™ platforms. This collaboration will enable customers to develop solutions that combine LoRaWAN® and Sigfox 0G technologies, providing global coverage for more IoT use cases such as asset management through ultra-low power geolocation in industries including supply chain and logistics. Semtech’s LoRa technology, with its long range, low power and secure communication capabilities, has emerged as the de facto IoT platform for private LPWAN IoT applications. Today, LoRa Edge and the LoRa Connect transceivers offer cutting-edge radio performance with highly desirable features such as multi-band connectivity, ultra-low power Wi-Fi and GNSS scanning capabilities in a single monolithic silicon, making them highly cost-effective platforms for IoT and geolocation applications in the global unlicensed LPWAN market, ensuring wide coverage. This collaboration paves the road for LoRa Cloud™ geolocation on the Sigfox global 0G network, currently present in over 70 countries. Simplifying IoT deployments and enhancing global availability based on the combined network’s coverage will enhance the options and opportunities for developers to create world-class solutions. UnaBiz joined the LoRa Alliance® as a Contributor member recently following a series of partnership announcements with several LoRaWAN ecosystem members. In April 2023, UnaBiz opened up the Sigfox device library to the public and IoT community to build bridges with all IoT communication technologies and power sustainable business growth. The open device library facilitated the validation of the Sigfox 0G technology with the LoRa Edge platform. “With this collaboration, we are bringing together the LoRaWAN and Sigfox ecosystems to expand Semtech's LoRa platform to an even larger footprint of LPWAN networks across the globe and provide IoT developers and customers with best-in-class solutions for ultra-low power connectivity, security and cloud-based geolocation,” said Tom Mueller, executive vice president and general manager of the IoT System Products Group, Semtech. “We are creating a cost-effective, single SKU platform for our customers to benefit from the best available network coverage globally and we are enabling LoRa Cloud geolocation across these networks, bringing ultra-low power Wi-Fi and GNSS sniffing for logistics and asset tracking.” “This collaboration demonstrates our commitment to provide our customers with the most cost-effective and energy-efficient technologies for sustainable solutions,” said Remi Lorrain, Vice President of Convergence, UnaBiz. “By accelerating technology convergence at the device and software layer, we provide our customers the freedom to select the most effective and relevant connectivity, leveraging both Sigfox 0G network and LoRaWAN coverage, based on their business requirements and sustainability goals.” About Semtech Semtech Corporation (Nasdaq: SMTC) is a high-performance semiconductor, IoT systems, and cloud connectivity service provider dedicated to delivering high-quality technology solutions that enable a smarter, more connected, and sustainable planet. Our global teams are committed to empowering solution architects and application developers to develop breakthrough products for the infrastructure, industrial and consumer markets.

Read More

Enterprise Iot, Industrial IoT, Security

Applied Information Integrates IoT Connectivity with Alpha Technologies UPS to Provide Reliable Power to Traffic Control Industry

Businesswire | July 05, 2023

Applied Information, Inc., the leading provider of intelligent transportation infrastructure technology, announced today the ability to integrate Internet of Things (IoT) connectivity with Alpha Technologies Inc.’s battery backup systems. The new capability enhances the reliability and uptime for the traffic control infrastructure. The announcement was made today at the 2023 IMSA Forum and Expo, taking place in Reno, NV at the Peppermill Resort Spa Casino from June 25th – 29th, 2023. Traffic infrastructure operators can now easily monitor and manage critical traffic control devices, such as traffic signals and warning systems, outfitted with Alpha’s battery backup systems. Instant alerts of power outages relay important system status changes for rapid response to power outages preventing interruptions of service which could lead to crashes. Knowing the nature of the problem instantly can also save resources by avoiding unnecessary truck rolls, especially to isolated locations. “The integration of Applied Information’s remote communications technology with Alpha’s power solutions increases customer value,” said Max Guenther, Director of Industry and Traffic at Alpha Technologies, Inc. “Having the Alpha UPS backup to support intersections outages is extremely important. When combining these two solutions, customers will know the nature of the outage, if the intersection is running on battery backup, and what to do to keep systems online.” “Alpha is a leader in the UPS market. By marrying battery backup and remote communication, we can provide detailed system insights and advanced warning of power failures,” said Peter Ashley, Vice-President of Business Development for Applied Information, Inc. “As a result, Traffic Engineers will see huge time savings by knowing the exact fault before heading to site.” About Alpha Technologies Alpha Technologies Inc. provides power conversion, protection and standby products for telecommunications and cable television industries, including custom, application-specific power solutions and hardened, powered gateways for data backhaul applications. In addition to product development, Alpha Technologies provides a comprehensive range of installation and maintenance services, software solutions and consulting services to support its global customer base. Alpha Technologies is a member of The Alpha Group. For more information about Alpha power solutions, visit www.alpha.com. About Applied Information Applied Information® is the industry-leading developer of Smart Cities, Connected Vehicle (C-V2X), and Intelligent Transportation System (ITS) solutions for the surface transportation sector. Key products are smart traffic signals, school zone safety beacons, emergency vehicle preemption, transit, and school bus priority, asset security, and intelligent street lighting. Applied Information’s Glance Smart City Supervisory platform enables cities to manage all their traffic and ITS assets on one web-based application. Applied Information’s TravelSafely Connected Vehicle Messenger Engine connects smartphones, vehicles, and navigation apps to the transportation infrastructure providing a safer mobility experience for motorists and vulnerable road users. Applied Information's core values are to develop products that save lives, improve traffic, drive commerce, and help the environment. Applied Information, Inc. was founded in 2011 and is based in Alpharetta, Georgia. The Company also operates the Infrastructure Automotive Technology Laboratory (iATL), an incubator and developer of Connected Vehicle Applications. Applied Information's products are deployed in more than 1,000 jurisdictions in the U.S. and Canada.

Read More