Any IoT or Cybersecurity specialist out there?

2,023 Views | 13 Replies | Last: 1 mo ago by eric76
bigredfish
How long do you want to ignore this user?
Always looking to network with fellow Ags that work in the IoT space or with cybersecurity. I specialize in a new segment of cybersecurity called Preemptive Cybersecurity.
Drundel
How long do you want to ignore this user?
AG
Due to my global role at work and semi-expertise with OT/IACS, I sorta am/do, but really my team are the experts.
Tailgate88
How long do you want to ignore this user?
AG
Preemptive is the goal for all of us, amirite?
videoag98
How long do you want to ignore this user?
AG
It's all nice and secure until Karen clicks on that email attachment
Post removed:
by user
AGSPORTSFAN07
How long do you want to ignore this user?
AG
I failed the CISSP miserably. Does that count?
saw em off
How long do you want to ignore this user?
I feel I'm very proficient in personal cybersecurity. I love teaching people, from an everyday consumer level, how to proactively secure their digital lives. I'm very locked down in my own digital life. I use a password manager, Yubikeys for MFA, separate email addresses for different entities (banking, social, travel, etc). Lie on my answers for those sites that, for some reason still ask security questions. Locking down IoT devices is tricky for me since they come with very limited security options to begin with. I have a firewall at the house where I segment my network and block certain networks from the internet, etc.
Average Joe
How long do you want to ignore this user?
AG
AGSPORTSFAN07 said:

I failed the CISSP miserably. Does that count?

I have like 60 hours of continuing education I need to do in the next week for mine. Ugh.
AgCMT
How long do you want to ignore this user?
AG
I work for a cybersecurity manufacturer. Not sure if that counts or not.
videoag98
How long do you want to ignore this user?
AG
I work for an ISP and we recently got a notice from the FBI that during one of their cyber investigations, it was determined that some of our customers had their home routers compromised via
this Cisco exploit. https://nvd.nist.gov/vuln/detail/cve-2018-0171 It was just a notice so we could notify our customers.

Our biggest concern is that our core routers are secure, not much we can do when customer's install their own CPE that gets compromised. All we know is that is was a 'foreign APT group"





eric76
How long do you want to ignore this user?
AG
Our outer firewall has no ports open to the Internet. Any connection to it from the Internet results in the packet being dropped.

One thing that I've been doing lately is tying down my ssh. Our ssh is now strictly whitelisted. And the addresses on the whitelist are a collection of VPN endpoints for one specific VPN. If someone wants to connect at all with ssh, they have to be on that VPN or they see nothing.

We also require three separate ssh keys to connect.

And only one account on each server has a password and that account is for logging into the console.

In the three months since we switched to the whitelisting, we haven't seen any unauthorized connections. Prior to that, we had IPv6 only for the previous six months and saw very few unauthorized connections then.
merlin403
How long do you want to ignore this user?
I start here: https://inteltechniques.com/data/10DaySecurity.pdf
AgCMT
How long do you want to ignore this user?
AG
merlin403 said:

I start here: https://inteltechniques.com/data/10DaySecurity.pdf

This is a fantastic reference! Thanks for posting.
eric76
How long do you want to ignore this user?
AG
One thing that everyone should realize whether small business or home, it is doubtful that there are any commercial router/firewalls out there that haven't had significant issues.

You can help a lot by disabling all management access from the Internet. It isn't a cure, but it will likely be useful.
Refresh
Page 1 of 1
 
×
subscribe Verify your student status
See Subscription Benefits
Trial only available to users who have never subscribed or participated in a previous trial.