<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IoT &amp; Consumer goods - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/category/sections/cybersecurity-digital-trust/iot-consumer-goods-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/category/sections/cybersecurity-digital-trust/iot-consumer-goods-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 20 Jul 2026 16:53:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>IoT &amp; Consumer goods - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/category/sections/cybersecurity-digital-trust/iot-consumer-goods-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Industrial Cyber-Resilience: How to Get Started with NIS 2 Compliance</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/07/industrial-cyber-resilience-how-to-get-started-with-nis-2-compliance/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/07/industrial-cyber-resilience-how-to-get-started-with-nis-2-compliance/#respond</comments>
		
		<dc:creator><![CDATA[Victor Hu]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 13:10:33 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[Sections]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[nis 2]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30486</guid>

					<description><![CDATA[<p>This figure reveals a profound shift: backups, often considered the last resort, have now become prime targets for attackers. When faced with a major cyberattack, traditional continuity plans are no longer sufficient. Indeed, they fall short in industrial environments, particularly...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/07/industrial-cyber-resilience-how-to-get-started-with-nis-2-compliance/">Industrial Cyber-Resilience: How to Get Started with NIS 2 Compliance</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><img fetchpriority="high" decoding="async" class="alignnone  wp-image-30470 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig1-437x127.png" alt="" width="578" height="168" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig1-437x127.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig1-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig1-768x223.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig1.png 976w" sizes="(max-width: 578px) 100vw, 578px" /></p>
<p><strong>This figure reveals a profound shift: backups, often considered the last resort, have now become prime targets for attackers. When faced with a major cyberattack, traditional continuity plans are no longer sufficient.</strong> Indeed, they fall short in industrial environments, particularly given the nature of the stakes involved: physical safety, environmental impact, continuous production, and more.</p>
<p>This is why the <strong>most advanced organizations are now building dedicated OT cyber-resilience programs</strong>, designed to manage crises in the face of major disruptions or incidents. That aim to ensure the continuity of essential operations and restore compromised assets.</p>
<p>The NIS2 Directive — and particularly ANSSI&#8217;s RECYF framework — supports this effort by introducing clear cyber-resilience obligations for essential and important entities.</p>
<p>Where to start, what obstacles to anticipate, and how to build OT resilience that meets NIS2 requirements?</p>
<h1><strong>NIS 2 and Industrial Resilience: Requirements and Current State</strong></h1>
<h2><strong>What NIS 2 Concretely Requires</strong></h2>
<p><span style="color: #451dc7;"><em>The growing integration of IT into industrial processes — MES, ERP systems connected to production </em><em>lines; the gradual shift away from paper-based processes — has profoundly changed the operational reality of manufacturing plants. Dependencies are numerous, often poorly mapped, and an IT failure can bring OT to a halt even when the physical equipment remains fully functional. In this regard, strengthening the cyber resilience of industrial environments has become a priority .</em></span></p>
<p>The NIS 2 directive significantly broadens the scope of entities subject to cybersecurity obligations. Two objectives are crucial in terms of resilience:</p>
<p><img decoding="async" class=" wp-image-30466 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2-393x191.png" alt="" width="882" height="429" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2-393x191.png 393w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2-768x374.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2-1536x747.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig2.png 1891w" sizes="(max-width: 882px) 100vw, 882px" /></p>
<h2><strong>Industrial State of Play</strong></h2>
<p>While industrial organizations have gradually invested in securing their OT environments, maturity around continuity and recovery remains insufficient to meet NIS 2 requirements. Several gaps are observed systematically:</p>
<ul>
<li> <strong>Gaps in the knowledge of assets</strong> and their criticality
<ul>
<li>Asset mapping that is often not formalised or incomplete</li>
<li>BIAs are absent or only partially completed</li>
</ul>
</li>
<li><strong>Existing business BCPs are designed for physical or traditional IT scenarios, but not for OT cyber challenges</strong></li>
<li><strong>Continuity and recovery capabilities are not tested</strong>: organisations limit themselves to unit tests or isolated VM restorations, never covering a complete production line or end-to-end scenario. Several factors explain this situation:</li>
</ul>
<p><img decoding="async" class=" wp-image-30462 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig3-296x191.png" alt="" width="885" height="571" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig3-296x191.png 296w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig3-61x39.png 61w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig3-768x495.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig3.png 1366w" sizes="(max-width: 885px) 100vw, 885px" /></p>
<p>Without the necessary maturity on these topics, a cyber incident can result in weeks of downtime</p>
<h1><strong>Building OT Resilience for NIS 2: A Practical Roadmap</strong></h1>
<h2><strong><img loading="lazy" decoding="async" class=" wp-image-30458 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4-322x191.png" alt="" width="1000" height="593" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4-322x191.png 322w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4-768x455.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig4.png 1183w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></strong><strong style="font-size: revert; color: initial;">Foundations and Prerequisites</strong><strong style="font-size: revert; color: initial;">     </strong></h2>
<p>Before building a recovery, plan or testing anything, the groundwork must be laid. <strong>Including knowing what to protect, how to hold up during an incident, and what to back up.</strong></p>
<h2><strong>Which stakeholders to involve from the start?</strong></h2>
<p>A cyber-resilience program driven solely by Cyber or IT teams risks failing to reflect operational realities and address the true business stakes: without the involvement and buy-in of operators, the initiative will struggle to move forward. This requires an evangelization phase, concretely explaining what an incident costs their operations, and identifying the right stakeholders in each department from the outset.</p>
<h2><strong>Which business perimeters to prioritise?</strong></h2>
<p>The goal of cyber-resilience is not to produce an exhaustive inventory of the industrial asset base. <strong>It is to identify the assets that underpin critical business processes</strong>. The starting point is to establish a BCP at the global level, followed by a BIA at the site level, which will define the RTO and RPO for each critical process.</p>
<p>Asset collection relies on a hybrid approach:</p>
<ul>
<li><strong>Operational interviews</strong> with field teams</li>
<li><strong>Analysis of architecture documents and configurations</strong> to identify additional dependencies</li>
</ul>
<p><span style="color: #451dc7;"><em>Network probes may seem like an obvious choice, but they only detect assets that are actively generating traffic. Any equipment that is not communicating at a given moment will simply disappear from the mapping. In OT environments, a significant number of devices are configured once and then operate autonomously, which severely limits their network visibility. Furthermore, some systems are entirely standalone and emit no traffic at all — even though they may be critical to operations. Relying solely on probes therefore provides a partial and potentially misleading view of the environment, with a real risk of overlooking essential assets.</em></span></p>
<h2><strong>What data to backup and how?</strong></h2>
<p><strong>Asset mapping makes it possible to catalogue and prioritise the systems that need to be protected based on their criticality, as validated with business teams</strong>. For each asset, the minimum backup content and backup frequency are then defined:<img loading="lazy" decoding="async" class=" wp-image-30454 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig5-437x184.png" alt="" width="857" height="361" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig5-437x184.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig5-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig5-768x324.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig5.png 1409w" sizes="auto, (max-width: 857px) 100vw, 857px" /><span style="color: initial; font-size: revert;">Several <strong>principles then structure the backup security strategy:</strong></span></p>
<ul>
<li>Redundancy, encryption, and immutability of backups</li>
<li>Air-gapping for the most sensitive environments</li>
<li>Differentiated retention policies by asset type</li>
<li>Contractual clauses governing backup obligations for third parties</li>
</ul>
<p><em>Backup infrastructure</em><em> is not merely technical storage systems: they are themselves sensitive targets and must be treated as critical systems, with the appropriate level of protection.</em></p>
<h2><strong>How to ensure continuity during an incident?</strong></h2>
<p>The <strong>first step of the BCP is to identify the crisis scenarios that need to be addressed</strong>, as these determine which stakeholders to involve, which procedures to define, and which operating modes to adopt. This work is carried out jointly with the HSE, business, cybersecurity, and risk management teams.</p>
<p>For each critical process identified, the following must then be defined in collaboration with the production, maintenance, and quality teams:</p>
<h1><strong>Validation and Recovery</strong></h1>
<h2><strong>How to validate that recovery works?</strong></h2>
<p>An untested DRP is a theorical DRP.</p>
<p><strong>Tests can be conducted in the following ways to limit the impact on production:</strong></p>
<ul>
<li>On a dedicated global test infrastructure, shared across sites,</li>
<li>On a test line,</li>
<li>During maintenance windows,</li>
<li>Using digital twins.</li>
</ul>
<p>These tests should be validated at least once a year.</p>
<p>Progression is gradual:<img loading="lazy" decoding="async" class="alignnone  wp-image-30446 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7-437x179.png" alt="" width="896" height="367" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7-437x179.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7-768x314.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7-1536x628.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig7.png 1715w" sizes="auto, (max-width: 896px) 100vw, 896px" /></p>
<p><strong>Each test is documented</strong>: actual RTO and RPO measured, comparison against theoretical targets, gaps identified, and corrective actions planned.</p>
<p><span style="color: #451dc7;"><em>RTO/RPO objectives may not be realistic in the context of a major cyber crisis. They should therefore not act as a blocking factor for conducting tests or for validating cyber-resilience principles under NIS2.</em></span></p>
<h2><strong>How to rebuild after an incident?</strong></h2>
<p><strong>The DRP defines how to restart critical systems following a disaster</strong>. It covers several scenarios: hardware failure, ransomware, and OT network loss.</p>
<p>For each scenario, it is necessary to:</p>
<ul>
<li>Define the restart sequencing based on dependencies between systems</li>
<li>Document the escalation and decision-making chain</li>
<li>Clearly define third-party involvement: intervention conditions, coordination modalities, and prerequisite security requirements (ransomware eradication, controlled environment such as a &#8220;clean room&#8221;, gradual recovery with network segmentation)</li>
</ul>
<p><span style="color: #451dc7;"><em>Two recovery logics must be distinguished: loss of availability (switching to backup resources) and loss of integrity (complete reconstruction from backups). The procedures are not the same and must be addressed separately.</em></span></p>
<h1><strong>From Asset Resilience to Crisis Management</strong></h1>
<p><strong>What we have described here constitutes the minimum foundation for initiating a recovery approach in an OT environment</strong>. But NIS 2 requires going further as the entire information system is concerned, and the question is no longer purely technical; it calls for a structured program, managed over time, capable of demonstrating compliance and asset resilience.</p>
<p><strong>This means deploying this approach pragmatically</strong>, taking into account cyber risks, regulatory constraints, and available resources. It also means not approaching OT resilience as a one-off project: cyber-resilience must be embedded by design, with tracked workstreams, documented evidence, and business teams engaged over the long term.</p>
<p>Finally, the market today offers solutions dedicated to OT resilience. Actively monitoring this space can prove valuable in identifying the right tools.</p>
<p>Moreover, <strong>resilience does not stop at technical recovery, it also encompasses crisis management</strong>: <a href="https://www.riskinsight-wavestone.com/en/2023/02/enabling-a-paradigm-shift-in-cyber-crisis-management-preparedness/">Enabling a paradigm shift in cyber crisis management preparedness &#8211; RiskInsight</a></p>
<h1><strong>Glossary</strong></h1>
<p><img loading="lazy" decoding="async" class="wp-image-30442 alignnone" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig8-437x120.png" alt="" width="1029" height="283" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig8-437x120.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig8-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig8-768x211.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/07/NIS2_EN_fig8.png 1530w" sizes="auto, (max-width: 1029px) 100vw, 1029px" /></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/07/industrial-cyber-resilience-how-to-get-started-with-nis-2-compliance/">Industrial Cyber-Resilience: How to Get Started with NIS 2 Compliance</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/07/industrial-cyber-resilience-how-to-get-started-with-nis-2-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Plug &#038; Charge and ISO 15118: what are the new cyber risks for charging stations? </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/#respond</comments>
		
		<dc:creator><![CDATA[Madeline Salles]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 15:26:09 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[ChargingStations]]></category>
		<category><![CDATA[ConnectedVehicles]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ElectricVehicles]]></category>
		<category><![CDATA[ISO15118]]></category>
		<category><![CDATA[PlugAndCharge]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30152</guid>

					<description><![CDATA[<p> As highlighted in our previous article, Electric vehicle charging infrastructures: Energy performance and new cybersecurity challenges, charge point operators (CPOs) operate within a demanding business model, where profitability depends on their ability to drive recurring usage of their networks. In this context, user experience becomes a key...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/">Plug &amp; Charge and ISO 15118: what are the new cyber risks for charging stations? </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span><span style="font-size: revert; color: initial;" data-contrast="auto">As highlighted in our previous article, </span><a style="font-size: revert;" href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/"><i><span data-contrast="none">Electric vehicle charging infrastructures: Energy performance and new cybersecurity challenges</span></i></a><span style="font-size: revert; color: initial;" data-contrast="auto">, charge point operators (CPOs) operate within a demanding business model, where profitability depends on their ability to drive recurring usage of their networks. In this context, </span><b style="font-size: revert; color: initial;"><span data-contrast="auto">user experience becomes a key lever</span></b><span style="font-size: revert; color: initial;" data-contrast="auto">: the smoother the charging journey, the fewer failures and friction points it involves, ultimately helping build customer loyalty.</span><span style="font-size: revert; color: initial;" data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">Plug &amp; Charge</span></b><span data-contrast="auto"> is being promoted precisely to address this challenge. Enabled by the </span><b><span data-contrast="auto">ISO 15118 standard</span></b><span data-contrast="auto">, this mechanism allows the charging station to automatically authenticate the user and initiate charging without the need for a badge or mobile application. Originally designed to standardize communication between the vehicle, the charging station and the grid, ISO 15118 paves the way for a more seamless charging experience—often summed up by the promise: “plug in and it charges.”</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, this apparent simplification on the user side actually relies on a </span><b><span data-contrast="auto">significant increase in complexity across the underlying trust chain </span></b><span data-contrast="auto">and technical mechanisms: digital certificates, Public Key Infrastructure (PKI), ISO 15118 communications, new authentication flows, and dependencies on trusted third parties. In other words, behind a frictionless charging experience, Plug &amp; Charge introduces new points of failure and expands the attack surface that operators must now address as critical cybersecurity concerns.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">In this article, we take a closer look at</span><b><span data-contrast="auto"> three risks directly associated with the deployment of Plug &amp; Charge and ISO 15118</span></b><span data-contrast="auto">:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">availability loss</span></b><span data-contrast="auto"> resulting from a compromise of the </span><b><span data-contrast="auto">V2G (Vehicle-to-Grid) PKI;</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">availability loss</span></b><span data-contrast="auto"> caused by the exploitation of </span><b><span data-contrast="auto">vulnerabilities on the ISO 15118 interface</span></b><span data-contrast="auto">;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">the theft of charging station certificates and its implications in terms of </span><b><span data-contrast="auto">fraud</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h1><span data-contrast="none">Risk 1: availability loss resulting from a compromise of the V2G PKI</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">To understand this risk, it is first important to recall that Plug &amp; Charge relies on a digital trust chain that enables the vehicle and the charging station to automatically authenticate each other using certificates and then initiate charging without any manual action from the user.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As illustrated in Figure 1, a Plug &amp; Charge session follows a multi-step sequence:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol style="list-style-type: upper-roman;">
<li><span data-contrast="auto">Establishment of the ISO 15118 communication channel between the vehicle and the charging station, along with mutual authentication, </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">Verification of the mobility contract followed by authorization,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><span data-contrast="auto">Start of charging session.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ol>
<p><span data-contrast="auto">If any of these steps fails due to a breakdown in digital trust, the charging session cannot be initiated.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:300}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img loading="lazy" decoding="async" class="size-full wp-image-30114 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1.png" alt="" width="2012" height="1056" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1.png 2012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-364x191.png 364w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-768x403.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borne_EV_en1-1536x806.png 1536w" sizes="auto, (max-width: 2012px) 100vw, 2012px" /></span><i><span data-contrast="auto">Figure 1: Steps of a Plug &amp; Charge session</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This mechanism relies on a shared PKI across the ecosystem, known as the </span><b><span data-contrast="auto">V2G PKI</span></b><span data-contrast="auto">, whose role is to ensure interoperability between vehicles, charging stations, and operators. This architecture is built on root and intermediate certificate authorities that issue and validate the certificates used throughout the charging session (Figure 2).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img loading="lazy" decoding="async" class="size-full wp-image-30116 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2.png" alt="" width="1698" height="1100" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2.png 1698w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-295x191.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-768x498.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en2-1536x995.png 1536w" sizes="auto, (max-width: 1698px) 100vw, 1698px" /></span><i><span data-contrast="auto">Figure 2: V2G PKI architecture</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">In Europe, this ecosystem currently relies on a limited number of key trusted players—such as </span><b><span data-contrast="auto">Hubject</span></b><span data-contrast="auto">, </span><b><span data-contrast="auto">Gireve</span></b><span data-contrast="auto">, and </span><b><span data-contrast="auto">Irdeto</span></b><span data-contrast="auto">—which combine the role of root certification authority (V2G Root CA) with Plug &amp; Charge certificate management and interoperability services.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Within this architecture, the CPO holds a pivotal position: charging stations must be integrated into this trust chain and, depending on the chosen model, the operator may run certain PKI components in-house (</span><i><span data-contrast="auto">make</span></i><span data-contrast="auto">) or rely on a specialized provider (</span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto">). In both cases, the CPO becomes dependent on a trust infrastructure whose compromise, misconfiguration, or unavailability can have a </span><b><span data-contrast="auto">direct impact on service availability</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The risk, therefore, lies in a </span><b><span data-contrast="auto">loss of service availability</span></b><span data-contrast="auto"> caused by an incident affecting the V2G PKI. Several scenarios are plausible: compromise of a root or intermediate authority, expired certificates that were not renewed, corruption of a trust store, or unavailability of a component involved in the certificate lifecycle. In all these situations, the operational outcome is the same: the charging station or the vehicle can no longer establish a valid trust relationship, and the Plug &amp; Charge session fails before charging even starts.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">With Plug &amp; Charge, PKI no longer only secures communications, it becomes a </span><b><span data-contrast="auto">critical production component</span></b><span data-contrast="auto">. An incident affecting the trust infrastructure is therefore not just a security or compliance issue, but a potential source of partial or large-scale service disruption.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The choice between </span><i><span data-contrast="auto">make</span></i><span data-contrast="auto"> and </span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto"> does not eliminate this risk; it shifts where control lies. A </span><i><span data-contrast="auto">make</span></i><span data-contrast="auto"> strategy provides greater control to the CPO, but requires mature PKI governance, robust operational capabilities, and strict discipline over certificate lifecycle management. A </span><i><span data-contrast="auto">buy</span></i><span data-contrast="auto"> strategy accelerates deployment but increases dependence on a third party for what has become a critical function, implying stronger requirements in terms of contractual oversight, auditability, and monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">From a cybersecurity standpoint, the implication is clear: the </span><b><span data-contrast="auto">V2G PKI must be treated as a critical operational asset within the charging stations information system</span></b><span data-contrast="auto">. This entails explicit governance of trust roles, continuous monitoring of certificate lifecycles, regular resilience and continuity testing, and the definition of degraded operating modes to prevent a PKI incident from escalating into large-scale service disruption.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Risk 2: loss of charging infrastructure availability through the exploitation of vulnerabilities in ISO 15118 communication</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">This risk stems directly from the increasing complexity of the communication channel. Where charging historically relied on relatively simple interactions—primarily based on electrical signaling and a limited set of basic messages—ISO 15118 introduces a high-level dialogue built on a much richer protocol stack (Figure 3).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-30118 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png" alt="" width="1664" height="1016" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png 1664w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-313x191.png 313w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-768x469.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-1536x938.png 1536w" sizes="auto, (max-width: 1664px) 100vw, 1664px" /><br /><i><span data-contrast="auto">Figure 3: OSI model applied to ISO 15118</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
<p><span data-contrast="auto">This shift from a minimalist protocol to a full-fledged application layer—including device discovery, IPv6 address allocation, authentication, certificate management, and cryptographic operations—mechanically expands the attack surface. This is particularly true because the communication interface via the charging connector is inherently accessible, with no physical barriers. Any vulnerability in these exchanges (e.g., manipulation of application messages, injection into PLC traffic, improper certificate validation) </span><b><span data-contrast="auto">could disrupt the charging session—or, in a worst-case scenario, lead to a full compromise of the charging <a href="https://www.cve.org/CVERecord?id=CVE-2026-9038">station</a></span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Exploiting such vulnerabilities, however, </span><b><span data-contrast="auto">requires physical access to the charging point</span></b><span data-contrast="auto">: the attacker must be able to interact with the communication channel between the vehicle and the station. In practice, this involves specialized equipment to connect to the PLC network, such as a HomePlug Green PHY compatible interface and a physical adapter for the charging connector. While this constraint makes the exploit harder, it does not eliminate the risk. Several research efforts have demonstrated the feasibility of lab setups capable of observing, relaying, or disrupting ISO 15118 communications directly at the cable or <a href="https://www.sstic.org/media/SSTIC2019/SSTIC-actes/v2g_injector_playing_with_electric_cars_and_chargi/SSTIC2019-Article-v2g_injector_playing_with_electric_cars_and_charging_stations_via_powerline-dudek.pdf">connector level</a>.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-contrast="auto"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-30118 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png" alt="" width="1664" height="1016" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3.png 1664w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-313x191.png 313w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-768x469.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en3-1536x938.png 1536w" sizes="auto, (max-width: 1664px) 100vw, 1664px" /></span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"> </span><i><span data-contrast="auto">Figure 4: Equipment required to exploit a vulnerability on the ISO 15118 interface</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">To mitigate these risks, CPOs </span><b><span data-contrast="auto">must ensure the security level of their vendors’ products</span></b><span data-contrast="auto">, for example through audits, and assess their cybersecurity maturity, particularly regarding processes for maintaining security over time.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">They must also </span><b><span data-contrast="auto">implement vulnerability management processes</span></b><span data-contrast="auto"> across their asset base, including </span><b><span data-contrast="auto">maintaining inventories</span></b><span data-contrast="auto"> such as </span><b><span data-contrast="auto">SBOMs</span></b><span data-contrast="auto"> and </span><b><span data-contrast="auto">HBOMs</span></b><span data-contrast="auto"> (Software and Hardware Bills of Materials), as well as robust </span><b><span data-contrast="auto">patch management practices</span></b><span data-contrast="auto">. This enables operators to identify vulnerable assets and respond effectively when attackers attempt to exploit vulnerabilities on this new communication channel.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Risk 3: theft of charging station certificates</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><span data-contrast="auto">The theft of a charging station certificate is not only a cryptographic incident: in an ecosystem built on digital trust, it amounts to a compromise of machine identity. For a CPO, such an incident directly impacts the integrity of exchanges and may open the door to </span><b><span data-contrast="auto">charging fraud</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Two attack scenarios must be distinguished here:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Extraction of the private key</span></b><span data-contrast="auto"> associated with the certificate, following a software compromise or a physical attack on an insufficiently protected component,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="auto">Impersonation of a charging station</span></b><span data-contrast="auto"> when obtaining a certificate, for example through an insufficiently authenticated enrolment process between the station and the CPMS (Charge Point Management System).</span>  </li>
</ul>
<p><img loading="lazy" decoding="async" class="size-full wp-image-30122 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5.png" alt="" width="1991" height="1010" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5.png 1991w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-377x191.png 377w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-768x390.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en5-1536x779.png 1536w" sizes="auto, (max-width: 1991px) 100vw, 1991px" /></p>
<p style="text-align: center;"><i><span data-contrast="auto">Figure 5: attack paths to obtain a charging station V2G certificate</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">Once in possession of a valid certificate, an attacker can impersonate a legitimate charging station and abuse the ecosystem’s trust for malicious purposes. In a Plug &amp; Charge context, this could allow an attacker to make a vehicle believe it is establishing a normal session, and then relay the proof of possession of the victim’s contract certificate into another session—effectively charging a different vehicle at the victim’s expense. This </span><b><span data-contrast="auto">relay attack</span></b><span data-contrast="auto"> scenario has been demonstrated in <a href="https://arxiv.org/abs/2512.15966">academic literature</a> and illustrates how a single compromised charging station certificate can enable tangible, operational fraud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img loading="lazy" decoding="async" class="size-full wp-image-30124 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6.png" alt="" width="2078" height="975" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6.png 2078w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-768x360.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-1536x721.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en6-2048x961.png 2048w" sizes="auto, (max-width: 2078px) 100vw, 2078px" /></span><i><span data-contrast="auto">Figure 6: exploitation of fraud through relay of the EV’s proof of possession</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This type of attack is facilitated in implementations based on </span><b><span data-contrast="auto">ISO 15118-2</span></b><span data-contrast="auto">, where Plug &amp; Charge security relies on a more limited model, particularly in terms of end-to-end authentication and certificate handling. By contrast, </span><b><span data-contrast="auto">ISO 15118-20</span></b><span data-contrast="auto"> strengthens communication security—especially through the widespread use of TLS and a move toward mutual authentication—making such fraud more difficult to exploit, although not eliminating it if machine identities are not properly protected.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This risk is all the more realistic because </span><b><span data-contrast="auto">it does not require large compromise</span></b><span data-contrast="auto">: a single valid certificate can be sufficient. An attacker may therefore target the least protected charging station or attempt to fraudulently obtain a certificate through a weak enrolment process or inadequately secured backend. For the CPO, the challenge is not only to protect already deployed certificates, but to secure the entire lifecycle of charging station identities from issuance to storage and renewal.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2><span data-contrast="none">Key takeaways</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p><span data-contrast="auto">To mitigate the risk of private key compromise, CPOs must ensure that charging stations provide </span><b><span data-contrast="auto">secure storage capabilities for cryptographic material</span></b><span data-contrast="auto">, for example by integrating a TPM (Trusted Platform Module).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Preventing impersonation during certificate issuance requires a different approach. CPOs must guarantee the authenticity of certificate requests processed by the V2G PKI.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This relies on </span><b><span data-contrast="auto">authenticating the charging station when establishing the communication channel with the CPMS</span></b><span data-contrast="auto">. In practice, the protocol used on this channel, OCPP, supports mutual certificate-based authentication (mTLS) from version 2.0.1 onwards. The charging station therefore presents a certificate to authenticate itself to the CPMS. Once the session is established, certificate enrolment requests (including ISO 15118 certificates) are authenticated, significantly reducing the risk of impersonation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">However, this architecture introduces a prerequisite: </span><b><span data-contrast="auto">deploying a dedicated certificate used to authenticate the charging station on the CPO network</span></b><span data-contrast="auto">. This certificate is distinct from the ISO 15118 certificate used for Plug &amp; Charge, as it serves a different scope and purpose.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">It is therefore necessary to implement </span><b><span data-contrast="auto">a dedicated PKI</span></b><span data-contrast="auto">, operated by the CPO, which can be referred to as a “Product PKI.” This PKI issues the certificates used to secure OCPP communications. The certificate management challenges described earlier also apply to this PKI. CPOs must therefore establish the organizational and technical capabilities required to operate such an infrastructure, including certificate lifecycle management, incident handling, and upskilling of teams.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">We thus arrive at a target architecture in which each charging station embeds multiple certificates issued by distinct PKIs, each serving a specific role in authentication across critical communication channels involved in the charging session (Figure 7).</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0}"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-30126 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7.png" alt="" width="1982" height="738" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7.png 1982w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-437x163.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-768x286.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/borneEV_en7-1536x572.png 1536w" sizes="auto, (max-width: 1982px) 100vw, 1982px" /> </span><i><span data-contrast="none">Figure 7: target architecture for Plug &amp; Charge deployment</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
<h2><span data-contrast="none">Risk summary</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:851}"> </span></h2>
<p><span data-contrast="auto">The introduction of Plug &amp; Charge and the ISO 15118 standard is progressively transforming charging infrastructures into a true digital trust chain, where service availability now depends as much on cybersecurity as on the electrical operation of the stations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The scenarios analyzed show that </span><b><span data-contrast="auto">the main risks no longer relate solely</span></b><span data-contrast="auto"> </span><b><span data-contrast="auto">to technical compromise of isolated components, but have broader impacts</span></b><span data-contrast="auto"> on:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><span data-contrast="auto">Service continuity,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">Charging fraud,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">User trust,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">And, ultimately, the operator’s reputation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
</ul>
<p><span data-contrast="auto">The table below summarizes the identified risks using an approach inspired by EBIOS Risk Manager, based on an assessment of:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><span data-contrast="auto">The likelihood of each scenario (scale from 1 to 4),</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">Its severity for the operator (scale from 1 to 4), with the highest impact being a nationwide loss of trust in the charging infrastructure, for instance, in a scenario where a significant portion of charging stations would no longer allow charging,</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
<li><span data-contrast="auto">And the resulting overall risk level.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0}"> </span></li>
</ul>
<table style="width: 100%;" data-tablestyle="MsoNormalTable" data-tablelook="1536" aria-rowcount="4">
<tbody>
<tr aria-rowindex="1">
<td style="width: 6.90477%;" data-celllook="69905">
<p style="text-align: center;"><b><span data-contrast="none">Ref.</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><b><span data-contrast="none">Risk scenarios</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
</td>
<td style="width: 14.5238%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Likelihood</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 12.381%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Severity</span></b><b><span data-contrast="none">​</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 13.0952%; text-align: center;" data-celllook="69905">
<p><b><span data-contrast="none">Risk</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
</tr>
<tr aria-rowindex="2">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R1</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact caused by loss of charging station availability following a compromise of the V2G PKI</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2​ </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>4 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Medium </p>
</td>
</tr>
<tr aria-rowindex="3">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R2</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact caused by loss of charging station availability following large-scale exploitation of a vulnerability in ISO 15118 communication</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>3 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Medium </p>
</td>
</tr>
<tr aria-rowindex="4">
<td style="text-align: center; width: 6.90477%;" data-celllook="69905">
<p><b><span data-contrast="auto">R3</span></b><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:0}"> </span></p>
</td>
<td style="width: 51.6667%;" data-celllook="69905">
<p><span data-contrast="auto">Reputational/financial impact related to fraud resulting from certificate theft</span></p>
</td>
<td style="text-align: center; width: 14.5238%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 12.381%;" data-celllook="69905">
<p>2 </p>
</td>
<td style="text-align: center; width: 13.0952%;" data-celllook="69905">
<p>Low</p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: center;"><i><span data-contrast="auto">Table 1: Summary of risks related to Plug &amp; Charge on charging infrastructure</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">This analysis, however, should be nuanced: </span><b><span data-contrast="auto">the scenarios presented deliberately take a cautious, even pessimistic, view of likelihood</span></b><span data-contrast="auto">. In practice, such attacks remain difficult to carry out. They often require advanced technical skills, specific physical or logical access, a deep understanding of ISO 15118, and the capability to exploit or manipulate complex trust mechanisms.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As such, these </span><b><span data-contrast="auto">risks should be seen as plausible scenarios to anticipate</span></b><span data-contrast="auto">, rather than threats that are currently trivial or widely observed in real-world operations. Their “medium” to “low” risk level reflects this balance: a still-limited probability, but potentially significant impacts if such attacks were to scale.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Conclusion</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h1>
<p><b><span data-contrast="auto">Plug &amp; Charge simplifies the charging experience but introduces a strong dependency on a digital trust chain built on ISO 15118, the V2G PKI, and charging station certificates. This dependency creates new risks for charging infrastructures, potentially leading to service disruptions and, ultimately, a loss of trust from users toward the CPO.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">While these attack scenarios remain difficult to execute, their potential impact justifies addressing them early starting from the design phase. For CPOs, the challenge is therefore no longer limited to securing charging stations but extends to securing the entire identity and trust chain that underpins the charging process.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/">Plug &amp; Charge and ISO 15118: what are the new cyber risks for charging stations? </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/06/plug-charge-and-iso-15118-what-are-the-new-cyber-risks-for-charging-stations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/#respond</comments>
		
		<dc:creator><![CDATA[Madeline Salles]]></dc:creator>
		<pubDate>Wed, 29 Apr 2026 15:56:17 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29885</guid>

					<description><![CDATA[<p>Electric mobility is experiencing rapid growth in France and across Europe: in January 2026, registrations of fully electric vehicles in France increased by more than 50% compared with January 2025, bringing their market share to nearly one third of total vehicle sales. This trajectory confirms a structural transformation of...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/">Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><b><span data-contrast="auto">Electric mobility is experiencing rapid growth in France and across Europe:</span></b><span data-contrast="auto"> in January 2026, registrations of fully electric vehicles in France increased by more than 50% compared with January 2025, bringing their market share to nearly one third of total vehicle sales. This trajectory confirms a structural transformation of the automotive sector, which appears to be entering a phase of massive electrification, particularly for light-duty vehicles. This momentum is fully aligned with the orientations set out in France’s Multiannual Energy Program (PPE), which translates national ambitions for the energy transition into operational targets. As such, the growth of electric vehicles can no longer</span><b><span data-contrast="auto"> </span></b><span data-contrast="auto">be considered short-term, but rather as a trajectory set to strengthen further.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="auto">This trajectory, however, relies on the availability of a dense, reliable, and properly dimensioned charging network across the entire territory.</span></b><span data-contrast="auto"> Whether for public charging (motorways, public roads, shopping centers) or private charging (homes, businesses), this infrastructure forms the backbone of the electric mobility ecosystem. At the heart of this ecosystem, Charging Point Operators (CPOs) play a structuring role, being responsible for the installation, operation, and maintenance of charging stations.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Cyber risk is now emerging as a major threat to charging infrastructures, in a context where electrical networks are increasingly targeted by cybercriminal groups and state-sponsored actors</span><span data-contrast="auto">1</span><span data-contrast="auto">2</span><span data-contrast="auto">.  For CPOs, this reality is a game changer: mastering cyber risk becomes a prerequisite for service reliability and ecosystem protection. As charging networks expand and grow more complex, </span><b><span data-contrast="auto">cybersecurity challenges become central: data protection, service continuity, securing financial flows, and managing third</span></b>‑<b><span data-contrast="auto">party risks.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This article is part of a series of three papers exploring three structuring challenges faced by electric mobility stakeholders, with the aim of analyzing their implications from a cybersecurity perspective.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Rethinking charging infrastructure: balancing operational requirements and emerging cyber constraints</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">In the context of strong growth combined with the gradual structuring of the market, </span><b><span data-contrast="auto">CPOs are facing a demanding economic equation</span></b><span data-contrast="auto">. The deployment of charging infrastructures requires significant upfront investments – land acquisition, grid connection, purchase and installation of charging points, supervision, and maintenance – while utilization rates remain heterogeneous across regions and site typologies. Added to this are the volatility of electricity prices, increasing competitive pressure, and the rapid evolution of technological standards, which require regular upgrades.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">As public subsidies tend to be streamlined and investors increasingly expect clearer profitability trajectories, optimizing the economic performance of assets becomes imperative. </span><b><span data-contrast="auto">Maximizing availability rates, fine</span></b>‑<b><span data-contrast="auto">tuning operating costs, improving utilization levels, and diversifying revenue streams are no longer secondary levers, but essential conditions for the long</span></b>‑<b><span data-contrast="auto">term sustainability of CPOs’ business models.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Charging infrastructures, as designed today, illustrated in Figure</span><span data-contrast="auto"> </span><span data-contrast="auto">1, generally rely on static power control managed by a central supervision system, the Charging Point Management System (CPMS). This operating model does not allow, or significantly limits, the CPO’s ability to adapt power distribution in real time to usage patterns and site-specific constraints.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-29868 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1.png" alt="" width="679" height="262" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1.png 679w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1-437x169.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN1-71x27.png 71w" sizes="auto, (max-width: 679px) 100vw, 679px" /></span><em> Figure 1: Architecture of a conventional charging infrastructure </em></p>
<p><span data-contrast="auto">Therefore, several optimization levers can be implemented.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">First, it is possible to enhance the site’s energy flexibility, particularly to support fast charging without having to oversize the grid connection. To achieve this, the deployment of a </span><b><span data-contrast="auto">Battery Energy Storage System (BESS)</span></b><span data-contrast="auto"> proves to be an effective solution: this stationary battery storage acts as a buffer, capable of storing energy when it is available and releasing it during peak demand, thereby improving the site’s stability and resilience.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The next step consists in integrating local, low</span>‑<span data-contrast="auto">carbon energy production directly at charging sites, making it available for immediate use or storage through the addition of </span><b><span data-contrast="auto">photovoltaic systems</span></b><span data-contrast="auto">. Solar panels, installed on rooftops or canopies, provide this renewable generation layer. Their effectiveness, however, relies on their integration with appropriate control and storage systems, ensuring the environmental coherence of electric mobility.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Finally, to enable the proper integration of these energy production and storage assets at charging sites, a global control system has emerged: the </span><b><span data-contrast="auto">Energy Management System (EMS)</span></b><span data-contrast="auto">. This system supervises and adjusts energy flows on site in real time, aligning them with demand, local constraints, and grid connection agreements. It controls power distribution, anticipates variable charging demand, and maximizes the use of local energy production, thereby transforming a conventional electrical installation into a dynamic and intelligent system.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Thanks to intelligent energy management via an EMS, battery storage, and the integration of solar generation, this architecture (illustrated in Figure</span></b><b><span data-contrast="auto"> </span></b><b><span data-contrast="auto">2) enables performance optimization while keeping costs under control and thus represents a key step towards the next phase of the energy transition.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-29866 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2.png" alt="" width="903" height="583" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2.png 903w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-296x191.png 296w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/04/borne_ev_EN2-768x496.png 768w" sizes="auto, (max-width: 903px) 100vw, 903px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure </span></i><i><span data-contrast="none">2</span></i><i><span data-contrast="none">: Architecture of a next-generation charging infrastructure</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559739&quot;:360,&quot;335559740&quot;:240}"> </span></p>
<p><span data-contrast="auto">In the remainder of this article, we will focus on </span><b><span data-contrast="auto">three new sources of cybersecurity risk</span></b><span data-contrast="auto"> introduced by the integration of Energy Management Systems (EMS) into CPOs’ charging infrastructures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">The EMS: an optimization lever that has become a critical risk point</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">EMS have become a key component of charging infrastructures, enabling CPOs to finely optimize power management and charging strategies. This central role makes EMS a </span><b><span data-contrast="auto">critical point in terms of cybersecurity </span></b><span data-contrast="auto">&#8211; their compromise can result in major operational impacts for a CPO:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Unavailability </span></b><span data-contrast="auto">of a part of the charging stations.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Degradation </span></b><span data-contrast="auto">of energy optimization, resulting in direct financial impacts.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Load imbalances</span></b><span data-contrast="auto"> that may lead to service limitations or outages at site level.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559738&quot;:240,&quot;335559739&quot;:0,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<p><span data-contrast="auto">Beyond these incident scenarios, the introduction of EMS also fundamentally reshapes the risk landscape to which charging infrastructures are exposed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Increased reliance on third</span>‑<span data-contrast="none">party infrastructures</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The deployment of EMS solutions is most often based on </span><b><span data-contrast="auto">turnkey offerings</span></b><span data-contrast="auto">, combined with </span><b><span data-contrast="auto">vendor</span></b>‑<b><span data-contrast="auto">operated management platforms hosted in cloud environments</span></b><span data-contrast="auto">. These platforms enable CPOs to centrally manage their entire EMS fleet and support a range of use cases, including optimization of available power, performance monitoring, and remote control of charging strategies.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><b><span data-contrast="auto">This architecture, however, introduces a direct dependency on third</span></b>‑<b><span data-contrast="auto">party infrastructures that lie outside the CPO’s perimeter of control. As a result, it expands the attack surface and increases CPOs’ exposure to supply</span></b>‑<b><span data-contrast="auto">chain</span></b>‑<b><span data-contrast="auto">related risks.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">This issue is further compounded by the fact that these vendors are often small, highly specialized players whose level of cybersecurity maturity can be heterogeneous. A compromise of these platforms may therefore lead to widespread impacts, potentially resulting in the unavailability of a significant share of the EMS fleet operated by a CPO and, by extension, a risk of charging station outages.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">In addition, the compromise of EMS cloud platforms may also lead to breaches of data confidentiality, as it could enable an attacker to collect sensitive operational information, which could notably be exploited for espionage purposes, including:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Detailed mapping of charging sites and deployed energy assets.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Energy management strategies, revealing the optimization logics implemented by the CPO.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Consumption and power data across the CPO’s entire portfolio of sites.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559740&quot;:278,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Local communications relying on weakly secured protocols</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><b><span data-contrast="auto">These new architectures also extend the attack surface at the local network level, particularly through communications with energy-related equipment, which still largely rely on weakly secured industrial protocols.</span></b><span data-contrast="auto"> </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Unlike exchanges between supervision systems (CPMS) and charging stations, which benefit from the standardization provided by OCPP, communications between the EMS and other components (BESS, charging points, etc.) still predominantly rely on Modbus.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Originally designed for closed industrial environments, this protocol does not natively implement security mechanisms such as authentication or encryption. In practice, each EMS vendor deploys its own protective measures, resulting in heterogeneous security levels. For CPOs, this diversity complicates the securing of the fleet and may introduce new exploitable weak points within the local network.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Levers to secure next</span>‑<span data-contrast="none">generation charging infrastructure</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">Securing next</span>‑<span data-contrast="auto">generation charging infrastructures relies on a structured approach that makes it possible to reconcile operational performance with effective cybersecurity risk management.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p aria-level="2"><span data-contrast="none">Ensuring the resilience of charging architecture</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></p>
<p><span data-contrast="auto">The evolution of charging infrastructures introduces a single point of failure for CPOs: the EMS. To address this risk, it is necessary to design resilient architectures capable of maintaining continuity even in the event of an EMS failure. This can notably be achieved through:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">The implementation </span><b><span data-contrast="auto">of monitoring and alerting mechanisms</span></b><span data-contrast="auto">, enabling rapid detection of EMS failures and activation of fallback mechanisms.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">The deployment of </span><b><span data-contrast="auto">degraded operating modes</span></b><span data-contrast="auto">, allowing charging stations to continue operating even in the event of EMS unavailability.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559739&quot;:120,&quot;335559740&quot;:300}"> </span></li>
<li><span data-contrast="auto">The definition of business continuity and disaster recovery strategies that explicitly include EMS failure scenarios.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559739&quot;:120,&quot;335559740&quot;:300}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Securing dependencies on unmanaged third</span><span data-contrast="none">&#8211;</span><span data-contrast="none">party infrastructures</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">The evolution of charging infrastructure architectures requires CPOs to address both supply</span>‑<span data-contrast="auto">chain</span>‑<span data-contrast="auto">related risks and risks inherent to the interconnection between the CPMS and EMS vendors’ cloud infrastructures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">To reduce supply</span>‑<span data-contrast="auto">chain risks, CPOs must implement robust vendor qualification processes, including in particular:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">Assessment of the vendor’s </span><b><span data-contrast="auto">cybersecurity maturity level.</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Evaluation of product security, notably through </span><b><span data-contrast="auto">penetration testing</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Contractual governance of supplier relationships, including, where appropriate, the implementation of </span><b><span data-contrast="auto">Security Assurance Plans (SAPs)</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<p><span data-contrast="auto">Beyond supply</span>‑<span data-contrast="auto">chain risk management, CPOs must also account for the risks introduced by the interconnection of their infrastructure with EMS vendors’ environments (EMS cloud). Securing these interconnections requires a strong control of data flows between the CPO infrastructure and these external environments. This can be achieved through three main levers:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><span data-contrast="auto">Implementing </span><b><span data-contrast="auto">traffic filtering and control mechanisms</span></b><span data-contrast="auto"> between the local charging infrastructure network and external networks, to restrict communications strictly to legitimate third</span>‑<span data-contrast="auto">party infrastructures.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Formalizing </span><b><span data-contrast="auto">secure architectural standards</span></b><span data-contrast="auto"> and ensuring their effective implementation during EMS deployment in the field, guaranteeing a consistent application of cybersecurity best practices.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
<li><span data-contrast="auto">Implementing </span><b><span data-contrast="auto">isolation mechanisms</span></b><span data-contrast="auto"> to contain potential EMS cloud failures and prevent their propagation across the entire charging infrastructure fleet.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:240,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Securing communications relying on industrial protocols</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">Communications between EMS and energy</span>‑<span data-contrast="auto">related equipment, particularly BESS, still largely rely on industrial protocols such as Modbus, which do not provide native security mechanisms. In this context, securing these exchanges cannot rely on the protocols themselves, but must instead be addressed at the infrastructure architecture level.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This notably involves:</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:276}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Implementing strict network segmentation within the local network</span></b><span data-contrast="auto">, isolating EMS, BESS, and other components to limit exposure surfaces.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Applying fine</span></b>‑<b><span data-contrast="auto">grained control over communications</span></b><span data-contrast="auto"> by locally restricting data flows to strictly necessary exchanges (filtering, whitelisting, limitation of authorized commands).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
<li><b><span data-contrast="auto">Deploying communication monitoring mechanisms</span></b><span data-contrast="auto"> to detect abnormal or unauthorized behavior.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:714,&quot;335559739&quot;:120,&quot;335559740&quot;:276,&quot;335559991&quot;:357}"> </span></li>
</ul>
<h2 aria-level="2"><span data-contrast="none">Establishing a structured cybersecurity governance</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:40,&quot;335559739&quot;:0}"> </span></h2>
<p><span data-contrast="auto">To address the diversity of components and infrastructures operated across their charging networks, it is essential for CPOs to structure their environment around clear governance, including in particular:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Clarification of</span></b><span data-contrast="auto"> </span><b><span data-contrast="auto">cyber roles and responsibilities</span></b><span data-contrast="auto"> across the entire value chain (CPOs, suppliers, service providers, etc.).</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:0,&quot;335559740&quot;:240}"> </span></li>
<li><span data-contrast="auto">Definition of security standards applicable to all projects and suppliers, ensuring overall architectural consistency</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:240,&quot;335559740&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">By combining rigorous supplier risk management, a solid governance framework, and strict control of data flows, CPOs can fully leverage the operational gains offered by EMS while securing their infrastructure in a sustainable manner.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559739&quot;:240}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">Optimizing without compromising: the challenge of charging infrastructure</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:0}"> </span></h1>
<p><span data-contrast="auto">To conclude, the rise of Energy Management Systems (EMS) is profoundly transforming charging infrastructures, providing essential optimization levers while also introducing new cybersecurity risks. For CPOs, the challenge is no longer limited to deploying these solutions but extends to securing them within a comprehensive approach that encompasses supplier risk management, the definition of secure architectures, and the establishment of structured cybersecurity governance. In this context, </span><b><span data-contrast="auto">cybersecurity is now emerging as a prerequisite for the sustainable performance of charging infrastructures.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/">Electric vehicle charging infrastructure: energy performance and new cybersecurity challenges</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/04/electric-mobility-charging-infrastructure-evolution-between-energy-optimization-and-emerging-cybersecurity-challenges/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Industrial cybersecurity: the ANSSI “Detailed Measures” guide overhaul </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/03/industrial-cybersecurity-the-anssi-detailed-measures-guide-overhaul/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/03/industrial-cybersecurity-the-anssi-detailed-measures-guide-overhaul/#respond</comments>
		
		<dc:creator><![CDATA[Loïc Lebain]]></dc:creator>
		<pubDate>Wed, 18 Mar 2026 07:52:59 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29433</guid>

					<description><![CDATA[<p>Classifying an industrial system is a first step; making that classification operational in the field is another matter altogether. This is precisely where version 2.0 of the guide “Industrial Systems Cybersecurity – Detailed Measures”, published on November 27, 2025, positions itself: translating cybersecurity classes into...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/industrial-cybersecurity-the-anssi-detailed-measures-guide-overhaul/">Industrial cybersecurity: the ANSSI “Detailed Measures” guide overhaul </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="auto">Classifying an industrial system is a first step; making that classification operational in the field is another matter altogether.</span> <br /><span data-contrast="auto">This is precisely where version 2.0 of the guide </span><i><span data-contrast="auto">“Industrial Systems Cybersecurity – Detailed Measures”</span></i><span data-contrast="auto">, published on November 27, 2025, positions itself: translating cybersecurity classes into concrete measures, at a time when OT environments must contend with a more acute threat landscape, increasingly interconnected architectures, and more visible compliance requirements.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:300}"> </span></p>
<p><span data-contrast="auto">This guide directly follows the publication of the second version of ANSSI’s </span><i><span data-contrast="auto">Industrial Systems Classification Method</span></i><span data-contrast="auto"> in March 2025, which we had already analyzed in a previous </span><a href="https://www.riskinsight-wavestone.com/en/2025/06/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification/"><span data-contrast="none">article</span></a><span data-contrast="auto">.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:300}"> </span></p>
<h1>An update built on continuity: the same structure, the same underlying logic<i></i></h1>
<p style="text-align: center;"><i><span data-contrast="auto"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-29423 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en1.png" alt="" width="961" height="420" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en1.png 961w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en1-437x191.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en1-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en1-768x336.png 768w" sizes="auto, (max-width: 961px) 100vw, 961px" /></span></i><em>Key differences between the first and second versions of the detailed measures guide </em></p>
<p><span data-contrast="auto">In terms of structure, the 2025 guide remains very close to the 2014 version. It opens with a reminder of the constraints and weaknesses specific to industrial environments, followed by a clear separation between organizational and technical measures. The themes themselves will come as no surprise: governance, access control, network segmentation, remote access, backups, supervision, vulnerability management, cybersecurity integration throughout the system lifecycle, and incident preparedness. Continuity is clearly intentional.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">This stability has an advantage: organizations already aligned with the 2014 guide do not have to start from scratch. At the same time, it also highlights the fact that most of the “core topics” were already well identified more than a decade ago. The real question is therefore less “what is new?” than “what has become more actionable — and at what cost?”.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">On this point, the guide is explicit about its scope. It proposes a </span><b><span data-contrast="auto">minimum baseline</span></b><span data-contrast="auto"> intended, among other things, to support security accreditation processes. However, it does not claim to replace IEC 62443, nor does it position itself as a certification framework. It simply reuses some of its principles and requirements, while clearly stating that the measures alone are not sufficient for the most critical systems.</span><span data-ccp-props="{}"> </span></p>
<h1>What has changed in concrete terms </h1>
<p><span data-contrast="auto">The most visible change is not the introduction of new topics, but a new way of expressing requirements.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">In 2014, the guide relied on a structuring distinction between </span><b><span data-contrast="auto">recommendations (R)</span></b><span data-contrast="auto"> and </span><b><span data-contrast="auto">directives (D)</span></b><span data-contrast="auto">, with a hardening mechanism depending on the cybersecurity class. In 2025, this grammar disappears. The guide now introduces a class based reading (C1 to C4) and several variants:</span> <br /><span data-contrast="auto">– </span><i><span data-contrast="auto">state of the art </span></i><em>recommendations</em><span data-contrast="auto">,</span> <br /><span data-contrast="auto">– </span><i><span data-contrast="auto">lower level alternatives</span></i><span data-contrast="auto">, indicated by a “–”,</span> <br /><span data-contrast="auto">– and </span><i><span data-contrast="auto">reinforced complementary recommendations</span></i><span data-contrast="auto">, indicated by a “+”.</span><span data-ccp-props="{}"> </span></p>
<p style="text-align: center;"><span data-ccp-props="{}"><img loading="lazy" decoding="async" class="size-full wp-image-29419 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en2.png" alt="" width="1392" height="391" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en2.png 1392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en2-437x123.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en2-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en2-768x216.png 768w" sizes="auto, (max-width: 1392px) 100vw, 1392px" /></span><i><span data-contrast="auto">Typical structure of a recommendation</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">A second major evolution is the explicit introduction of a fourth cybersecurity class and the strengthened alignment with IEC 62443, in line with the updated classification method. For each recommendation, a correspondence with an IEC 62443 requirement is indicated when it exists and referenced in a dedicated appendix.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">According to Appendix B, a large proportion of the 214 recommendations have a direct equivalent in the previous version. This confirms that the overhaul is primarily based on reorganization and reformulation rather than a fundamental shift in doctrine. After analyzing the 35 measures identified as having no direct equivalence, it appears that they are not necessarily new. They typically reflect:</span><span data-ccp-props="{}"> </span></p>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-29435 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1.png" alt="" width="1746" height="627" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1.png 1746w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1-437x157.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1-71x25.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1-768x276.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en5-1-1536x552.png 1536w" sizes="auto, (max-width: 1746px) 100vw, 1746px" /><i><span data-contrast="auto">Categories of reasons for no direct equivalence, with illustrated examples</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-ccp-props="{}"> <img loading="lazy" decoding="async" class="size-full wp-image-29415 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3.png" alt="" width="1657" height="814" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3.png 1657w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3-389x191.png 389w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3-768x377.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en3-1536x755.png 1536w" sizes="auto, (max-width: 1657px) 100vw, 1657px" /></span></p>
<p style="text-align: center;"><i><span data-contrast="auto">Summary of recommendations with no direct equivalents in Annex B</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h1>A more architecture-driven doctrine on interconnections and remote access </h1>
<p><span data-contrast="auto">Where the 2025 version truly changes the dynamic is in certain topics that are handled in a more structured way. In the first version, the doctrine on interconnections and remote access was already relatively prescriptive: it emphasized that remote management greatly increases the attack surface, set out operational rules, and even went as far as banning remote maintenance in class 3, using a logic of one-way (unidirectional) data flows.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">The modernization brought by the 2025 version makes the whole set more coherent and better structured: it moves from a reasoning mainly centered on components and means (firewalls, VLANs, data diodes, VPNs) to an interpretation in terms of security functions that must be combined and positioned according to the classes and the flow directions in Table 3. The rows of the latter correspond to the issuing class (“from”) and the columns to the receiving class (“to”); the icons indicate the security functions to implement in order to authorize the flow in that direction. For example, from class C1 to IT, only a system that can verify whether the data comes from an authorized source—Aut(IT)—is required.</span><span data-ccp-props="{}"> </span></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-29411 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en4.png" alt="" width="1018" height="789" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en4.png 1018w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en4-246x191.png 246w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en4-50x39.png 50w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/anssi2_en4-768x595.png 768w" sizes="auto, (max-width: 1018px) 100vw, 1018px" /></p>
<p style="text-align: center;"><i><span data-contrast="auto">Summary of Table 3 – Section 4.2.1: all listed measures are associated with a data transfer </span></i><b><i><span data-contrast="auto">unidirectionality</span></i></b><i><span data-contrast="auto"> function</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="auto">It should be noted, however, that the definition of </span><i><span data-contrast="auto">Inno (OT)</span></i><span data-contrast="auto"> is not explicitly provided in the document.</span><span data-ccp-props="{}"> </span></p>
<h1>From framework to on-the-ground implementation </h1>
<p><span data-contrast="auto">The 2025 version of the Detailed Measures logically brings to a close the overhaul initiated with the publication of the second version of the classification method, and it strengthens compatibility with IEC 62443. In a context where the threat to industrial environments is now highly visible, this document comes at just the right time: it’s an opportunity to adjust your action plan—or even to launch a full 2030 roadmap. A guide that isn’t put into practice has never stopped an attacker!</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Among the priority workstreams that are regularly identified, we often see:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li><span data-contrast="auto">Revisit the IT mapping and the business’s dependencies on IT</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Adapt the technical architecture by trading “new authorizations” for stronger authentication and better content control</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Harden and centralize remote access, especially given the many suppliers present in industrial environments</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Strengthen industrial environments or connect them to your SOC</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<p><span data-ccp-props="{}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/03/industrial-cybersecurity-the-anssi-detailed-measures-guide-overhaul/">Industrial cybersecurity: the ANSSI “Detailed Measures” guide overhaul </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/03/industrial-cybersecurity-the-anssi-detailed-measures-guide-overhaul/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Purple Teaming for OT:  How to switch from a compliance to a performance mindset?</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/12/purple-teaming-for-ot-how-to-switch-from-a-compliance-to-a-performance-mindset/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/12/purple-teaming-for-ot-how-to-switch-from-a-compliance-to-a-performance-mindset/#respond</comments>
		
		<dc:creator><![CDATA[Arnaud Soullié]]></dc:creator>
		<pubDate>Wed, 10 Dec 2025 15:40:14 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=28481</guid>

					<description><![CDATA[<p>In our previous articles of this OT cybersecurity monitoring series (Cybersecurity monitoring for OT / Cybersecurity tooling strategy), we explained the current state of OT detection capabilities and discussed the right tooling strategy.  This third article focuses on a key question: how do you measure the efficiency of...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/12/purple-teaming-for-ot-how-to-switch-from-a-compliance-to-a-performance-mindset/">Purple Teaming for OT:  How to switch from a compliance to a performance mindset?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><span data-contrast="auto">In our previous articles of this OT cybersecurity monitoring series (</span><a href="https://www.riskinsight-wavestone.com/en/2025/09/cybersecurity-monitoring-for-ot-current-situation-perspectives/"><span data-contrast="none">Cybersecurity monitoring for OT</span></a><span data-contrast="auto"> / </span><a href="https://www.riskinsight-wavestone.com/en/2025/10/cybersecurity-tooling-strategy-for-an-effective-industrial-detection/"><span data-contrast="none">Cybersecurity tooling strategy</span></a><span data-contrast="auto">), we explained the current state of OT detection capabilities and discussed the right tooling strategy.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">This third article focuses on a key question: </span><b><span data-contrast="auto">how do you measure the efficiency of your OT detection?</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h1 aria-level="1"><span data-contrast="none">From compliance to efficiency: a KPI paradigm shift</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:360,&quot;335559739&quot;:80}"> </span></h1>
<p><span data-contrast="auto">KPI stands for </span><i><span data-contrast="auto">Key Performance Indicator. </span></i><span data-contrast="auto">However, we tend to create KPIs to monitor progress against our plans, not real performance. While useful, monitoring only deployment or coverage (number of sites connected to the SOC, EDR deployment on OT machines, number of probes registered to the management console) </span><b><span data-contrast="auto">tells you very little about the actual ability of your SOC to detect a real attacker.</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">So, how confident are you in your detection tools, use cases, and processes? The only way to be sure is simple: </span><b><span data-contrast="auto">test them. </span></b><span data-contrast="auto">And the best way to test them is through </span><b><span data-contrast="auto">Purple Team exercises</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h1 aria-level="1">What is Purple Teaming in OT? </h1>
<p><span data-contrast="auto">A Purple Team exercise is a </span><b><span data-contrast="auto">collaborative mission</span></b><span data-contrast="auto"> between the Red Team (attackers) and the Blue Team (defenders). Unlike a traditional Red Team assessment, where the defenders are kept in the dark and evaluated afterward, </span><b><span data-contrast="auto">a Purple Team exercise is an iterative, joint effort</span></b><span data-contrast="auto">.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">This collaborative approach allows both teams to:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Share assumptions about the OT environment</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Validate detection logic in real time</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Understand blind spots</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Improve playbooks and detection pipelines</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Align everyone around a realistic threat model</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<h1 aria-level="2">Performing a Purple Team Exercise </h1>
<p><span data-contrast="auto">A Purple Team operation can be summarized in </span><b><span data-contrast="auto">three main phases</span></b><span data-contrast="auto">:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2>1. Preparation</h2>
<p><span data-contrast="auto">The preparation phase is often the most challenging, especially in OT environments, where safety, process continuity, and vendor constraints must be considered.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Depending on the maturity of the organization, preparation can range from basic to highly sophisticated:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Unit Tests</span></b> <br /><span data-contrast="auto">Small, isolated tests of specific detection rules (e.g., “Detect Modbus function code 90”).</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Feared Scenario-based Testing</span></b> <br /><span data-contrast="auto">Build scenarios around the organization’s crown jewels and failure modes (e.g., “Unauthorized remote program upload on a PLC controlling a critical process”).</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">CTI-Infused Testing</span></b> <br /><span data-contrast="auto">Integrate threat intelligence: test techniques used by real OT-focused attackers (e.g. TTPs from Volt Typhoon, Sandworm, Xenotime, or ransomware groups targeting industrial environments).</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">To structure the preparation phase, two elements are essential:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">A good knowledge of your OT environment</span></b> <br /><span data-contrast="auto">Planning an exercise that will be relevant to both the business risks &amp; OT detection without impacting the process requires a deep knowledge of the site and its automation.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Mapping to the </span></b><a href="https://attack.mitre.org/matrices/ics/"><b><span data-contrast="none">MITRE ATT&amp;CK for ICS matrix</span></b></a> <br /><span data-contrast="auto">Mapping your tests to the ATT&amp;CK matrix allows you to have a common language with the detection teams. This allows you to select relevant techniques, avoid blind spots, and ensure coverage across multiple layers: OT workstations, PLCs, network interactions, engineering actions…</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<h2>2. D-day (Execution)</h2>
<p><span data-contrast="auto">Execution is performed jointly:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">The Red Team launches controlled and authorized actions</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">The Blue Team monitors detections in real time</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Both teams adjust, document, and validate findings as the exercise unfolds</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">Depending on the scope and complexity of the tests, the Purple Team operation can last from a few hours to a few days.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h3 aria-level="4"><i><span data-contrast="none">Ensuring Reproducibility with Caldera</span></i><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:80,&quot;335559739&quot;:40}"> </span></h3>
<p><span data-contrast="auto">To ensure repeatability and consistency across Purple Team exercises, automation becomes key.  </span><a href="https://www.mitre.org/resources/caldera-ot"><b><span data-contrast="none">Caldera</span></b></a><span data-contrast="auto">, an open-source Breach &amp; Attack Simulation (BAS) framework developed by MITRE, is a powerful tool for this.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">As a former pentester, I’ve always disliked the term “automated pentest”—but BAS tools are the closest thing we have to repeatable, safe attack execution.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h3 aria-level="5"><em>Why use Caldera instead of performing tests manually? </em></h3>
<p><span data-contrast="auto">Caldera enables you to:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Prepare and validate a controlled list of tests on a controlled list of assets</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Ensure only authorized actions are executed</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Guarantee reproducibility across environments</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Replay the exact same actions to measure improvements after configuration changes</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">Some OT-specific plugins already exist in the </span><b><span data-contrast="auto">Caldera-OT</span></b><span data-contrast="auto"> module, supporting Modbus, Profinet, DNP3, and others.</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Recently, Wavestone released two additional OT plugins:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Siemens S7 protocol support</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">OPC-UA communications actions</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<h3 aria-level="5"><em>Caldera in a nutshell </em></h3>
<p><span data-contrast="auto">Caldera usage relies on:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Abilities</span></b><span data-contrast="auto">: atomic technical actions (e.g., reading coils, writing tags, scanning a PLC)</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Adversaries</span></b><span data-contrast="auto">: collections of abilities that form a scenario</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Operations</span></b><span data-contrast="auto">: real-time execution of those adversaries against a target</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><b><span data-contrast="auto">Fact sources</span></b><span data-contrast="auto">: parameters provided for an operation; you can launch the same operations against different environments by just changing the fact source.</span><span data-ccp-props="{&quot;335559685&quot;:720}"> </span></p>
<p><span data-contrast="auto">The following video (French with English subtitles) will walk you through a demonstration of Caldera on our small ICS demo setup:</span> </p>
<div align="center"><iframe loading="lazy" title="YouTube video player" src="//www.youtube.com/embed/wq8BMagjhwE" width="800" height="450" frameborder="0" allowfullscreen="allowfullscreen" data-mce-fragment="1"></iframe></div>
<div align="center"> </div>
<h2>3. Debriefing</h2>
<p><span data-contrast="auto">The debrief is where most of the value is extracted. The following types of </span><i><span data-contrast="auto">Key Performance Indicators</span></i><span data-contrast="auto"> might be used:</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><b><span data-contrast="auto">Detection Coverage</span></b><span data-contrast="auto"> – what percentage of executed stimuli were detected?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Alert Quality</span></b><span data-contrast="auto"> – were alerts actionable, precise, and intelligible?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Reaction Time</span></b><span data-contrast="auto"> – how long before an alert is raised and acknowledged?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">Playbook Efficiency</span></b><span data-contrast="auto"> – were the right actions taken in the expected time frame?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">These might phase results in:</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Updated detection rules</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Improved SIEM/SOC playbooks</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Better monitoring architecture</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Training material for analysts and engineers</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<h1 aria-level="1"><span data-contrast="none">Start Testing Now!</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:360,&quot;335559739&quot;:80}"> </span></h1>
<p><span data-contrast="auto">Purple Team testing brings value immediately, no matter what your current maturity level is:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">It validates your tools in real-world conditions</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">It trains your SOC and OT teams</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">It reveals blind spots early in the program</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">It provides quantitative KPIs to drive detection improvements</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">And yes, </span><b><span data-contrast="auto">it is possible, in most production environments, under the following conditions</span></b><span data-contrast="auto">:</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<ul>
<li><span data-contrast="auto">Strictly controlled scope</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Vendor-approved actions</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">No disruptive functions executed</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Involvement of operations and safety teams</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><span data-contrast="auto">Continuous monitoring of system behavior during testing</span><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">In short: </span><b><span data-contrast="auto">start small, stay safe, and iterate.</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Do not wait for your OT security program to be “finished” before you start testing its effectiveness!</span></b><span data-ccp-props="{&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/12/purple-teaming-for-ot-how-to-switch-from-a-compliance-to-a-performance-mindset/">Purple Teaming for OT:  How to switch from a compliance to a performance mindset?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/12/purple-teaming-for-ot-how-to-switch-from-a-compliance-to-a-performance-mindset/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The security of the MQTT protocol</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/#respond</comments>
		
		<dc:creator><![CDATA[Madeline Salles]]></dc:creator>
		<pubDate>Wed, 01 Oct 2025 07:37:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=27856</guid>

					<description><![CDATA[<p>“Smart homes”, “Smart devices” and even “Smart cities”: these now familiar expressions illustrate how deeply embedded the Internet of Things (IoT) is in our daily lives. At the heart of these technologies, the MQTT protocol plays a subtle yet essential role....</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/">The security of the MQTT protocol</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><b><span data-contrast="none">“Smart homes”, “Smart devices” and even “Smart cities”: these now familiar expressions illustrate how deeply embedded the Internet of Things (IoT) is in our daily lives. At the heart of these technologies, the MQTT protocol plays a subtle yet essential role. This article presents methods for securing MQTT in response to the growing challenges of IoT.</span></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">In 2024, the number of connected IoT devices worldwide was estimated at around 18 billion, more than double the world&#8217;s population. From connected alarms to smart elevators, industrial sensors, and medical devices, these technologies now shape our daily lives.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">Recent advances in the field of IoT have transformed the way we interact with connected objects. Designed to be intuitive, they are accessible without specific expertise. The connections between them, often wireless, go almost unnoticed by users. However, behind this apparent simplicity lie sophisticated communication protocols, including MQTT. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">Due to its popularity and growing presence in sensitive operations, MQTT has been the subject of research for several years regarding the risks associated with its use. Here, we will focus on how it works, its potential vulnerabilities, and best practices for ensuring secure communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">MQTT and the reasons behind its popularity</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<h2><span data-contrast="none">This protocol’s strengths</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p><span data-contrast="none">Developed in 1999 by Andy Stanford-Clark (IBM) and Arlen Nipper (Arcom), MQTT was designed to provide a</span><b><span data-contrast="none"> lightweight</span></b><span data-contrast="none">, </span><b><span data-contrast="none">efficient</span></b><span data-contrast="none"> solution with </span><b><span data-contrast="none">low energy</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">bandwidth consumption</span></b><span data-contrast="none"> for monitoring isolated oil pipelines in the desert via satellite link.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">It is precisely because of these fundamental properties that MQTT has now established itself as the standard for IoT data transmission. This protocol is also frequently used to upload data from sensors or connected objects to cloud platforms.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27836 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1.png" alt="" width="776" height="364" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1.png 1410w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_1-768x360.png 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 1 – MQTT key features</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h2><span data-contrast="none">How it operates</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<p><strong><i>Definitions of key terms</i> </strong></p>
<p><b><span data-contrast="none">MQTT Client: </span></b><span data-contrast="none">A device that exchanges information.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">MQTT Broker: </span></b><span data-contrast="none">An intermediary entity that allows MQTT clients to communicate and through which all MQTT messages pass. Specifically, the broker receives published messages and distributes them to the relevant recipients (subscribers to the corresponding topic). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">Topic: </span></b><span data-contrast="none">A string of characters used to filter and organize messages according to a hierarchical structure. When a client posts a message, they associate it with a topic. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><b><span data-contrast="none">Publish/Subscribe:</span></b><span data-contrast="none"> A model derived from the classic client/server model, in which requests are not initiated by a client requesting resources from a server, but by a server regularly sending updates to clients without active solicitation.</span></p>
<p><span data-contrast="none">MQTT is a “Machine to Machine” or M2M communication protocol that operates according to a </span><b><span data-contrast="none">Publish/Subscribe model</span></b><span data-contrast="none">, allowing for great flexibility in its implementation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">MQTT clients can take on the role of</span><b><span data-contrast="none"> publisher</span></b><span data-contrast="none">, </span><b><span data-contrast="none">subscriber</span></b><span data-contrast="none">, or </span><b><span data-contrast="none">both</span></b><span data-contrast="none">. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">To receive the information they need, </span><b><span data-contrast="none">subscribers</span></b><span data-contrast="none"> subscribe to </span><b><span data-contrast="none">topics</span></b><span data-contrast="none"> (1), which are generally organized hierarchically within the broker (e.g., Home/Room/etc.). When a publisher sends a message intended for subscribers to that topic (2), they are notified by the </span><b><span data-contrast="none">broker</span></b><span data-contrast="none"> (3).</span></p>
<p><span data-contrast="none">As a result, MQTT clients are not required to share the same network or be active at the same time, and do not need to be synchronized with each other. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-27838 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361.png" alt="" width="1370" height="398" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361.png 1370w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-437x127.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-71x21.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_2-e1759302752361-768x223.png 768w" sizes="auto, (max-width: 1370px) 100vw, 1370px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 2 – Illustration of a simplified MQTT architecture</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">Moreover, MQTT offers a </span><b><span data-contrast="none">“Quality of Service” mechanism</span></b><span data-contrast="none"> for its messages, allowing communications to be tailored to the requirements of the application. For example, it can guarantee message delivery in the event of an unstable connection. MQTT clients can select one of three QoS levels for the distribution of their messages:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul>
<li><b><span data-contrast="none">QoS 0</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">At most once » </span></i></b><span data-contrast="none">– The message will be delivered once or not at all, without acknowledgment.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="none">QoS 1</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">At least once » </span></i></b><span data-contrast="none">– The message will be delivered periodically until the sender receives an acknowledgment. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
<li><b><span data-contrast="none">QoS 2</span></b><span data-contrast="none"> « </span><b><i><span data-contrast="none">Once » </span></i></b><span data-contrast="none">– The message is guaranteed to be delivered once and only once.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p><span data-contrast="none">The chosen QoS level also affects</span><b><span data-contrast="none"> how long the message is stored locally</span></b><span data-contrast="none"> by the sender and recipient. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">This architecture enables </span><b><span data-contrast="none">decentralized</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">scalable communications</span></b><span data-contrast="none">. These features are particularly advantageous in the IoT field, where flexibility is essential to accommodate a wide range of use cases. They also explain why MQTT extends far beyond the IoT and finds applications in many other environments, such as telemetry and industrial monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">Is MQTT vulnerable?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">Like many other communication protocols, MQTT is </span><b><span data-contrast="none">not secure by default</span></b><span data-contrast="none">. Although most implementations now incorporate robust security solutions, certain weaknesses and configuration errors persist, leaving systems vulnerable.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="none">To illustrate these concepts, we will look at a standard example of how this protocol is used in an industrial environment.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27840 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3.png" alt="" width="614" height="545" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3.png 955w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-215x191.png 215w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-44x39.png 44w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_3-768x681.png 768w" sizes="auto, (max-width: 614px) 100vw, 614px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 3 – Illustration of an example of industrial use of MQTT</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">In this scenario, all systems represented contain an MQTT client that allows users to subscribe to topics and communicate with the on-premise broker. MQTT communications are unencrypted and there is no authentication of the broker or clients, leaving it possible for an attacker to access production data exchanged in clear text or to send commands to equipment by impersonating the broker or one of its clients.</span><span data-ccp-props="{}"> </span></p>
<h1><span data-contrast="none">How can you protect yourself?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">To effectively mitigate these risks, the broker and MQTT clients must be carefully deployed and configured. Here we propose various security measures to ensure confidentiality, integrity, authenticity, and availability of end-to-end communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="4"><span data-contrast="none">Securing the MQTT broker</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<h3><span data-contrast="none">Enabling default encryption for communications</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">When </span><b><span data-contrast="none">port 8883</span></b><span data-contrast="none"> is the only MQTT port defined, unencrypted communication attempts on the broker are rejected. Furthermore, it is essential that the broker has access to a </span><b><span data-contrast="none">valid certificate</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">private key</span></b><span data-contrast="none"> and that t</span><b><span data-contrast="none">he cryptographic suite</span></b><span data-contrast="none"> used is </span><b><span data-contrast="none">secure</span></b><span data-contrast="none"> (e.g., TLS 1.2 or 1.3). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27842 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4.png" alt="" width="701" height="435" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4.png 1036w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-308x191.png 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-63x39.png 63w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_4-768x477.png 768w" sizes="auto, (max-width: 701px) 100vw, 701px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 4 – Enabling encryption on a Mosquitto MQTT broker via a configuration file</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">Many IoT devices have </span><b><span data-contrast="none">low computing power</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">limited resources</span></b><span data-contrast="none">, so adding mechanisms such as TLS can represent a </span><b><span data-contrast="none">significant overhead</span></b><span data-contrast="none">.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Implementation of customer authentication and control of their access rights</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">MQTT allows </span><b><span data-contrast="none">the</span></b> <b><span data-contrast="none">authentication of clients</span></b><span data-contrast="none"> connecting to a broker using common methods such as a username and password (with an associated password file) and </span><b><span data-contrast="none">verification of the client&#8217;s certificate</span></b><span data-contrast="none">, validated by a certification authority (the broker must have the certificate from this authority). Some brokers also allow</span><b><span data-contrast="none"> the use of external authentication solutions</span></b><span data-contrast="none">.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="none">To restrict subscriptions or publications on certain topics by clients, an</span><b><span data-contrast="none"> Access Control List or ACL</span></b><span data-contrast="none"> logic can be added.</span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27844 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5.png" alt="" width="660" height="429" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5.png 1030w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-294x191.png 294w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_5-768x500.png 768w" sizes="auto, (max-width: 660px) 100vw, 660px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 5 – Addition of a certificate and password authentication with access control on a Mosquitto MQTT broker</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><b><span data-contrast="none">Strict management of topics</span></b><span data-contrast="none"> is essential </span><b><span data-contrast="none">to prevent data leaks</span></b><span data-contrast="none"> and </span><b><span data-contrast="none">limit the risk of compromising</span></b><span data-contrast="none"> the broker. The use of wildcards # and + must be carefully monitored, as an overly permissive configuration would allow an attacker to access all ongoing exchanges.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Deployment of broker protection measures   </span><span data-ccp-props="{}"> </span></h3>
<p><span data-contrast="none">A quick search on the Shodan search engine reveals thousands of MQTT brokers exposed on the Internet, often left in their default configuration, whose users are unaware of their existence or implications. It is therefore essential </span><b><span data-contrast="none">to protect the broker from both internal and external threats</span></b><span data-contrast="none"> by applying </span><b><span data-contrast="none">good security practices</span></b><span data-contrast="none">, such as regularly updating the system or restricting the number of simultaneous requests and connections, to prevent denial-of-service attacks and ensure its availability.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="4"><span data-contrast="none">Securing MQTT clients</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:120}"> </span></h2>
<h3><span data-contrast="none">Enabling communication encryption</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">To connect to the broker, clients must use </span><b><span data-contrast="none">port 8883</span></b><span data-contrast="none"> and have a v</span><b><span data-contrast="none">alid certificate </span></b><span data-contrast="none">and </span><b><span data-contrast="none">private key</span></b><span data-contrast="none">, otherwise the connection will be rejected.</span></p>
<p><img loading="lazy" decoding="async" class=" wp-image-27846 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6.png" alt="" width="687" height="318" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6.png 1033w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-413x191.png 413w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_6-768x355.png 768w" sizes="auto, (max-width: 687px) 100vw, 687px" /></p>
<p style="text-align: center;"><i><span data-contrast="none">Figure 6 – Encrypted connection on an MQTT Paho client</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<p><span data-contrast="none">The use of self-signed certificates to connect to the broker is </span><b><span data-contrast="none">strongly discouraged</span></b><span data-contrast="none"> because they can be easily substituted. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="none">Implementation of broker authentication (mutual authentication)</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">In addition to client authentication, MQTT supports </span><b><span data-contrast="none">broker authentication</span></b><span data-contrast="none"> by verifying the certificate authority that signed its certificate, thus ensuring </span><b><span data-contrast="none">mutual authentication (mTLS)</span></b><span data-contrast="none"> and secure communications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> <img loading="lazy" decoding="async" class=" wp-image-27848 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7.png" alt="" width="616" height="277" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7.png 1041w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-425x191.png 425w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/09/mqtt_en_7-768x345.png 768w" sizes="auto, (max-width: 616px) 100vw, 616px" /></span></p>
<p><i><span data-contrast="none">Figure 7 – Broker authentication on an MQTT Paho client</span></i><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> </span></p>
<h3><span data-contrast="none">Implementation of customer protection measures</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<p><span data-contrast="none">If an MQTT client is compromised, an attacker could access a significant amount of information depending on the configuration of the targeted broker. This is why clients, and their secrets, must also be protected by </span><b><span data-contrast="none">applying good security practices on the client&#8217;s host machine</span></b><span data-contrast="none"> and on the content of exchanges (e.g., adding anti-replay mechanisms to requests). </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h1><span data-contrast="none">What does the future hold for MQTT?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:360}"> </span></h1>
<p><span data-contrast="none">Despite its maturity, MQTT remains an evolving protocol and is gradually incorporating innovative features to meet the growing demands of connected environments. In a context where demand for reliable, secure, and low-power communications continues to increase, it is likely that MQTT use cases will continue to multiply in the coming years.</span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/">The security of the MQTT protocol</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/10/the-security-of-the-mqtt-protocol/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why is SBOM considered a vital ally for the security of your products?</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/03/why-is-sbom-considered-a-vital-ally-for-the-security-of-your-products/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/03/why-is-sbom-considered-a-vital-ally-for-the-security-of-your-products/#respond</comments>
		
		<dc:creator><![CDATA[Paul Chopineau]]></dc:creator>
		<pubDate>Fri, 08 Mar 2024 17:14:36 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=22663</guid>

					<description><![CDATA[<p>Since its initial appearance in 2014 and following its formalization in 2021 under the auspices of the Biden administration, the concept of SBOM (Software Bill of Materials) continues to captivate attention within the cyber community. CISOs, CIOs and DevSecOps teams...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/03/why-is-sbom-considered-a-vital-ally-for-the-security-of-your-products/">Why is SBOM considered a vital ally for the security of your products?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Since its initial appearance in 2014 and following its formalization in 2021 under the auspices of the Biden administration, the concept of SBOM (Software Bill of Materials) continues to captivate attention within the cyber community. <strong>CISOs,</strong> <strong>CIOs </strong>and <strong>DevSecOps</strong> teams all wonder how to put it into practice and leverage it.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>What is SBOM, and in what context does it come into play?</strong></h1>
<p style="text-align: justify;"><strong> </strong>The SBOM (Software Bill of Materials) is a formal inventory, typically in JSON, XML, or plain text format, designed to be machine-readable. It contains detailed information about the software components of a system, including their dependencies, attributes, and hierarchical relationships. The primary goal of an SBOM is to provide a comprehensive and up-to-date view of all the software elements composing an application or system (<strong>source:</strong> <strong><a href="https://www.ntia.gov/page/software-bill-materials">NTIA-Software-Bill-Of-Materials</a>)</strong></p>
<p style="text-align: justify;">Like a physical product, software is a complex assembly of various elements. It includes internally developed code, third-party components (open-source libraries or modules subject to different licenses), as well as all the tools necessary for assembling the final product.</p>
<p style="text-align: justify;">However, with each new vulnerability discovered by researchers or exploited by hackers, suppliers and buyers are faced with a crucial question: where do potential critical vulnerabilities lie within their product?</p>
<p style="text-align: justify;">Today, Wavestone&#8217;s analysis formally attests that the SBOM is undeniably an essential element to address this issue.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>Generation methods </strong></h1>
<p style="text-align: justify;">A comprehensive technical analysis of tools available on the market has revealed the methods for generating Software Bill of Materials (SBOMs).</p>
<p style="text-align: justify;">Three main sources emerge for creating a SBOM:</p>
<ul style="text-align: justify;">
<li>Binary Code (compiled)</li>
<li>Project Source Code</li>
<li>Image Container, generated by platforms such as Docker.</li>
</ul>
<p style="text-align: justify;">These three sources can produce a file compliant with established standards, including<strong> SPDX</strong> and<strong> CycloneDX</strong>. However, it is essential to note that not all tools support these three inputs uniformly.</p>
<p style="text-align: justify;">The technical challenge lies in decompiling binary code, which can sometimes impede its integration. In such cases, the search for specific predefined indicators within the code proves to be an effective method for identifying most of hierarchical interdependencies in an appropriate format.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="wp-image-22665 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage1.png" alt="" width="832" height="295" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage1.png 1129w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage1-437x155.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage1-71x25.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage1-768x272.png 768w" sizes="auto, (max-width: 832px) 100vw, 832px" /></p>
<p style="text-align: center;"><em>Types of Inputs for Generating an SBOM</em></p>
<p style="text-align: justify;">Despite these code extraction and analysis techniques, data completeness is not guaranteed, and additional verification must be considered.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>Facilitated generation but an exploitation that remains to be determined, posing numerous unanswered questions</strong></h1>
<p style="text-align: justify;"><strong> </strong>The creation of an SBOM has been significantly simplified due to the presence of major players specialized in the market, such as <strong>Dependency Track</strong>, <strong>Adolus</strong>, and <strong>Fossa</strong>, to name a few. Additionally, well-established Software Composition Analysis (<strong>SCA</strong>) tools within our clients&#8217; development teams now offer the capability to generate and read an SBOM.</p>
<p style="text-align: justify;"><strong>Generating it is no longer a major challenge today</strong>, thanks to the implementation of the standards mentioned earlier. They facilitate automated SBOM generation by providing clear guidelines on how information about components should be structured and presented. Moreover, many software development and supply chain management tools now natively integrate SBOM creation.</p>
<p style="text-align: justify;"><strong>However, the systems designed to analyze SBOMs are not yet fully mature.</strong> Clients receiving these inventories often face questions about how to use and share them with other parties. Furthermore, to this technical issue, organizational challenges are added, as the framework for use between organizations has not yet been clearly defined.</p>
<p style="text-align: justify;">Nevertheless, stakeholders are actively working to establish a secure integration architecture for these SBOMs within their <strong>CI/CD pipelines</strong>.</p>
<p style="text-align: justify;">Currently, obtaining a reliable SBOM from a third party remains a challenge. Concerns about exchange and sharing arise as soon as this topic is addressed. The <strong>diversity of contracts with suppliers</strong>, who seek to protect their intellectual property, and the challenge of <strong>centralization</strong> pose hurdles to the content of such inventories. Each inventory is developed heterogeneously, without follow-up or a uniform regulatory framework imposed. From a technical standpoint, each entity has the freedom to report the information of their choice.</p>
<p style="text-align: justify;">As of now, we observe that pioneers in the field are opting for internal generation of their SBOMs, including for third-party software. This approach offers greater control over the quality and specificity of data, underscoring the need for more detailed regulation and stricter standards to ensure the reliability of software inventory exchanges.</p>
<p style="text-align: justify;"><strong> </strong></p>
<h1 style="text-align: justify;"><strong>The SBOM Integrated into the Core of Your Software Processes</strong></h1>
<p style="text-align: justify;">All these gaps have prompted the design of an optimal, theoretically state-of-the-art process to integrate an SBOM into a CI/CD pipeline, a process that can be broken down into a few steps.</p>
<ol style="text-align: justify;">
<li><strong>Creation of an SBOM Generation and Collection Space</strong>, Automating the collection of these data to ensure their accuracy and completeness.</li>
<li><strong>Storage of SBOMs in a Repository, </strong>Configuring a centralized repository to store all generated SBOMs. This could be a version control repository or a suitable data storage system.</li>
<li><strong>Distribution of an SBOM Package upon Client Request, </strong>Ensuring that SBOMs are easily accessible, and clients can securely retrieve them on demand.</li>
</ol>
<p style="text-align: justify;"><strong> <img loading="lazy" decoding="async" class="size-full wp-image-22667 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage2.png" alt="" width="1255" height="537" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage2.png 1255w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage2-437x187.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage2-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/03/ENImage2-768x329.png 768w" sizes="auto, (max-width: 1255px) 100vw, 1255px" /></strong></p>
<p style="text-align: justify;">                                   <em>Projection</em> <em>on the Integration of an SBOM within a Software Supply Chain</em></p>
<p style="text-align: justify;">This theoretical outlook paves the way for the automation of the process of generating, storing, and disseminating inventories and vulnerability reports.</p>
<p style="text-align: justify;">This will provide stakeholders with the ability to:</p>
<ul style="text-align: justify;">
<li>Receive real-time SBOMs and vulnerability reports.</li>
<li>Authenticate the legitimacy of received artifacts (image containers, documents, etc.).</li>
<li>Establish trust and validation through transparency at the heart of the software production process.</li>
</ul>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>A Bright Future for SBOM?</strong></h1>
<p style="text-align: justify;"><strong> </strong>Political entities are becoming aware of the level of unpreparedness of their infrastructures in the face of increasing cyber threats. In this context, SBOM is increasingly seen as an effective means to enhance responsiveness to vulnerabilities that could simultaneously affect many companies.</p>
<p style="text-align: justify;">Even though the market is not quite ready for a widespread transition to the use of this solution, it is common for regulation, even if it may seem arbitrary, to profoundly influence the trajectory in a new direction.</p>
<p style="text-align: justify;">It is likely that Europe will eventually converge towards the regulation established in the United States, even though it still seems to be in a preliminary and incomplete stage, especially concerning the mechanisms for sharing and exchanging these inventories.</p>
<p style="text-align: justify;">In the current context, stakeholders are compelled to reassess their priority criteria. It will be important to have data on software composition, the origin of its components, their source, known vulnerabilities, and to trust the production and quality control process.</p>
<p style="text-align: justify;">However, it is necessary to bring back to the agenda the series of challenges they generally face:</p>
<ul style="text-align: justify;">
<li><strong>Incomplete or lacking data,</strong> the absence of comprehensive data on software composition can make risk assessment difficult.</li>
<li><strong>Ad hoc approaches for data sharing,</strong> non-standardized methods and improvised approaches for information sharing can make communication inefficient and unreliable.</li>
<li><strong>Additional costs for data collection and maintenance,</strong> Collecting, verifying, and updating information on software composition can incur additional costs.</li>
<li><strong>Lack of standardization,</strong> the lack of standards in collecting and sharing data makes it difficult to compare and analyze information among different stakeholders.</li>
<li><strong>Governance and data privacy,</strong> managing sensitive data on software composition raises concerns about its confidentiality, integrity, and availability.</li>
</ul>
<p style="text-align: justify;">In conclusion, the SBOM serves as a vital ally for the security of your products, enabling transparency, risk reduction, and informed decision-making throughout the software development lifecycle.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/03/why-is-sbom-considered-a-vital-ally-for-the-security-of-your-products/">Why is SBOM considered a vital ally for the security of your products?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/03/why-is-sbom-considered-a-vital-ally-for-the-security-of-your-products/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Improving the security of your IoT infrastructure: configuration tips and best practices on Azure IoT</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/04/improving-the-security-of-your-iot-infrastructure-configuration-tips-and-best-practices-on-azure-iot/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/04/improving-the-security-of-your-iot-infrastructure-configuration-tips-and-best-practices-on-azure-iot/#respond</comments>
		
		<dc:creator><![CDATA[Arnaud Soullié]]></dc:creator>
		<pubDate>Fri, 07 Apr 2023 13:00:00 +0000</pubDate>
				<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[RBAC]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20232</guid>

					<description><![CDATA[<p>Internet of Things (IoT) platforms enable the connection, management and monitoring of fleets of devices. The 3 cloud leaders, GCP, AWS and Azure each have their own offering, in a particularly fragmented sector, which sees many players competing. Azure, in...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/04/improving-the-security-of-your-iot-infrastructure-configuration-tips-and-best-practices-on-azure-iot/">Improving the security of your IoT infrastructure: configuration tips and best practices on Azure IoT</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Internet of Things (IoT) platforms enable the connection, management and monitoring of fleets of devices. The 3 cloud leaders, GCP, AWS and Azure each have their own offering, in a particularly fragmented sector, which sees many players competing.</p>
<p>Azure, in recent years, has been gaining a foothold in this sector, as Gartner has pointed out, ranking them among the <strong>visionary leaders</strong> of Industrial IoT (IIoT) platforms [1] due to its capabilities, and its almost complete coverage of all use cases and industries.</p>
<p>The IoT, by nature often widely exposed, even on the Internet, can be the<strong> target of attacks</strong>. It is therefore essential to put in place security mechanisms, and to<strong> apply best practices</strong> to improve the security level of the platform and the objects that connect to it, which we will explore in this article.</p>
<p>Before moving on to specific <strong>recommendations</strong> for protecting your IoT devices and data, let&#8217;s look at how the various Azure IoT services can be used together to<strong> create secure IoT solutions</strong>.</p>
<h1><span lang="EN-GB" style="font-size: 20.0pt; line-height: 107%;">Presentation of the Azure IoT offer</span></h1>
<p>Microsoft Azure IoT is an <strong>end-to-end platform</strong> for connectivity, analysis and visualization of data from IoT devices. It also offers <strong>interconnection with other standard Azure services</strong> such as Azure Machine Learning and Azure SQL Database.</p>
<p>Azure IoT offers <strong>two solution ecosystems</strong> to its customers:</p>
<ul style="text-align: justify;">
<li>Azure IoT Central is a <strong>fully managed aPaaS</strong>, Platform as a Service application that <strong>simplifies the creation of IoT solutions</strong>. This service is responsible for connecting, managing and operating fleets of devices, and provides a management user interface. Azure IoT Central is an <strong>aggregate of different Azure IoT services</strong> such as Azure IoT Hub or Azure IoT Hub Device Provisioning Service (DPS).</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20200 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image1.png" alt="" width="836" height="543" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image1.png 836w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image1-294x191.png 294w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image1-60x39.png 60w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image1-768x499.png 768w" sizes="auto, (max-width: 836px) 100vw, 836px" /></p>
<p><em>Azure IoT Central </em><strong>offers application models</strong> according to several business domains: Retail, Health, Energy, Industry, etc., and aims at a &#8220;turnkey&#8221; implementation.  </p>
<ul style="text-align: justify;">
<li>A <strong>customised ecosystem</strong> thanks to the various Azure PaaS (Platform as a Service) services. In this ecosystem, two services; Azure IoT Hub and Azure Digital Twins are the <strong>foundations of an IoT solution</strong>. We have also combined them with Azure Device Provisioning and Azure Device Update for optimal coverage of cyber security needs.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20202 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image2.png" alt="" width="830" height="519" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image2.png 830w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image2-305x191.png 305w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image2-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image2-768x480.png 768w" sizes="auto, (max-width: 830px) 100vw, 830px" /></p>
<p>These two ecosystems enable Azure to <strong>address all types of IoT and IIoT needs</strong>:</p>
<ul style="text-align: justify;">
<li>Azure IoT Central offers a complete service if you want to quickly develop a <strong>low-complexity application</strong> thanks to its application template catalogue.</li>
<li>If you want a <strong>custom solution</strong>, or with features not supported by Azure IoT Central: opt for an ecosystem based on Azure IoT Hub.</li>
</ul>
<p>Now that we have a good understanding of the Azure IoT ecosystems, it is important to <strong>focus on securing these ecosystems</strong>. How can we effectively protect IoT devices and data when using Azure IoT services? This is what we will explore in the following sections.</p>
<p> </p>
<h1><span lang="EN-GB" style="font-size: 20.0pt; line-height: 107%;">Preamble: the Azure CLI tool</span></h1>
<p>In order to manage Azure resources, Microsoft provides several tools, most of which can be used in CLI (Command Line Interface). The tool offering the most functionality for management is <strong>Azure CLI</strong>.</p>
<p>This tool, available for <strong>Windows</strong> and <strong>UNIX</strong> operating systems, allows a user who is a member of an Azure environment to <strong>manage and obtain information about Azure resources</strong>. It should be noted that the range of possibilities of this tool varies according to the rights that the user has over the resources in question.</p>
<p>To install it, Microsoft provides a <a href="https://learn.microsoft.com/fr-fr/cli/azure/install-azure-cli">dedicated page</a> explaining the steps for any type of environment.</p>
<p>In order to use it, all you must do is <strong>connect</strong> to an Azure user account via the chosen command interface (<strong>PowerShell</strong> or <strong>Bash</strong>), then <strong>enter the desired commands</strong>. Once the use of this tool is finished, a disconnection of the account is recommended.</p>
<p>A <strong>typical use</strong> of this tool is shown below:</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 100%; background-color: #002060; border-color: #002060; border-style: solid;">
<p><span style="color: #ffffff;"><span style="color: #ffff00;">az</span> login [<span style="color: #808080;">-u</span> Nom d’utilisateur] [<span style="color: #808080;">&#8211;use-device</span>]</span></p>
<p><span style="color: #ffffff;">[Commandes Azure CLI] [Exemple : ]</span><br /><span style="color: #ffffff;"><span style="color: #ffff00;">az</span> resource list</span></p>
<p><span style="color: #ffffff;"><span style="color: #ffff00;">az</span> logout</span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"><span style="font-size: revert; color: initial;">The documentation of this tool, presenting and explaining all the possible commands, is available at this </span><a style="font-size: revert;" href="https://learn.microsoft.com/fr-fr/cli/azure/reference-index?view=azure-cli-latest">address</a><span style="font-size: revert; color: initial;">.</span></p>
<p>This tool will be used later in the example of technical manipulations.</p>
<h1 style="text-align: justify;"><span lang="EN-GB" style="font-size: 20.0pt; line-height: 107%;">1st security vector: authentication of objects</span></h1>
<p>Device authentication is crucial for an Azure infrastructure as it ensures that <strong>only authorised devices can access cloud resources</strong>. Azure IoT services support two main means of authentication for IoT devices:</p>
<ul style="text-align: justify;">
<li>A <strong>SAS Token</strong> (Shared Access Signature) is a <strong>string of characters</strong> used to authenticate devices and services. An SAP token has the following structure:</li>
</ul>
<p style="text-align: justify;"> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20249 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12.png" alt="" width="2426" height="637" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12.png 2426w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12-437x115.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12-71x19.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12-768x202.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12-1536x403.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image12-2048x538.png 2048w" sizes="auto, (max-width: 2426px) 100vw, 2426px" /></p>
<p>This type of authentication has a <strong>defined validity period</strong> and permissions, which are assigned based on an access policy, on a <strong>given perimeter</strong>. The <strong>signature</strong>, on the other hand, is a crucial element because it is responsible for guaranteeing the security of communications between the object and Azure services, but also for proving the identity of the device. This signature is generated from a secret that must be <strong>specific to each device</strong>.</p>
<ul style="text-align: justify;">
<li>An <strong>X.509 certificate</strong> [2] is a digital certificate allowing <strong>strong authentication</strong> of the object. It contains information about the <strong>entity issuing</strong> the certificate, the validity period of the certificate and the<strong> identity of the subject</strong> (e.g. the object). One of the strengths of certificates is the ability to create chains of certificates, and thus <strong>create trust relationships</strong>:</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20206 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image4.png" alt="" width="844" height="426" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image4.png 844w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image4-378x191.png 378w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image4-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image4-768x388.png 768w" sizes="auto, (max-width: 844px) 100vw, 844px" /></p>
<p style="text-align: justify;"><span style="font-size: revert; color: initial;">X.509 certificates offer a <strong>higher level of security</strong>, assuming a state-of-the-art cryptographic algorithm, as they <strong>allow trust relationships to be represented</strong>. However, the management and use of certificates can involve <strong>additional complexity</strong> for an IoT project.</span></p>
<p>In order to force the use of X.509 certificates to authenticate connected objects, it is possible <strong>to prohibit SAS tokens for an IoT Hub</strong>. Indeed, Azure IoT Hubs have three properties related to the <strong>use or not of SAS tokens</strong>: disableLocalAuth, disableDeviceSAS and disableModuleSAS. Therefore, the best practice associated with disabling SAS tokens is to set these three parameters to True. This can be done using the <strong>Azure CLI</strong> tool:</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 836px; background-color: #002060; border-color: #002060; border-style: solid;">
<p><span style="color: #ffffff;"><span style="color: #ffff00;">az <span style="color: #ffffff;">resource update <span style="color: #808080;">&#8211;resource-group</span> &lt;Resource_Group&gt; <span style="color: #808080;">-n</span> &lt;IoT_Hub&gt;<span style="color: #808080;"> &#8211;resource-type</span> Microsoft.Devices/IotHubs <span style="color: #808080;">&#8211;set</span> properties.disableDeviceSAS=true properties.disableModuleSAS=true properties.disableLocalAuth=true</span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p>Checking the values of these same parameters can also be done using the <strong>Azure CLI</strong>:</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 836px; background-color: #002060; border-color: #002060; border-style: solid;">
<p><span style="color: #ffffff;"><span style="color: #ffff00;"><span style="color: #ffffff;"><span style="color: #ffff00;">az</span> resource show <span style="color: #808080;">&#8212;resource-group</span> &lt;Resource_Group&gt; <span style="color: #808080;">-n</span> &lt;IoT_Hub&gt; <span style="color: #808080;">&#8211;resource-type</span> Microsoft.Devices/IotHubs | <span style="color: #ffff00;">Select-String</span> <span style="color: #33cccc;">&#8220;(disableLocalAuth|disableDeviceSAS|disableModuleSAS)&#8221;</span></span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p>In the example response below, the disableDeviceSAS property has been set correctly, but the other two have not.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20217 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image9.png" alt="" width="907" height="127" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image9.png 907w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image9-437x61.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image9-71x10.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image9-768x108.png 768w" sizes="auto, (max-width: 907px) 100vw, 907px" /></p>
<p style="text-align: justify;">The <strong>Azure portal</strong> also allows you to perform this verification:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20208 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image5.png" alt="" width="580" height="317" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image5.png 580w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image5-349x191.png 349w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image5-71x39.png 71w" sizes="auto, (max-width: 580px) 100vw, 580px" /></p>
<p style="text-align: justify;">The choice of authentication method for Azure IoT will <strong>depend on the security requirements</strong> of your solution. If you need <strong>strong security</strong> and have the infrastructure to manage certificates, then <strong>X.509 certificate</strong> authentication is a good option. However, if you are looking for <strong>a solution that is simple to manage and use</strong>, the SAS token may be more suitable for your needs.</p>
<h1 style="text-align: justify;"><span lang="EN-GB" style="font-size: 20.0pt; line-height: 107%;">2nd security vector: RBAC and alerts </span></h1>
<p>The assignment of roles on your Azure IoT infrastructure must be <strong>thoughtful and defined according to the needs of the users</strong>. A <strong>precise definition of roles and permissions</strong> makes it possible to limit access to resources and to the various functionalities available on the platform. The various Azure IoT services provide a <strong>multitude of pre-configured roles</strong> that can be adapted to your needs and your organisation. Secondly, <strong>applying the principle of least privilege</strong>, and limiting the number of accounts with important privileges, allows you to <strong>improve the security level</strong> of your Azure IoT infrastructure.</p>
<p><strong>Azure CLI </strong>allows you to <strong>list the users with rights to the desired Azure IoT</strong> resource and their associated roles. The following command allows you to perform this action</p>
<table style="border-collapse: collapse; width: 100%; height: 129px;">
<tbody>
<tr style="height: 129px;">
<td style="width: 100%; background-color: #002060; border-color: #002060; border-style: solid; height: 129px;">
<p><span style="color: #ffffff;"><span style="color: #ffff00;"><span style="color: #33cccc;"><span style="color: #ffff00;">az</span> <span style="color: #ffffff;">role assignment list</span> <span style="color: #808080;">&#8211;scope</span> &#8220;/subscriptions/&lt;ID_de_souscription&gt;/resourceGroups/&lt;Resource_Group&gt;/providers/Microsoft.Devices/IotHubs/&lt;IoT_Hub&gt;&#8221; <span style="color: #808080;">&#8211;include-inherited</span></span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p><span style="font-size: revert; color: initial;">It is possible to use string selectors (Select-String for </span><strong style="font-size: revert; color: initial;">PowerShell</strong><span style="font-size: revert; color: initial;">, grep for </span><strong style="font-size: revert; color: initial;">Bash</strong><span style="font-size: revert; color: initial;">) to retrieve only the desired information.</span></p>
<p>In the example below, <strong>names, types</strong> and <strong>roles</strong> were the only items retrieved using Select-String:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20220 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image10.png" alt="" width="852" height="802" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image10.png 852w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image10-203x191.png 203w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image10-41x39.png 41w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image10-768x723.png 768w" sizes="auto, (max-width: 852px) 100vw, 852px" /></p>
<p>The Azure built-in roles feature is available on <a href="https://learn.microsoft.com/fr-fr/azure/role-based-access-control/built-in-roles">this page</a>.</p>
<p>Configuring <strong>alerts based on the metrics</strong> of your Azure IoT services is another tool to consider. Alerts can be configured to detect suspicious behaviour or anomalies, <strong>allowing for rapid investigation</strong> of your infrastructure. Azure provides its customers with a large collection of signals to define alert conditions. It is also possible to <strong>define custom alert signals </strong>via the query language used by Azure Log Analytics.</p>
<p>The <strong>Azure Portal</strong> is the easiest way to set up alerts based on the data collected by the IoT Hub. For example, to define a log alert rule, you need to:</p>
<ol style="text-align: justify;">
<li>Go to the management page of the desired IoT Hub;</li>
<li>Go to the Logs sub-category of the Monitoring category;</li>
<li>Choose a rule using the Azure Log Analytics language;</li>
<li>Add an alert rule related to this query;</li>
<li>Choose the operator, unit, threshold value, check recurrence and time period for the rule</li>
</ol>
<p style="text-align: justify;">These actions are summarised in the screenshots below:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20210 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image6.png" alt="" width="909" height="244" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image6.png 909w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image6-437x117.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image6-71x19.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image6-768x206.png 768w" sizes="auto, (max-width: 909px) 100vw, 909px" /></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20212 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image7.png" alt="" width="824" height="603" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image7.png 824w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image7-261x191.png 261w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image7-53x39.png 53w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image7-768x562.png 768w" sizes="auto, (max-width: 824px) 100vw, 824px" /></p>
<p>It will then be sufficient to choose an <strong>action group</strong> linked to a type of action (sending an email, SMS, etc.).</p>
<p>The example given will lead to an action if the number of failed connections of connected objects to the IoT Hub concerned exceeds 10 failures in 10 minutes or less.</p>
<p>A <a href="https://learn.microsoft.com/fr-fr/azure/azure-monitor/alerts/tutorial-log-alert">detailed guide</a> in the form of a tutorial is available on the Azure documentation. Note that this service is available at an additional cost.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><span lang="EN-GB" style="font-size: 20.0pt; line-height: 107%;">3rd vector of security: the service itself </span></h1>
<p>Finally, <strong>setting up proper configuration</strong> of Azure IoT services is a key element in improving the platform&#8217;s cyber maturity level. This includes options such as <strong>routing rules</strong> or setting the minimum version of TLS used by devices to connect to Azure IoT Hub.</p>
<p><strong>Routing rules</strong> are used to <strong>redirect messages</strong> from IoT devices to an endpoint (storage, services, database, etc.) and are configurable by routing requests. It is recommended to <strong>filter incoming messages</strong>, via routing requests, to increase the security of your IoT solution.</p>
<p><strong>Checking the minimum TLS version accepted</strong> can be done using the <strong>Azure CLI</strong>: indeed, an IoT Hub has the minTlsVersion attribute to check this property. This check is performed using the following command:</p>
<table style="border-collapse: collapse; width: 100%;">
<tbody>
<tr>
<td style="width: 100%; background-color: #002060; border-color: #002060; border-style: solid;">
<p><span style="color: #ffffff;"><span style="color: #ffff00;">az <span style="color: #ffffff;">resource show <span style="color: #808080;">&#8212;resource-group</span> &lt;Resource_Group&gt; <span style="color: #808080;">-n</span> &lt;IoT_Hub&gt; <span style="color: #808080;">&#8211;resource-type</span> Microsoft.Devices/IotHubs | <span style="color: #ffff00;">Select-String</span> <span style="color: #33cccc;">&#8220;minTlsVersion&#8221;</span></span></span></span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;">Si cette commande <strong>ne retourne rien</strong>, ou retourne <strong>une valeur inférieure à 1.2</strong>, alors la configuration <strong>n’est pas satisfaisante</strong>.</p>
<p style="text-align: justify;">Le <strong>portail d’Azure</strong> permet également d’effectuer cette vérification</p>
<p>If this command <strong>returns nothing</strong>, or returns a <strong>value less than 1.2</strong>, then the configuration <strong>is not satisfactory</strong>.</p>
<p>The <strong>Azure portal</strong> also allows you to perform this check:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-20214 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image8.png" alt="" width="668" height="315" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image8.png 668w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image8-405x191.png 405w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/04/Image8-71x33.png 71w" sizes="auto, (max-width: 668px) 100vw, 668px" /></p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;"><strong>En synthèse</strong></h1>
<p><strong>Security is a major issue for IoT projects</strong>: Microsoft, with its Azure IoT product, provides an IoT platform that meets the majority of IoT needs in a secure manner, provided that it is configured correctly. In this article, we have discussed<strong> recommendations for improving the security</strong> of your Azure IoT infrastructure.</p>
<p>It is important to keep in mind that <strong>other attack vectors exist</strong>, such as hardware and software vulnerabilities and the networks used by IoT devices.  Securing an IoT infrastructure is a <strong>complex challenge that requires an end-to-end approach</strong>.</p>
<p style="text-align: justify;"><strong> </strong></p>
<p style="text-align: justify;"><em> </em></p>
<p style="text-align: center;"><em>With the help of Marius ANDRE</em></p>
<p style="text-align: justify;">[1] “Magic Quadrant for Global Industrial IoT Platforms”</p>
<p style="text-align: justify;"><a href="https://www.gartner.com/doc/reprints?id=1-2BQFX3BJ&amp;ct=221116&amp;st=sb">https://www.gartner.com/doc/reprints?id=1-2BQFX3BJ&amp;ct=221116&amp;st=sb</a></p>
<p style="text-align: justify;">[2] “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”</p>
<p style="text-align: justify;"><a href="https://www.rfc-editor.org/rfc/rfc5280">https://www.rfc-editor.org/rfc/rfc5280</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/04/improving-the-security-of-your-iot-infrastructure-configuration-tips-and-best-practices-on-azure-iot/">Improving the security of your IoT infrastructure: configuration tips and best practices on Azure IoT</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/04/improving-the-security-of-your-iot-infrastructure-configuration-tips-and-best-practices-on-azure-iot/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Connecting your connected coffee machine: yes, but how?</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/04/connecting-your-connected-coffe-machine-yes-but-how/</link>
		
		<dc:creator><![CDATA[Paul Fauchet]]></dc:creator>
		<pubDate>Mon, 05 Apr 2021 07:00:43 +0000</pubDate>
				<category><![CDATA[How to]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[risk analysis]]></category>
		<category><![CDATA[use cases]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15425</guid>

					<description><![CDATA[<p>Networks are at the backbone of every modern systems; for the ecosystems of connected objects, this is no exception. In this article, we will provide you with a methodology to use from the get-go to help in choosing a secure...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/04/connecting-your-connected-coffe-machine-yes-but-how/">Connecting your connected coffee machine: yes, but how?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Networks are at the backbone of every modern systems; for the ecosystems of connected objects, this is no exception. In this article, we will provide you with a methodology to use from the get-go to help in choosing a secure and suitable network for your IoT project.</p>
<p>In this example, we will assume that you are a coffee machine manufacturer. Your current project is to build a connected coffee machine for your corporate customers. You have identified multiple use cases for this IoT machine. For instance, it automatically orders new coffee capsules when the stock falls below a certain threshold. A second option would be that the coffee machine, sends automatic alerts to your servers when maintenance management such as cleaning, repairs, etc. is needed. Finally, it offers your clients functionalities for monitoring consumption.</p>
<p>How can you choose the right network for your needs? What questions should you ask yourself? How do you make a good choice while considering the overall security of your system?</p>
<p>&nbsp;</p>
<h2>First Step – Define your business requirements and perform a risk analysis</h2>
<p>First, you must identify the requirements for your IoT network which are twofold: business and security requirements. We characterize these requirements with levels 0 to 3, 0 being the lowest and 3 being the highest level.</p>
<p>For the business requirements, you must answer questions such as:</p>
<ol>
<li>How far should the object&#8217;s signal reach?</li>
<li>How much bandwidth do you need?</li>
<li>What is the autonomy of your object?</li>
</ol>
<p>In our example, we assume that your connected coffee machines will be distributed to corporate customers operating over a large geographical area (i.e. over 100 km radius). Therefore, you will need a wide coverage to enable your customers’ widespread machines to communicate with your Information System.</p>
<p>Two business cases are outlined here: If your customer agrees to connect your machine to its existing local network, you will then only need a short-range wireless network between the machine and the internet router. If they refuse to do so, you will then need to set up a long-range network as you will deploy your service and machines over a wide area.</p>
<p>For the bandwidth, a small/short amount will be needed as it solely requires to be able to send small data packages a few times a day at most (capsule orders, alerts, general status, …).</p>
<p>In regard to energy consumption, a coffee machine is traditionally connected to a power supply to perform its tasks; henceforth, power does not constitute an issue in terms of IOT, i.e. the object autonomy is therefore not constraint. There is no energy consumption requirement per se as it is already covered by the coffee machine’s connection to the power grid.</p>
<p>We summarize the levels for business requirements as follows:</p>
<ul>
<li>Range (R) = 3 or 1</li>
<li>Bandwidth (B) = 1</li>
<li>Energy consumption (E) = 0</li>
</ul>
<p>Having defined your business requirements, a risk analysis must be conducted to formulate the security requirements of your project for availability, integrity, confidentiality, and traceability purposes.</p>
<p>A loss of availability would occur in the event of a dysfunction on the connected coffee machine that would render it unusable for a customer. A loss of access to the network or unavailability of backend servers should never result in the machine being unavailable: it must remain working off-network. However, if a dysfunction of the machine occurs, we assume that you would want it to be reported back as quickly as possible through the network in order for maintenance actions to be triggered.</p>
<p>How long can this last? The answer would be several hours rather than several days, as we wouldn’t want to deprive employees from their coffee breaks! Therefore, 4 to 24 hours is an acceptable window of unavailability which can be translated into an availability requirement level of 2.</p>
<p>A loss of integrity would result in data corruption. For example, a potential excess order of coffee capsules may occur by altering the messages sent by the coffee machine or by replacing the same order multiple times. In both cases, this would result in a financial loss for your client. Data on the network needs to be communicated rigorously and exactly. Hence, we can conclude this is a requirement level of 3.</p>
<p>A loss of confidentiality would result in data being divulged; orders quantities are rather sensitive data that shouldn’t be shared with external parties. It needs to be ensured that data is communicated securely on the network and is not accessible by externals parties. &nbsp;Hence, we conclude that confidentiality has a requirement level of 2.</p>
<p>For traceability, and for simplification reasons, we choose to leave this aspect aside assuming that it is already accounted for by the study of the first 3 criteria.</p>
<p>In a nutshell, risk analysis concludes to the following security requirements:</p>
<ul>
<li>Availability (A) = 2</li>
<li>Integrity (I) = 3</li>
<li>Confidentiality (C) = 2</li>
</ul>
<p>For more details about risk analysis methodology for smart objects, you can refer to this <a href="https://www.riskinsight-wavestone.com/en/2021/01/risk-analysis-and-iot-a-marriage-of-love-or-reason/">article</a>.</p>
<p>At the end of this analysis, you obtain for both of your business cases a radar chart of your requirements.</p>
<h3>Business case 1: your customer connects your coffee machine to its local network</h3>
<figure id="post-15428 media-15428" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15428 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-1.png" alt="" width="966" height="470" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-1.png 966w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-1-393x191.png 393w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-1-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-1-768x374.png 768w" sizes="auto, (max-width: 966px) 100vw, 966px" /></figure>
<h3>Business case 2: your customer does not connect your coffee machine to its local network</h3>
<figure id="post-15430 media-15430" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15430 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-2.png" alt="" width="945" height="465" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-2.png 945w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-2-388x191.png 388w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-2-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-2-768x378.png 768w" sizes="auto, (max-width: 945px) 100vw, 945px" /></figure>
<p>Though not discussed in this article, financial aspects are also important and depend on various factors such as the network operator pricing model. Same goes for geographic constraints as some networks may not be available on some regions.</p>
<p>Eventually, the ease of configuration of the network may be included in your business requirements, especially if your connected object targets a B2C audience.</p>
<p>&nbsp;</p>
<h2>Second step &#8211; Choose your IoT Network</h2>
<p>Building on business and security requirements, we developed a methodology to choose the right network that will be optimal to meet your business and security needs: range, bandwidth, energy consumption, availability, integrity, confidentiality.</p>
<p>The three business requirements are mandatory, the network you choose must fulfil them, otherwise, it will be eliminated.</p>
<p>For security requirements, the assessment requires pre-emptive analysis. Between two networks that cover the same business requirements, you should choose the one that offers the best level of security with the minimum cost.</p>
<p>If a network doesn’t cover one of the security requirements, you will have to implement some additional security feature as a part of your project backlog, consequently raising your costs.</p>
<p>You should also be vigilant that the additional implementation doesn’t impact the system’s performance. For instance, if you implement data encryption at the application layer, increasing processing times would negatively impact your maximum data rate or could be constrained by the hardware capabilities of the device, with a potential financial impact in case of a hardware upgrade. Consequently, one of your business requirements may no longer be met.</p>
<p>In case high availability is required (A=3), you ought to choose a robust network by design that will meet your real-time needs.</p>
<p>In fact, spread spectrum (like Bluetooth or ZigBee) or frequency hopping modulated protocols (like Sigfox or Bluetooth) are more resistant to radio jamming or radio interferences.</p>
<p>These types of networks are particularly recommended when availability is an important requirement, such as on an industrial production line.</p>
<p>Moreover, mesh protocols are known to be more reliable and scalable than point to point protocols. However, for them to achieve efficiency, they need to be used in a context where multiple connected devices are linked together. Mesh protocols like WirelessHART can also guarantee real-time communications. Their usage is especially adapted to an industrial context.</p>
<p>A simple methodology to choose the right network is to confront your business requirements to the network’s business and security offerings.</p>
<p>In the following radar charts, we present different types of IoT networks providing different levels of business and security offerings, and we compare each one of them to our business requirements.</p>
<h3>Business case 1: your customer connects your coffee machine to its local network</h3>
<figure id="post-15432 media-15432" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15432 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-3.png" alt="" width="1128" height="697" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-3.png 1128w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-3-309x191.png 309w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-3-63x39.png 63w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-3-768x475.png 768w" sizes="auto, (max-width: 1128px) 100vw, 1128px" /></figure>
<h3>Business case 2: your customer does not connect your coffee machine to its local network</h3>
<figure id="post-15434 media-15434" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15434 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-4.png" alt="" width="1127" height="712" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-4.png 1127w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-4-302x191.png 302w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-4-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-4-768x485.png 768w" sizes="auto, (max-width: 1127px) 100vw, 1127px" /></figure>
<p>Let&#8217;s apply the previous methodology to your connected coffee machine. First, we use our previous radar charts to see which networks comply with our business requirements.</p>
<h3>Business case 1: your customer connects your coffee machine to its local network</h3>
<p>For your first business case, Bluetooth and Wi-Fi are two viable short-range options if your customer connects the machine to its local network. On the one hand, Bluetooth meets all the security requirements, but it is less straightforward to implement compared to Wi-Fi. On the other hand, Wi-Fi meets all of them except for availability but that is something we can work out with SLA agreements.</p>
<h3>Business case 2: your customer does not connect your coffee machine to its local network</h3>
<figure id="post-15439 media-15439" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15439 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-5-1.png" alt="" width="1471" height="537" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-5-1.png 1471w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-5-1-437x160.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-5-1-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/Image-5-1-768x280.png 768w" sizes="auto, (max-width: 1471px) 100vw, 1471px" /></figure>
<p>For your second business case, Zigbee, BLE and Wi-Fi are clearly out of the equation because they do not meet the range requirements. However, LoRa, LTE-M and Sigfox are still in the mix.</p>
<p>We use the radar charts again, this time to assess these three candidate&#8217;s compliance with the security requirements.</p>
<p>Sigfox does not meet one of your security requirements (confidentiality) whereas LoRa complies with all security requirements. LTE-M is the best offering as it meets all your requirements, but it is also the most expensive. We conclude that LoRa is a relatively good candidate.</p>
<p>In conclusion, we have one good candidate: LoRa which will require the deployment of a new network and an alternative using a pre-existing Wi-Fi network. It should be noted that you may refuse to connect to the Wi-Fi network on company premises for security reasons.</p>
<p>We will undertake a new scenario in a next article: a customer company buys the machine and discusses what payment options to use.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/04/connecting-your-connected-coffe-machine-yes-but-how/">Connecting your connected coffee machine: yes, but how?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Risk analysis and IoT: a marriage of love or reason?</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/01/risk-analysis-and-iot-a-marriage-of-love-or-reason/</link>
		
		<dc:creator><![CDATA[Bertrand Carlier]]></dc:creator>
		<pubDate>Wed, 27 Jan 2021 06:00:22 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[connected devices]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IoT risk]]></category>
		<category><![CDATA[methodology]]></category>
		<category><![CDATA[project management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk analysis]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14988</guid>

					<description><![CDATA[<p>Wavestone and Sigfox share a common passion for tech, innovation and security. Our discussions led us to explore the foundation of all cybersecurity initiatives (the risk analysis), why this is different for an IoT project and, most importantly, how you...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/risk-analysis-and-iot-a-marriage-of-love-or-reason/">Risk analysis and IoT: a marriage of love or reason?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Wavestone and Sigfox share a common passion for tech, innovation and security. Our discussions led us to explore the foundation of all cybersecurity initiatives (the risk analysis), why this is different for an IoT project and, most importantly, how you can get started.</p>
<p>&nbsp;</p>
<h2>What is a cyber risk analysis?</h2>
<p>Did you ever wonder what would happen if a device your company developed and sells leak the data it collects? Or if that data were corrupted or suddenly made unavailable? What would be the most detrimental? <strong>What if your solution was vulnerable to a cyberattack?</strong> Could the consequences be a takeover of device(s) which leads to a safety hazard such as a building taking fire or even a human casualty? Or maybe it could “just” be a pivot attack onto your customer’s network that leads to a full incapacity for your and your customer’s businesses to operate.</p>
<p>If you are currently developing an IoT solution and are not having a nervous breakdown when considering such possibilities, you are probably wondering though how your CISO (Chief Information Security Officer) is not having one.</p>
<p>Well it is probably because your CISO<strong> has a method</strong>: they consider every risk from <strong>an unbiased perspective and in a comparable manner</strong>. Ensuring each risk is correctly evaluated (i.e. not overestimated or underestimated) and sharing the outcome of this evaluation with all project stakeholders is the first important step. Once all stakeholders agree upon every risk your company has the right basis to decide control measures.</p>
<p>This approach does not mean you should address every risk to the point that your solution is virtually <em>unhackable</em>. Frankly, this is not technically possible, and your budget would vanish far before achieving a so called zero cyber risk solution. Each control measure must be prioritized and proportional to the risk likelihood and severity.</p>
<p>What we described above is known as a <strong>risk analysis methodology</strong>. Cybersecurity professionals use this methodology as the baseline to their company’s cybersecurity initiatives. The professionals evaluate risk scenarios (often tied to service availability, data integrity, confidentiality and/or traceability of actions) and the impacts on their company’s brand image, legal liabilities, safety consequences and of course financial outcomes. The higher the risk is evaluated, the higher the priority is set to lower the likelihood of the risk occurring (e.g. add barriers to an attack, reduce the attack surface, etc.) or the severity of outcomes if the risk occurs (e.g. apply segmentation to reduce the spread of an attack).</p>
<p>If you want to learn more about the existing risk analysis methodologies you should start with ISO27005 which has a wide scope of adoption and understanding across various industries.</p>
<p>Be reassured that <strong>talking about risks will not increase the likelihood of the problem occurring </strong>(if you ever feared that), however not talking about them puts the project at great risk.</p>
<p>&nbsp;</p>
<h2>What makes an IoT Project risk analysis different?</h2>
<p>Hopefully we have convinced you that doing a risk analysis of your project is an important task; we will touch upon how you can get started quickly in the next chapter. Before we get there, we will detail what makes the exercise specific for an IoT project: what are the characteristics of such projects and what makes the risk analysis more difficult or simpler?</p>
<p>Let us start with the common characteristics that should be considered for a risk analysis. First of all, an IoT initiative often relies on a very decentralized network of hardware (sensors, gateways, servers, etc.). These devices can be spread over a large geographical area, sometimes all over the world, and are meant to remain in the field for a long time with little to no onsite maintenance. It is common to see B2B IoT devices that aim for a lifetime of more than 10 years (e.g. a water metering project for utility companies). B2C devices can also aim for such lifetimes – think of connected vehicles for instance. It is also noteworthy that IoT devices usually have limited user interfaces such as a screen and keyboard. Despite this, the buttons, LED and mobile applications allow the necessary interactions or customizations to the IoT device for you to collect data from the field. Remember, the data collected from connected devices is where the value resides. Thus, whether that data is critical or not is essential in the risk evaluation. Finally, we need to remind ourselves that an IoT project is still an IT project. If the devices are not typical laptops, the application servers and storage remain central in most cases. This is where a large part of the risk remains, but fortunately, there are many best practices for this portion of the solution as well.</p>
<p>From a cybersecurity perspective such characteristics can make IoT projects riskier. For instance:</p>
<ul>
<li>The physical security of a decentralized network is very hard to enforce. Where are the devices located? Are the devices accessible to the public? Can someone easily steal, damage or tamper the devices? For example, a tracker installed on a pallet travels outside trusted premises and can be damaged or removed – intentionally or not. Of course, this risk is amplified by a wider geographical footprint.</li>
<li>Given the limited user interactions and the longer device lifetime, it can become very costly and time-consuming to maintain the devices, especially if you must physically dispatch technicians. Hands-on intervention can be simply unrealistic, but even firmware upgrades have a failure rate. Because of all this, the controls must be relevant for the long run.</li>
<li>In any IoT project, the sensitivity of the data is a factor that must be considered. Is it critical for your company? For consumer projects the sensitivity of the data can be perceived as very high because the devices will collect data from the “real” world.</li>
<li>IoT solutions consist of many different technologies and vendors. This is a challenge for us: what are the security practices followed by each of these vendors and do these practices sufficiently cover my risks?</li>
<li>Finally, the security controls that can be applied are dependent on the capacities of the devices and softwares. For example, many sensors run on 8-bits MCU and thus cannot run complicated encryption algorithms.</li>
</ul>
<p>Fortunately, all these characteristics also play a role in reducing the cyber risks for IoT projects.</p>
<ul>
<li>With very decentralized deployments, the level of effort required by an attacker to access a large number of devices is burdensome. Compromising a single device is one thing but compromising the entire fleet of devices is an entirely different task. This is especially true if physical tampering or proximity is required.</li>
<li>The application of the IoT devices are rarely handled directly by a user and there are limited user interactions after installation. Thus, attackers have limited opportunities to trick the user into misusing the application.</li>
<li>Depending on the context, the value of the data can be very limited for attackers (e.g. room temperature monitoring used to control AC systems). What is more, the value can also decrease sharply with time. Production data can be critical for real-time control of processes, but it becomes a lot less valuable a few minutes after.</li>
<li>The architecture of IoT solutions is usually segregated from the IT systems including servers or data centers. This segregation enables companies to easily define and protect integration points.</li>
<li>Finally, the limited capacities of the device play a role in preventing any harmful attempt. Attackers simply cannot access, implant malware or effectively control sensors with 8-bit MCUs.</li>
</ul>
<p>&nbsp;</p>
<div class="slate-resizable-image-embed slate-image-embed__resize-full-width">
<figure id="post-15039 media-15039" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15039 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3.png" alt="" width="1845" height="883" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3.png 1845w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3-399x191.png 399w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3-768x368.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/01/Image-1-3-1536x735.png 1536w" sizes="auto, (max-width: 1845px) 100vw, 1845px" /></figure>
</div>
<div></div>
<h2>So now, how can I get started?</h2>
<p>Well, take a deep breath and involve your CISO.</p>
<p>The CISO must identify and evaluate applicable regulations, decide what level of risks is acceptable, provide policies to follow and tools to implement security measures. Perhaps you should appoint Product Security Officer to specifically address IoT security in your company or even a given IoT product’s security if the stakes require it.</p>
<p>Getting to an acceptable level of security will require expertise on the various areas of the IoT solution. If you are that expert, then you should probably be ready to get involved. This will drive the whole team to consider the:</p>
<ul>
<li>End-to-end security on the technology stack: from hardware to cloud including embedded software, network connectivity, mobile apps, etc.</li>
<li>End-to-end security from a device lifecycle perspective. When you design your device, think about all phases: from manufacturing to distribution; from initial use to normal usage; resell, refurbish, recycle or trash.</li>
<li>Partners involvement: make sure not to forget them and assess their maturity. You might need to take measures to support them or upskill them (<em>hint</em>: ask your CISO or PSO for it).</li>
<li>Audit of your device and the whole technology stack. Do this regularly because your software may not have changed but the threats and known vulnerabilities may have.</li>
<li>Long-term security updates and maintenance: define for how long you will update and deploy your devices.</li>
<li>Incident response organization: define how you can be notified of vulnerabilities or breaches and how you can plan to respond (from a technical and a communication point of view).</li>
</ul>
<p>IoT cybersecurity is not impossible. It actually provides methodologies and tools to help achieve a secure landscape.</p>
<p>Project stakeholders and customers are seeking and pressuring for secure products. Regulation to enforce security are imminent and frameworks to help align every actor regarding its duties will continue to be applied. It is time to get ahead now if you are looking to make cybersecurity an asset for your product on your market!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/01/risk-analysis-and-iot-a-marriage-of-love-or-reason/">Risk analysis and IoT: a marriage of love or reason?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/</link>
		
		<dc:creator><![CDATA[Raquel De Faria Cristas]]></dc:creator>
		<pubDate>Fri, 28 Aug 2020 13:07:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[Jitsuin]]></category>
		<category><![CDATA[POC]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Smart House]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14147</guid>

					<description><![CDATA[<p>In a previous article, we discovered how &#8220;Security Twins&#8221; could improve the security and trust of connected devices. In this new article we will now look at how the “Security Twins” can improve the security of physical accesses to a building...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">In a <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">previous article</a>, we discovered how &#8220;Security Twins&#8221; could improve the security and trust of connected devices. In this new article we will now look at how the “Security Twins” can improve the security of physical accesses to a building through a PoC made by Wavestone in collaboration with the start-up Jitsuin using their tool: “Jitsuin Archivist”.</p>
<p>&nbsp;</p>
<h2>What does “Jitsuin Archivist” look like?</h2>
<p style="text-align: justify;">The start-up Jitsuin has developed a tool called &#8220;Jitsuin Archivist&#8221; based on Distributed Ledger Technology (DLT). The purpose of this tool is to know &#8220;Who did what to a Thing and When”.</p>
<p style="text-align: justify;">As of today, 5 types of users can interact with the tool: Archivist Administrator, System Administrator, Maintenance Operator, Auditor, Custom (currently in beta version).</p>
<p>&nbsp;</p>
<figure id="post-14148 media-14148" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14148 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1.png" alt="" width="1277" height="275" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1.png 1277w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-437x94.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-71x15.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-768x165.png 768w" sizes="auto, (max-width: 1277px) 100vw, 1277px" /></figure>
<p style="text-align: center;">Figure 1 – The 5 user roles of “Jitsuin Archivist”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">On this tool the user has access to the &#8220;Security Twins&#8221; of the connected devices. Indeed, after logging in, the user accesses a dashboard through which he has a global view of all the connected devices linked to the tool. He can see relevant statistics related to his IoT deployment, such as the number of critical incidents, the activity of connected objects, etc.</p>
<p style="text-align: justify;">The user can also access the &#8220;Manage Assets&#8221; page where he will find a map with the location of all the connected objects linked to the tool and a list of them (where he can also see in more detail the events linked to a particular connected device).</p>
<p>&nbsp;</p>
<figure id="post-14150 media-14150" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14150 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2.png" alt="" width="1339" height="653" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2.png 1339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-392x191.png 392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-768x375.png 768w" sizes="auto, (max-width: 1339px) 100vw, 1339px" /></figure>
<p style="text-align: center;">Figure 2 &#8211; The different views of the tool &#8220;Jitsuin Archivist&#8221;: 1. dashboard with a global view, 2. all the objects and their location, 3. detailed view of an object, 4. all the actions of the object useful during security audits</p>
<p>&nbsp;</p>
<h2>The PoC: A House with a digital lock</h2>
<p style="text-align: justify;">Wavestone used Jitsuin&#8217;s tool to first address the issue of identity and access management in buildings in at the dawn of digital transformation and the to illustrate the usefulness of &#8220;Security Twins&#8221;.</p>
<p style="text-align: justify;">To do this Wavestone used the lego house &#8220;SmartHouse&#8221; :</p>
<p>&nbsp;</p>
<figure id="post-14152 media-14152" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14152 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3.jpg" alt="" width="1085" height="955" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3.jpg 1085w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-217x191.jpg 217w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-44x39.jpg 44w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-768x676.jpg 768w" sizes="auto, (max-width: 1085px) 100vw, 1085px" /></figure>
<p style="text-align: center;">Figure 3 – The “SmartHouse”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Equipped with an RFID card reader, a Raspberry Pi microcontroller and a servomotor, the entrance door of the &#8220;SmartHouse&#8221; only opens to users who have an authorized access card. All actions related to opening, closing, granting of entry rights, etc. are recorded on &#8220;Jitsuin Archivist&#8221; (see figure 4).</p>
<p>&nbsp;</p>
<figure id="post-14154 media-14154" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14154 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4.png" alt="" width="1037" height="474" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4.png 1037w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-418x191.png 418w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-768x351.png 768w" sizes="auto, (max-width: 1037px) 100vw, 1037px" /></figure>
<p style="text-align: center;">Figure 4 – The functional diagram of the “SmartHouse”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">In order to facilitate the interaction with the digital lock of the “SmartHouse”, a platform allowing the simulation of different operations made by different peopled involved in the life cycle of connected devices has been created using the Django web framework and Bootstrap. This platform allows, among other things, to:</p>
<ul style="text-align: justify;">
<li>Send security patches to the connected lock (using Azure IoTHub)</li>
<li>Assign access rights to the “SmartHouse”</li>
<li>View the history of access rights requests made and those awaiting validation, etc.</li>
</ul>
<p style="text-align: justify;">This is what the platform looks like:</p>
<p>&nbsp;</p>
<figure id="post-14156 media-14156" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14156 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5.png" alt="" width="1426" height="729" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5.png 1426w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-768x393.png 768w" sizes="auto, (max-width: 1426px) 100vw, 1426px" /></figure>
<p style="text-align: center;">Figure 5 &#8211; SmartHouse&#8217;s management platform</p>
<p>&nbsp;</p>
<p style="text-align: justify;">The use of “Jitsuin Archivist” in this PoC is very interesting when regards to security audits of connected devices. Indeed, as “Jitsuin Archivist” is based on Distributed Ledger Technology (DLT), this system can be considered as &#8220;secure by design&#8221; since an auditor has a technical guarantee on the non-compromise of data (provided that the sending of this data is secure).</p>
<p style="text-align: justify;">Here is the &#8220;Auditor View&#8221; on “Jitsuin Archivist” where it is possible to see all the information regarding the connected devices linked to the platform and to know who has done what to the connected device:</p>
<p>&nbsp;</p>
<figure id="post-14158 media-14158" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14158 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6.png" alt="" width="1804" height="884" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6.png 1804w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-390x191.png 390w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-768x376.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-1536x753.png 1536w" sizes="auto, (max-width: 1804px) 100vw, 1804px" /></figure>
<p style="text-align: center;">Figure 6 &#8211; The &#8220;Auditor View&#8221; of “Jitsuin Archivist”</p>
<p>&nbsp;</p>
<h2>The PoC scenario: WaveHouse rents “SmartHouses” in France &#8230;</h2>
<figure id="post-14160 media-14160" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14160 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7.png" alt="" width="1246" height="566" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7.png 1246w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-420x191.png 420w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-768x349.png 768w" sizes="auto, (max-width: 1246px) 100vw, 1246px" /></figure>
<p>Here is the general architecture of the PoC:</p>
<p>&nbsp;</p>
<figure id="post-14162 media-14162" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14162 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8.png" alt="" width="1326" height="831" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8.png 1326w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-305x191.png 305w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-768x481.png 768w" sizes="auto, (max-width: 1326px) 100vw, 1326px" /></figure>
<p style="text-align: center;">Figure 7 &#8211; The general architecture of the PoC</p>
<p>&nbsp;</p>
<p style="text-align: justify;">As one can see, the digital lock (represented by the RFID card reader, the Raspberry Pi microcontroller and the servomotor) interacts with Azure IoTHub as well to facilitate the management of its firmware updates.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">The main use cases studied by Wavestone and Jitsuin</h2>
<p>The main use cases studied by Wavestone and Jitsuin are explained in the video below:</p>
<p><div style="width: 640px;" class="wp-video"><video class="wp-video-shortcode" id="video-14147-1" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4?_=1" /><a href="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4">https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4</a></video></div></p>
<p>&nbsp;</p>
<h2>Conclusion</h2>
<p style="text-align: justify;">Wavestone and Jitsuin were able to demonstrate &#8211; with the different use cases illustrated above in the video &#8211; how to improve the security of connected devices:</p>
<ul style="text-align: justify;">
<li>First of all, all of the people involved in the life cycle of the digital lock of the “SmartHouse” had access to its &#8220;Security Twin&#8221;. Indeed, each of them had access to a decentralized and unchangeable register provided by “Jitsuin Archivist” with all the information regarding the security of the digital lock.</li>
<li>Then, as mentioned above, this architecture is &#8220;secure by design&#8221; because as “Jitsuin Archivist” is based on Distributed Ledger Technology (DLT), one has a technical guarantee on the non-compromising of data.</li>
<li>The &#8220;Security Twin&#8221; of the digital lock ensured physical security since it had the rights management information, allowing all the people involved to know who had access to the &#8220;SmartHouse&#8221;.</li>
<li>Finally, since the “Security Twin” also had firmware information, the different people involved could easily know which connected devices had vulnerabilities and quickly plan the distribution of security patches.</li>
</ul>
<p style="text-align: justify;">The &#8220;Security Twins&#8221; would therefore ultimately improve the security of the connected devices, since it would be easy to know which objects are secure and which are not.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/</link>
		
		<dc:creator><![CDATA[Raquel De Faria Cristas]]></dc:creator>
		<pubDate>Fri, 24 Jul 2020 12:55:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[connected device]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13959</guid>

					<description><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 20201. Even if...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 2020<sup>1</sup>. Even if the market is not as developed as it was first predicted, it is still growing: those 5.8 billion of IoT devices represent <strong>an increase of 21%</strong> over 2019.</p>
<p>Despite their usefulness, introducing connected devices unfortunately brings <strong>new risks</strong> for companies. Indeed, according to the Palo Alto Networks report<sup>2</sup> published in March 2020, <strong>57% of the connected devices analyzed were vulnerable to medium or high severity attacks</strong>. This is not surprising. Securing connected devices is proving to be an arduous task that explains why Beecham Research<sup>3</sup> finds 62% of Industrial IoT transformations fail to scale because of a lack of trust.</p>
<p>Therefore, with this article we will try to ask ourselves about the security and trust issues of connected devices and how companies can deal with them.</p>
<p>&nbsp;</p>
<h2>What are the security and trust issues of connected devices?</h2>
<p style="text-align: justify;">In order to mitigate the security risks on connected devices, NIST recommends in its report<sup>4</sup> published in 2019 to focus on 6 main areas:</p>
<ul>
<li style="text-align: justify;"><strong>Inventory</strong>: Maintain an accurate inventory of all connected devices and their most relevant characteristics throughout their lifecycle (<a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">see the article</a> detailing the lifecycle of connected devices).</li>
</ul>
<p>&nbsp;</p>
<figure id="post-13960 media-13960" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13960 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png" alt="" width="1479" height="755" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png 1479w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-768x392.png 768w" sizes="auto, (max-width: 1479px) 100vw, 1479px" /></figure>
<p style="text-align: center;">Figure 1 &#8211; Connected device lifecycle</p>
<ul>
<li style="text-align: justify;"><strong>Vulnerabilities</strong>: Identify and eliminate known vulnerabilities in the software and firmware of connected devices to reduce the likelihood and ease of exploitation and compromise.</li>
<li style="text-align: justify;"><strong>Access</strong>: Prevent unauthorized and inappropriate physical and logical access, use and administration of connected devices by people, processes and other computing devices.</li>
<li style="text-align: justify;"><strong>Detect security incidents of connected devices</strong>: Monitor and analyze connected device activity for signs of incidents involving the security of the device.</li>
<li style="text-align: justify;"><strong>Detect data security incidents</strong>: Monitor and analyze the activity of the connected device for signs of data security incidents.</li>
<li style="text-align: justify;"><strong>Protect data</strong>: Prevent access and alteration of data that could expose sensitive information or allow manipulation or disruption of the operation of connected devices.</li>
</ul>
<p style="text-align: justify;">However, current IoT platforms only partially meet these security requirements (<a href="https://www.wavestone.com/en/insight/iot-platforms-cornerstone-successful-iot-strategy/">see the article</a> detailing the usefulness of IoT platforms).</p>
<p>&nbsp;</p>
<p id="post-13962 media-13962" class="align-none" style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-13962 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png" alt="" width="1073" height="329" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png 1073w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-437x134.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-71x22.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-768x235.png 768w" sizes="auto, (max-width: 1073px) 100vw, 1073px" />Figure 2 &#8211; The usefulness of IoT platforms</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Indeed, traditional IoT architectures rely on a <strong>centralized cloud platform</strong>, operated by a third-party company and where most often the rules for data collection and storage are opaque. <strong>This is not the best solution to ensure the security of connected devices since</strong>:</p>
<ul>
<li>The use of a centralized cloud platform introduces the risk of &#8220;<strong>single point of failure</strong>&#8221; on the <strong>IoT architecture</strong> (although today this risk is mitigated with the implementation of a redundant architecture and backups).</li>
<li>It is entirely possible for an attacker to <strong>change the data stored in the cloud database</strong>. The decision making of the different stakeholders is therefore impacted.</li>
<li><strong>Collaboration</strong> between the different stakeholders of the IoT deployment (manufacturers, maintenance operators, &#8230;) becomes more <strong>difficult</strong> because access to the platform can be restricted to them.</li>
</ul>
<p style="text-align: justify;">The use of a <strong>decentralized management system</strong> for connected devices where all stakeholders would have the possibility to <strong>reliably consult or contribute information</strong> regarding connected devices (firmware version, maintenance operations, etc.) becomes essential to guarantee the security of those devices and the integrity of data they produce.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">How do &#8220;Security Twins&#8221; help meet the security challenges of connected devices?</h2>
<p>In order to support IoT platforms and improve the security of IoT deployments, the notion of  <strong>&#8220;Security Twin&#8221; should be introduced in IoT deployments.</strong></p>
<p>The principle of a &#8220;Security Twin&#8221; is simple. It is a <strong>virtual representation</strong> of the connected device that <strong>contains all its security information</strong>, such as firmware version, vulnerabilities, etc. upon which all stakeholders involved in its upkeep can reach consensus (see figure 3).</p>
<p>&nbsp;</p>
<figure id="post-13966 media-13966" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13966 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png" alt="" width="1012" height="459" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-421x191.png 421w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-768x348.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-730x330.png 730w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p style="text-align: center;">Figure 3 &#8211; The &#8220;Security Twin&#8221; mechanism (from: Jitsuin)</p>
<p>&nbsp;</p>
<p>A &#8220;Security Twin&#8221; gains effectiveness when more <strong>stakeholders</strong> of the deployment <strong>can interact with it</strong> and reach consensus that the<strong> information provided/recorded is correct</strong>.</p>
<p>Therefore, solutions based on <strong>Distributed Ledger Technology (DLT)</strong> represent a logical first step in the creation of Security Twins, as they would allow the security information of the connected device to be gathered in <strong>a decentralized and immutable registry</strong> that would be accessible by all authorized stakeholders in the IoT deployment. The best well known distributed registry solution is the Blockchain (<a href="https://www.wavestone.com/en/insight/blockchain-practice/">see the article</a> on Blockchain’s uses and limitations).</p>
<p>Taking up the points raised earlier in the NIST report, one could say that the use of a &#8220;Security Twin&#8221; would therefore improve:</p>
<ul>
<li><strong>Device and access management</strong>: all stakeholders of the IoT deployment would have access to a decentralized and immutable register of all the connected devices with the corresponding security and trust information.</li>
<li><strong>Vulnerability management and the detection of device security incidents</strong>: the different stakeholders could share device security information and take the necessary actions (e.g. the manufacturer of a connected device could notify the other stakeholders of the availability of a new firmware update thanks to the &#8220;Security Twin&#8221;).</li>
<li><strong>Data protection and the detection of data related security incidents</strong>: The very foundation of a &#8220;Security Twin&#8221; is based on the use of a decentralized and immutable register to record data related to the security of connected devices. This makes it more difficult for attackers to change the data, which reduces the risk of a security incident.</li>
</ul>
<p>The use of &#8220;Security Twins&#8221; therefore offers the possibility of strengthening the security, integrity, trust and resilience of connected devices.</p>
<p>The start-up Jitsuin has developed &#8220;Jitsuin Archivist&#8221; a tool based on Distributed Ledger Technology (DLT) to overcome the lack of collaborative tools to secure connected devices. The purpose of this tool is not to replace IoT platforms but to allow the creation of &#8220;Security Twins&#8221;.</p>
<p>Together, Wavestone and <a href="https://jitsuin.com/">Jitsuin</a> sought to demonstrate the benefits of using a decentralized architecture with “Security Twins”. The two companies have therefore collaborated on the construction of a PoC (Proof of Concept) to tackle identity and access management of buildings using connected devices, which will be introduced in a future article.</p>
<p>&nbsp;</p>
<p>1 Gartner, 29th August 2019 : https://www.gartner.com/en/newsroom/press-releases/2019-08-29-gartner-says-5-8-billion-enterprise-and-automotive-io<br />
2 Palo Alto Networks, 10th March 2020, “Unit 42 IoT threat report”: https://unit42.paloaltonetworks.com/iot-threat-report-2020/<br />
3 Why IoT projects fail https://www.whyiotprojectsfail.com/?cs=br2<br />
4 NIST – “Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks” : https://csrc.nist.gov/publications/detail/nistir/8228/final</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IAM of Things, un marché émergeant mais un besoin déjà présent</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/</link>
		
		<dc:creator><![CDATA[Kévin Guérin]]></dc:creator>
		<pubDate>Mon, 17 Feb 2020 13:28:16 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[IoT & smart products]]></category>
		<category><![CDATA[CIAM]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAMoT]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[SI]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12648</guid>

					<description><![CDATA[<p>Dans un précédent article, nous avons pu découvrir l’IAM of Things (IAMoT) et souligner les très fortes interactions avec les domaines de l’IAM et du Customer IAM (CIAM). Dans ce nouvel article, nous allons maintenant mettre en évidence les lacunes...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/">IAM of Things, un marché émergeant mais un besoin déjà présent</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Dans <a href="https://www.riskinsight-wavestone.com/en/2019/01/what-is-iam-of-things/">un précédent article</a>, nous avons pu découvrir l’IAM <em>of Things</em> (IAMoT) et souligner les très fortes interactions avec les domaines de l’IAM et du <em>Customer</em> IAM (CIAM). Dans ce nouvel article, nous allons maintenant mettre en évidence les lacunes actuelles du marché à couvrir les besoins de l’IAMoT.</p>
<p>&nbsp;</p>
<h2>Quels besoins pour l’IAMoT ?</h2>
<p>Il est possible de définir l’IAM comme une discipline permettant de « <strong>donner les bons droits, aux bonnes personnes, aux bons moments</strong> ». L’IAMoT vient ajouter une composante à cette définition pour permettre de « donner les bons droits, <strong>aux bonnes personnes et aux bons objets</strong>, aux bons moments ».</p>
<p>Mettre en œuvre des solutions pour permettre une gestion adaptée des identités des objets connectés se traduit donc par le besoin de prendre en compte :</p>
<ul>
<li>La gestion des identités des objets et de leur état (<a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">voir l’article</a> détaillant le cycle de vie des objets) ;</li>
<li>La gestion du contrôle d’accès et des habilitations :
<ul>
<li>des objets sur le SI et sur ses données ;</li>
<li>des objets sur les autres objets et leurs données ;</li>
<li>des employés/partenaires de l’entreprise sur l’objet et ses données ;</li>
<li>des clients finaux sur l’objet et ses données ;</li>
</ul>
</li>
<li>La gouvernance des identités des objets et la pertinence des droits associés dans le temps.</li>
</ul>
<p>Tout comme pour l’IAM, pour chacun de ces domaines, il va être nécessaire de définir des processus, une organisation associée et des outils adaptés aux contraintes technologiques du projet.</p>
<p>La question est donc maintenant : vers quelles solutions s’orienter pour répondre à mes besoins ?</p>
<p>&nbsp;</p>
<h2>Des plates-formes IoT orientées connectivité et gestion de flotte</h2>
<p>Le premier réflexe est de se tourner vers les services que peuvent fournir les plates-formes de gestion d’objets connectés.</p>
<p>En étudiant ces plates-formes plus en détail, nous avons fait le constat que leur priorité est déjà de couvrir les services essentiels pour la gestion de la flotte des objets connectés :</p>
<ul>
<li>gérer la connectivité multi-protocolaire des objets avec le SI de l’entreprise (SigFox, LoRa, 3/4/5G…) ;</li>
<li>maîtriser l’inventaire des objets déployés et en assurer la configuration ou la mise à jour via un module de « Device Management » (LWM2M, OMA-DM, TR-069/CWMP…) ;</li>
<li>permettre la remontée et la mise à disposition des données générées par l’objets (DTLS, CoAP, MQTT, AMQP…).</li>
</ul>
<p>Ces fonctions s’accompagnent de solutions techniques d’authentification de l’objet sur les plates-formes mais celle-ci n’offrent aucune opportunité de couverture des besoins métier.</p>
<p>Dans ce cas, que font les acteurs traditionnels de l’IAM et du CIAM ? Puis-je me tourner vers leurs solutions qui sont aujourd’hui orientées sur la couverture des besoins des utilisateurs ?</p>
<p>&nbsp;</p>
<h2>Des marchés IAM et CIAM en mutation pour couvrir une infime partie du besoin IoT</h2>
<p>Les éditeurs historiques de solutions IAM et CIAM ont compris l’énorme opportunité que représente l’IAMoT et orientent progressivement leurs offres et le discours associé sur ce marché. Néanmoins, nous constatons qu’ils ne couvrent encore que très partiellement les besoins identifiés ci-dessus et que selon leur capacité à innover le délai de mise en œuvre des nouveautés pourra être important.</p>
<p>Forts de leurs savoir-faire technologiques, ils se concentrent aujourd’hui quasi-exclusivement sur le volet contrôle d’accès. Ils offrent ainsi des solutions pertinentes pour permettre l’authentification applicative des objets sur le SI et la délivrance de jetons d’autorisation dont la gestion du contenu relève encore d’un défi propre à chaque projet. Sur les autres volets de l’IAMoT tels que la gestion de l’identité et de l’état des objets, la gestion du modèle de rôles liant objets / utilisateurs / identités internes / identités externes, ou la gouvernance des droits dans le temps, il est urgent que leur offre s’étoffe.</p>
<p>Dès lors, comment peut-on couvrir des besoins IAMoT bien présents malgré les lacunes du marché ?</p>
<p>&nbsp;</p>
<h2>Une hétérogénéité des usages rendant complexe la normalisation des pratiques et la standardisation des solutions</h2>
<p>La diversité des usages et donc des modes de fonctionnement des objets connectés est évidemment à l’origine de la difficulté des éditeurs à proposer une offre générique adaptée à ses clients. Mais les projets IoT sont là et il n’est pas envisageable d’attendre que le marché prenne forme.</p>
<p>Mais si l’harmonisation est actuellement impossible au niveau global du marché, un effort peut être consenti au niveau de l’entreprise afin d’essayer d’harmoniser les réponses pour l’ensemble de ses usages IoT. Ainsi tout en cherchant à tirer parti de ce que propose le marché IAMoT, il est nécessaire d’envisager le développement modulaire des briques manquantes et en priorité celles ayant trait à la gestion des relations « objets / utilisateurs / identités internes / identités externes ». Attention toutefois à ne pas succomber aveuglement à l’utilisation des <em>frameworks</em> bas-niveau propriétaires proposés par les plates-formes IoT. Chacun devra être vigilant à conserver un niveau d’abstraction et d&#8217;autonomie suffisant pour ne pas être lié <em>ad vitam æternam</em> à un éditeur unique. Ce point d’attention est d’autant plus important dans un marché peu mature et en explosion où les bonnes idées se font et se défont.</p>
<p>&nbsp;</p>
<h2>Que faut-il retenir ?</h2>
<p>Aucune solution du marché ne couvre l’intégralité des besoins fondamentaux de l’<em>IAM of Things</em>. Les plates-formes IoT se limitent aux fonctions de connectivité des objets, de gestion de flotte et de remontée de données. Les plates-formes IAM et CIAM n’offrent quant à elles que des réponses technologiques aux besoins d’authentification et d’autorisation.</p>
<p>Afin de combler les manques, chaque entreprise devra évaluer le besoin de se lancer dans le développement de ses propres modules applicatifs. Un effort tout particulier devra être entrepris pour atteindre un niveau adapté de généricité des modules pour l’ensemble de leurs usages et d’indépendance vis-à-vis des solutions éditeur.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/">IAM of Things, un marché émergeant mais un besoin déjà présent</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A life cycle approach for IoT security</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/</link>
		
		<dc:creator><![CDATA[Kévin Guérin]]></dc:creator>
		<pubDate>Tue, 17 Sep 2019 20:59:03 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[Life cycle]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12089</guid>

					<description><![CDATA[<p>As with employee or customer identity management, the life cycle approach of connected objects within the Internet of Things (IoT) makes it possible to address all security issues. This article presents the key elements of this methodology and the major...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">A life cycle approach for IoT security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As with employee or customer identity management, the life cycle approach of connected objects within the Internet of Things (IoT) makes it possible to address all security issues. This article presents the key elements of this methodology and the major points to be addressed at each event in the life of a connected object.</p>
<h2>What are the risks in the iot world?</h2>
<p>The IoT advent has enabled millions of new potential technological advantages for consumers and companies. However, with <strong>these new advantages</strong>, certain risks are higher in the field of connected devices.</p>
<p>&nbsp;</p>
<figure id="post-12098 media-12098" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-12098 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1.png" alt="" width="1441" height="977" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1.png 1441w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-282x191.png 282w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-768x521.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-58x39.png 58w" sizes="auto, (max-width: 1441px) 100vw, 1441px" /></figure>
<p style="text-align: center;"><em>Figure 1 – Most significant risks in the IoT world</em></p>
<p>&nbsp;</p>
<p>These business and technological risks which could cause significant potential impacts for consumers and companies, should be identified <strong>from the upstream phases of an IoT project.</strong></p>
<p>&nbsp;</p>
<h2>Which project methodology to choose in order to ensure security of connected devices?</h2>
<p>Even though security issues to address in IoT project are common for all project, we think necessary <strong>to structure reflections regarding the life cycle of the connected device</strong>.</p>
<p>The diagram below highlights all the stages of their life cycle.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12096 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2.png" alt="" width="1479" height="755" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2.png 1479w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-768x392.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-71x36.png 71w" sizes="auto, (max-width: 1479px) 100vw, 1479px" /></p>
<p style="text-align: center;"><em>Figure 2- A life cycle enabling to address all the security issues</em></p>
<p>&nbsp;</p>
<p>Let us review  some important issues raised by this approach:</p>
<ol>
<li><strong>Design, manufacturing, and distribution phases</strong></li>
</ol>
<p>This first phase addresses issues related to the design of the object, regarding business stakes, targeted users (B2B, B2C, B2E), deployment environment (controlled or not) and criticality of the use:</p>
<ul>
<li>What are the regulatory constraints related to the use of the object?</li>
<li>What identity should be labeled and how is this identity created?</li>
<li>How is the security related to object’s hardware and software secrets and data stored in the object?</li>
<li>How is the state of a device on the management platform initialized, ensuring it has no right on the IS before the initialization step?</li>
</ul>
<p>The determined choices during the manufacturing phases are crucial because they determine characteristics and capacities of the device. Some of them will therefore be immutable throughout the life of the device and will impose strong constraints in the following steps.</p>
<p>Furthermore, although the end of the manufacturing phase marks the beginning of the existence of the device on the device management platform, there is still no reason to consider an interaction with the IS.</p>
<p>Any interaction before the device’s association to a user (physical or moral) would mean that it has been diverted in the distribution phase. <strong>Any access to the IS before the initialization phase must be strictly limited</strong> to the firmware update (version N installed at the factory and version N+1 available when unpacking) or to the pre-customization of the object (operating settings or injection of secrets not related to the user). Beyond IS security, an object that is unused before any pairing phase will reduce the risk of theft of that object in the factory or during distribution<em>.</em></p>
<ol start="2">
<li><strong>Initialization phase</strong></li>
</ol>
<p>Initialization phase materializes the association phase (also named pairing) between a device and its owner. Any data generated by the device (or realized action) is then declared as belonging or attributed to its owner..</p>
<p>Therefore, the main challenge is to <strong>ensure a reliable level of user / object association corresponding to the following business stakes:</strong></p>
<ul>
<li>Low level of association required (low-risk situation): An employee declares the usage of an attendance identification system in the meeting room;</li>
<li>Strong level of association required (high-risk situation): when purchasing a connected lock, a consumer provides a serial number and a one-time secret code to allow his mobile application to unlock the door of his home.</li>
</ul>
<p>It is very important to find a balance between the user experience and security.</p>
<p>The robustness of the expected association will <strong>vary according to the nature of the services to which the customer has subscribed.</strong></p>
<ol start="3">
<li><strong>Use phase</strong></li>
</ol>
<p>The definition of the use cases of connected devices is the most anticipated step by companies, however <strong>many aspects of security remain neglected</strong>.</p>
<p>Besides business use cases, additional questions must be raised:</p>
<ul>
<li>How can regular updates of the connected device be implemented?</li>
<li>What are the different actors of the company roles regarding the maintenance of the device operating system layer: the application layer, and the network module?</li>
<li>What is the detection and response requirements for a compromised device?</li>
<li>How to take advantage of the company SIEM (<strong><em>S</em></strong><em>ecurity <strong>I</strong>nformation and <strong>E</strong>vent <strong>M</strong>anagement</em>) and SOC (<strong><em>S</em></strong><em>ecurity <strong>O</strong>peration <strong>C</strong>enter</em>) for technical security incidents (software compromise of the device) and for business security incidents (misuse or theft of a device)?</li>
<li>How can backward compatibility of protocols and APIs used by different versions of the same type of device be maintained?</li>
<li>What are the models of roles and interactions between different populations acting on the object?</li>
</ul>
<p>Concerning this last question, and as an example, the scheme below illustrates the potential complexity stemming from the interactions and roles model such as a connected vehicle.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12094 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3.png" alt="" width="1464" height="725" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3.png 1464w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-386x191.png 386w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-768x380.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-71x35.png 71w" sizes="auto, (max-width: 1464px) 100vw, 1464px" /></p>
<p style="text-align: center;"><em>Figure 3- Example of a roles and interactions model with a connected vehicle (research carried out with IMT Atlantique)</em></p>
<p>&nbsp;</p>
<ol start="4">
<li><strong>Resale phase</strong></li>
</ol>
<p>Today, the resale is <strong>the most neglected</strong> phase during the device design. This event essentially concerns devices for B2C markets and raises very specific issues:</p>
<ul>
<li>How to detect and handle the resale of a device between individuals?</li>
<li>What privacy-by-design principles should be implemented to protect secrets and data from the former owner while resetting a device?</li>
<li>How can access rights of the former owner of the device be removed?</li>
<li>What are the ways to reset a device in a stable and clean state before re-pairing?</li>
</ul>
<p>The major difficulty involves <strong>the detection of the resale event</strong> which triggers the device/user unpairing processes, reset the state of the object, etc.</p>
<p>Our experience allows us to identify some circumstances that could indicate a change of ownership.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12092 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4.png" alt="" width="1463" height="509" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4.png 1463w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-437x152.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-768x267.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-71x25.png 71w" sizes="auto, (max-width: 1463px) 100vw, 1463px" /></p>
<p style="text-align: center;"><em>Figure 4 – Examples of events that could indicate the change of ownership</em></p>
<p>&nbsp;</p>
<p>Despite such examples, we witness that resale remains a complex event to identify. Thus, some companies choose <strong>not to authorize the device resale</strong> via a lease contract. The device must therefore be returned when the service is terminated; otherwise it must be made unusable. This model is comparable to renting an Internet box with an ISP (<strong>I</strong>nternet <strong>S</strong>ervice <strong>P</strong>rovider).</p>
<ol start="5">
<li><strong>End-of-life and recycling</strong></li>
</ol>
<p>Although<strong> essential</strong>, we currently have little perspective on this step, however there are multiple stakes:</p>
<ul>
<li>Revoke access rights on the Information System of an end-of-life device;</li>
<li>Renew the identity of a recycled device;</li>
<li>Ensure the replacement of a defective object by re-associating a new one with the same owner and the same data;</li>
<li>Detect the inactivity of a device to trigger a replacement.</li>
</ul>
<p>The main risks are <strong>the loss of access control over the company IS</strong> via identifiers associated with recycled devices, <strong>the disclosure of personal data</strong> of the former owner or <strong>the additional cost of license</strong> for data generated by devices considered out of the scope.</p>
<p>&nbsp;</p>
<h2>A variable capacity of action in response to the risks according to the nature of the project</h2>
<p>At this stage of your reading, you probably think that this article is not your concern because you purchase pre-conceived connected modules or devices.</p>
<p>Unfortunately this mindset is wrong –  you are still exposed to the same risks! Even though you only purchase or welcome connected devices in your IS, by addressing all the issues above you will be able to feed the contents of requirement specifications to suppliers.</p>
<p>To conclude, <strong>whatever the nature of your IoT project</strong>, it is essential to design your object by structuring the reflections around its life cycle: from its manufacturing to its disposal. It is therefore necessary, at each stage, to address all the relevant security themes: Network / application / hardware security, standards, detection and reaction, governance, maintenance in security condition&#8230;</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12090 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5.png" alt="" width="807" height="589" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5.png 807w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-262x191.png 262w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-768x561.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-53x39.png 53w" sizes="auto, (max-width: 807px) 100vw, 807px" /></p>
<p style="text-align: center;"><em>Figure 5 – Main security themes for an IoT project</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">A life cycle approach for IoT security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>L’INTERVIEW D’ICARE TECHNOLOGIES – LA BAGUE INTELLIGENTE SECURISEE</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/08/interview-icare-technologies-bague-intelligente-securisee/</link>
		
		<dc:creator><![CDATA[Gabriel Amirault]]></dc:creator>
		<pubDate>Tue, 07 Aug 2018 16:09:09 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & smart products]]></category>
		<category><![CDATA[Banque]]></category>
		<category><![CDATA[BCSIA]]></category>
		<category><![CDATA[CIAM]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity & access management]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IoT & consumer goods]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11164/</guid>

					<description><![CDATA[<p>Dans le cadre des Banking CyberSecurity Innovation Awards, ICARE Technologie a reçu le prix spécial France pour sa bague intelligente. Celle-ci, couplée à une application smartphone, permet au porteur de la programmer pour remplacer l’intégralité du portefeuille et du porte-clefs....</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/interview-icare-technologies-bague-intelligente-securisee/">L’INTERVIEW D’ICARE TECHNOLOGIES – LA BAGUE INTELLIGENTE SECURISEE</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Dans le cadre des Banking CyberSecurity Innovation Awards, <strong>ICARE Technologie</strong> a reçu le <strong>prix spécial France</strong> pour sa bague intelligente. Celle-ci, couplée à une application smartphone, permet au porteur de la programmer pour remplacer l’intégralité du portefeuille et du porte-clefs. Voici l’interview de son représentant, Georges Bote qui détaille pour nous comment sa solution contribue à la cybersécurité de la banque de demain.</em></p>
<h2>Comment l&#8217;idée vous est-elle venue ?</h2>
<p><strong>Georges Bote (ICARE Technologies)</strong> raconte que l&#8217;idée est venue au fondateur, Jérémy Neyrou <em>« il y a 6 ans de cela, en perdant mes clés de voiture sur une plage Corse complètement déconnectée de tout réseau, après avoir parcouru près d&#8217;une dizaine de kilomètres en plein soleil d&#8217;été à pied »</em>, il imagine un « <em>objet à la fois intuitif et autonome qui permettrait d&#8217;embarquer [le] trousseau de clés et [les] moyens de paiement</em> ». C&#8217;est ainsi qu&#8217;est née Aeklys, « <em>cette bague intelligente qui permet d&#8217;embarquer jusqu&#8217;à 28 fonctionnalités différentes</em> ».</p>
<h2>Quel est le plus grand risque de sécurité pour les banques et pour ses clients selon vous ? Comment répondez-vous à la menace qui pèse sur les banques ?</h2>
<p><strong>Georges Bote (ICARE Technologies)</strong> s&#8217;accorde également à dire que « <em>la fraude à la fois bancaire et sur l&#8217;identité des personnes reste le grand risque pour les banques et leurs clients</em> ». C&#8217;est pourquoi la bague connectée proposée par ICARE Technologies embarque un mécanisme de désactivation en cas de perte ou de vol, protégeant ainsi son propriétaire contre l&#8217;usurpation de ses moyens de paiement sans qu&#8217;il ne doive faire opposition d&#8217;une quelconque manière que ce soit.</p>
<h2>L&#8217;enjeu pour les RSSI aujourd&#8217;hui est de parvenir à concilier la facilité d&#8217;implémentation, la simplicité d&#8217;utilisation des solutions de sécurité avec une technologie sécurisée. Comment convaincre un RSSI de la pertinence de votre solution et de la sécurité du produit ? Quels sont les différenciateurs qui vous démarquent sur le marché ?</h2>
<p><strong>ICARE Technologies</strong> explique que la pertinence de la sécurité de sa solution « <em>réside dans notre technique et différentes certifications bancaires. Notre secure element dispose d&#8217;un niveau EAL6+ certifié par l&#8217;ANSSI, ce qui nous permet de travailler dans le domaine militaire en plus d&#8217;avoir un chiffrement en AES 256 bits </em>».</p>
<h2>Quelles sont les synergies entre votre innovation et les solutions de sécurité bancaires existantes à l&#8217;heure actuelle ?</h2>
<p>La force du produit d&#8217;<strong>ICARE Technologies</strong> réside dans son innovation et en sa sécurité : « <em>de plus, il caractérise une nouvelle forme de liberté et de sécurité qui est fortement attractive pour les clients potentiels. L’intérêt est donc d’en faire devenir un objet « à la mode » de manière à orienter la connotation sociale de la bague comme une tendance</em> ».</p>
<p>Les synergies existent et la technologie est actuellement en phase de test avec des partenaires bancaires et industriels pour travailler notamment sur la sécurisation de valises informatiques. Georges Bote annonce <strong>« </strong><em>la préparation d&#8217;un 2ème tour de table et de belles surprises pour notre Go To Market qui sera prévu le 1er trimestre 2019 </em>».</p>
<p>Pour en savoir plus : <a href="https://fr.icaretechnologies.com/">https://fr.icaretechnologies.com/</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/interview-icare-technologies-bague-intelligente-securisee/">L’INTERVIEW D’ICARE TECHNOLOGIES – LA BAGUE INTELLIGENTE SECURISEE</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Objets connectés : les 4 dimensions de la sécurité</title>
		<link>https://www.riskinsight-wavestone.com/en/2016/11/objets-connectes-4-dimensions-de-securite/</link>
		
		<dc:creator><![CDATA[Chadi Hantouche]]></dc:creator>
		<pubDate>Wed, 30 Nov 2016 09:42:59 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & smart products]]></category>
		<category><![CDATA[CARA]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IoT & consumer goods]]></category>
		<category><![CDATA[transformation numérique]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9323</guid>

					<description><![CDATA[<p>Comme toute révolution technologique, la transformation numérique impacte de nombreux domaines de l’économie : la domotique, la sécurité physique, la mobilité, la santé, etc. L’Internet des Objets (IoT en anglais) joue un rôle important dans cette ten­dance, avec l’émergence de nombreux...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/11/objets-connectes-4-dimensions-de-securite/">Objets connectés : les 4 dimensions de la sécurité</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Comme toute révolution technologique, la transformation numérique impacte de nombreux domaines de l’économie : la domotique, la sécurité physique, la mobilité, la santé, etc. L’Internet des Objets (IoT en anglais) joue un rôle important dans cette ten­dance, avec l’émergence de nombreux objets connectés. Les chiffres sont en effet significatifs : de nombreux analystes considèrent qu’il y aura entre 20 et 200 milliards d’objets connectés d’ici 2020.  </em></p>
<p>&nbsp;</p>
<h2> <strong>AU COEUR DE LA TRANSFORMATION NUMÉRIQUE</strong></h2>
<p>Aucune industrie ne peut aujourd’hui ignorer cette tendance et les entreprises voient un intérêt grandissant à s’emparer de ce qu’elles perçoivent comme une véritable opportunité.</p>
<p>Alors que des start-ups conçoivent chaque jour des dispositifs intelligents, des partenariats se mettent en place entre les vendeurs et les industries traditionnelles – tels les secteurs de l’assurance, automobile, administratif, bancaire – afin d’offrir de nouveaux services aux consommateurs grâce à divers éléments connectés.</p>
<p>&nbsp;</p>
<h2><strong>UNE SURFACE D’ATTAQUE DE PLUS EN PLUS EN PLUS VASTE POUR LES CYBERCRIMINELS</strong></h2>
<p>L’essor de cet Internet des Objets n’est pas sans danger, d’autant plus que les risques, qui étaient surtout virtuels, s’étendent au domaine du physique.</p>
<p>Une <a href="http://www8.hp.com/us/en/hp-news/press-release.html?id=1744676#.WD6bZ_nhA2w">étude frappante</a> a été menée par HP Fortify en 2014, mettant en avant un constat sans appel : en testant la sécurité des 10 des objets connectés les plus en vogue du moment, une moyenne de 25 vulnérabilités par objet a été trouvée. La plupart d’entre elles sont liées à des problèmes de sécurité basiques, tels que la <strong>mauvaise gestion de la confidentialité des données et des droits d’accès</strong>, <strong>l’absence de chiffrement des flux</strong>, <strong>une interface d’adminis­tration Web non sécurisée</strong>, ou encore <strong>une protection générale inadaptée</strong>. <a href="http://www8.hp.com/us/en/hp-news/press-release.html?id=2037386#.WD6boPnhA2w">La suite de cette étude en 2015</a> a également montré que les 10 smartwatchs et les 10 systèmes de sécurité pour les particuliers les plus vendus présentaient tous des vulnérabilités majeures concernant la confidentialité des données de l&#8217;utilisateur.</p>
<p>Ce manque de durcissement augmente le risque de vulnérabilités pouvant affecter toute sorte d’objets : des réfrigérateurs aux toilettes connectées, en passant par les <a href="https://www.riskinsight-wavestone.com/en/2017/06/cyber-crash-tests-security-solution-driverless-cars/">voi­tures </a>et les serrures. L&#8217;actualité des derniers mois en est la preuve avec par exemple l&#8217;<a href="http://searchsecurity.techtarget.com/news/450401962/Details-emerging-on-Dyn-DNS-DDoS-attack-Mirai-IoT-botnet">attaque DDoS sur le DNS Dyn</a> avec le botnet Mirai en octobre 2016 ou <a href="https://www.wired.com/2016/09/security-news-week-hackers-take-control-moving-teslas-brakes/">la prise de contrôle à distance d&#8217;une Tesla</a> par une équipe de hackers chinois en septembre 2016.</p>
<p>&nbsp;</p>
<h2><strong>DANS QUELLE CATÉGORIE DE RISQUES VOUS SITUEZ-VOUS ?</strong></h2>
<p>En ce qui concernent les entreprises, les risques dépendent de la posture adoptée. Dans le cas des objets connectés, quatre cas sont possibles. Les différentes postures ont été réunies sous l’acronyme « <strong>CARA </strong>» (pour <strong>Concevoir</strong>, <strong>Acquérir</strong>, <strong>Recommander</strong>, <strong>Accueillir</strong>) comme le montre le tableau ci-dessous. Une fois la posture identifiée, il convient de spécifier les risques génériques et les recommandations associées.</p>
<p><img loading="lazy" decoding="async" class="wp-image-9324 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2016/11/CARA1.png" alt="CARA1" width="459" height="496" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2016/11/CARA1.png 720w, https://www.riskinsight-wavestone.com/wp-content/uploads/2016/11/CARA1-177x191.png 177w, https://www.riskinsight-wavestone.com/wp-content/uploads/2016/11/CARA1-36x39.png 36w" sizes="auto, (max-width: 459px) 100vw, 459px" /></p>
<p>Afin d’évaluer le risque, le cabinet Wavestone a développé un outil spécifique, la matrice « <strong>heat map</strong> ». Elle prend en compte deux dimensions : le niveau de risque et la posture.</p>
<p>&nbsp;</p>
<h2><strong>UN OUTIL D’ÉVALUATION EFFICACE : LA MATRICE « HEAT MAP »</strong></h2>
<p>Le schéma ci-dessous présente l’exemple concret de l’utilisation d’objets connectés pour le secteur bancaire et ses divers ser­vices. Ce contexte présente des contraintes particulières. D’un côté la réalisation d’une transaction financière est plus risquée que la consultation du solde bancaire. Mais d’un autre côté, la personnalisation des fonctions de sécurité sur un appareil appartenant à un employé ou à un client est bien plus compliqué que le durcissement d’un produit choisi par l’entreprise et qui a été acquis à un fournisseur, ou même développé en interne.</p>
<figure id="post-9324 media-9324" class="align-none">
<figure id="post-9325 media-9325" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-9325 " src="https://www.riskinsight-wavestone.com/wp-content/uploads/2016/11/CARA2.png" alt="CARA2" width="702" height="271" /></figure>
</figure>
<p>Cette matrice permet de réaliser une <strong>cartographie des risques</strong> qui requièrent la plus grande attention.</p>
<p>&nbsp;</p>
<h2><strong>DES DISPOSITIFS DE SÉCURITÉ HABITUELS : DE NOUVEAUX MODES D’IMPLÉMENTATION</strong></h2>
<p>Une fois la cartographie des risques établie, il faut s’intéresser aux réponses que l’on peut y apporter. Une référence intéressante à ce propos est celle de l’<a href="https://www.owasp.org/index.php/OWASP_Inter%ADnet_of_Things_Project">initiative « IoT Project » de l’OWASP</a> (Open Web Application Security Project – organisation à but non lucratif) qui propose notamment une liste de recommandations de sécurité intéressantes et compréhensibles.</p>
<p>La première chose à noter à propos de ce guide est qu’il est divisé en 3 catégories selon les cibles d’audience visées : fabri­cants, développeurs, consommateurs. Cette structure a du sens dans la mesure où <strong>la sécurité est partagée entre ceux qui conçoivent les composants </strong>(matériel ou logiciel), <strong>et ceux qui les utilisent</strong>.</p>
<p>Par ailleurs, les dispositifs de sécurité doivent être <strong>complets – renforçant non pas les seuls objets connectés, mais aussi toute la sur­face d’une attaque </strong>(physique, matériel, logiciel, base de données, local ou à distance, etc.). À cet égard, les mesures de sécurité proposées sont surtout construites sur les bonnes pratiques de l’industrie de la sécurité.</p>
<p>L’Internet des Objets apporte un réel changement dans la mise en œuvre des dispositifs de sécurité.</p>
<p>En effet, plusieurs contraintes liées aux objets connectés sont à prendre en compte :</p>
<ul>
<li><strong>Ergonomie</strong> : la taille et le design influenceront les mesures de sécurité acceptables par les utilisateurs – par exemple, la taille de l’écran pour taper un mot de passe.</li>
<li><strong>Puissance</strong> : les petits objets embarqués actuels ont une puissance de calcul limitée. Plusieurs opérations ne peuvent être réalisées en même temps dans un laps de temps raisonnable. Par exemple, Apple a conseillé aux développeurs de ne pas implémenter des fonctionnalités nécessitant de long temps d’exécution sur l’Apple Watch.</li>
<li><strong>Connectivité</strong> : l’Internet des Objets utilise généralement du Bluetooth ou des protocoles NFC, deux technologies ayant une portée et un débit limité, ce qui ne permet pas toujours d’embarquer un niveau de sécurité suffisant.</li>
<li><strong>Durée de vie de la batterie</strong> : les algo­rithmes cryptographiques (comme du chiffrement / déchiffrement asymé­trique en temps réel) peuvent affecter durement la consommation énergé­tique, même s’ils permettent de pro­curer un meilleur niveau de protection.</li>
<li><strong>Gestion des mises à jour</strong> : il est indis­pensable de mettre à jour le système, sans interférer avec l’utilisation de l’objet. Cela est particulièrement frap­pant dans le cas des voitures connec­tées que l’on ne peut pas conduire lorsque le logiciel est en train de se mettre à jour. Cela peut prendre plus de 45 minutes.</li>
</ul>
<p>&nbsp;</p>
<p>Au-delà de la sécurité, la confidentialité est également indispensable pour les consommateurs ainsi qu’une exigence pour les autorités. L’implémentation pourrait être complexe, mais plusieurs initiatives pour la confidentialité des objets connectés ont émergé ces dernières années.</p>
<p>Parmi ces initiatives, le projet <a href="https://www.preserve-project.eu/">PRESERVE </a>est un exemple intéressant. Il offre à l’industrie automobile un nouveau moyen d’utiliser les PKI et les certificats numériques pour les voitures et les routes connectées. Le projet utilise des « pseudonymes » modifiés régulièrement afin de garantir que le conducteur reste anonyme tout en assurant que les communications entre les véhicules et l’infrastructure routière sont authentiques et sécurisées.</p>
<p>Nous sommes entrés dans une ère où sécurité et confidentialité des données sont devenues des critères essentiels dans le choix des consommateurs. <strong>Cette évolution ne peut plus être ignorée par les acteurs concernés, qu’ils conçoivent, acquièrent, recommandent ou accueillent des objets connectés</strong>.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/11/objets-connectes-4-dimensions-de-securite/">Objets connectés : les 4 dimensions de la sécurité</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Des objets et des hommes</title>
		<link>https://www.riskinsight-wavestone.com/en/2014/01/des-objets-et-des-hommes/</link>
		
		<dc:creator><![CDATA[Bertrand Carlier]]></dc:creator>
		<pubDate>Thu, 09 Jan 2014 12:32:49 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & smart products]]></category>
		<category><![CDATA[Métiers - Marketing et relation client]]></category>
		<category><![CDATA[gestion des identités]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[identity & access management]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IoT & consumer goods]]></category>
		<category><![CDATA[système d'information]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=4840</guid>

					<description><![CDATA[<p>Nous assistons en ce moment même à un virage majeur dans la gestion des identités. Traditionnellement, les identités gérées par l’entreprise étaient des utilisateurs internes du SI de l’entreprise : employés et prestataires. Quelques centaines ou milliers d’utilisateurs dont il fallait...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/01/des-objets-et-des-hommes/">Des objets et des hommes</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Nous assistons en ce moment même à un virage majeur dans la gestion des identités. Traditionnellement, les identités gérées par l’entreprise étaient des utilisateurs internes du SI de l’entreprise : employés et prestataires. Quelques centaines ou milliers d’utilisateurs dont il fallait maîtriser le cycle de vie et les comptes dans le système d’information.</p>
<p>Et puis sont venus les partenaires externes et leurs employés. Dans le cas d’usage classique, un constructeur d’avion doit pouvoir collaborer avec l’ensemble de ses sous-traitants : il faut leur permettre l’accès aux applications, gérer ou faire gérer leurs comptes et leurs droits. La fédération des identités ainsi que ses standards et protocoles ont permis de répondre à cette problématique. La gestion des identités si elle devait prévoir de nouveaux processus n’a été que faiblement impactée (la volumétrie restait d’un ordre de grandeur comparable, les utilisateurs restaient des humains maîtrisés, etc.)</p>
<p>Aujourd’hui, un premier palier doit être franchi pour gérer une volumétrie beaucoup plus forte et des utilisateurs d’un nouveau type : les clients. Des centaines de milliers voire des millions d’identités. Il faut maintenant gérer l’identité d’un client et pouvoir l’authentifier et l’autoriser sur les applications mises à sa disposition. Il faut savoir l‘authentifier simplement de son point de vue (e.g. via un réseau social) et faire le lien avec son compte traditionnel dans le CRM pour gérer la relation. Les opérateurs télécoms et les banques et leurs bases clients sont devenues le nouveau cas d’usage classique : les accès aux applications via Internet et terminaux mobiles sont dans l’air du temps.</p>
<p>Au-delà de ce changement d’échelle, les caractéristiques de ces identités de clients sont différentes des traditionnelles identités de l’entreprise : le nombre d’applications accédées et de rôles est plus faible. Par ailleurs, plus question de devoir gérer des cas particuliers, tous les clients sont logés à la même enseigne et ce pour le plus grand bénéfice des projets IAM qui vont enfin voir se réduire fortement leur complexité fonctionnelle.</p>
<p>Enfin, un deuxième palier s’annonce déjà : la gestion des identités des objets connectés. Le CES 2014 qui s’achève ces jours-ci nous en offre de multiples illustrations : brosses à dent, cocottes minutes, lits, ampoules, etc. Tous les objets du quotidien sont désormais connectés. Par ailleurs, la complexité et les facultés de ces objets nous environnant sont telles aujourd’hui que de nouvelles approches sont nécessaires.</p>
<p><span style="font-size: 13px;">Les premiers objets connectés étaient de simples capteurs : température, pression, cellules infrarouge, compteurs, etc. Généralement non connectés directement à Internet, ils émettaient de l’information dans un protocole spécifique à destination d’une passerelle qui elle avait pour rôle de centraliser les données et de les transmettre via Internet à un serveur de traitement.</span></p>
<h2>Nouveaux usages et nouveaux besoins</h2>
<p>L’identification de ces objets est alors très sommaire, allant de la simple déclaration d’adresse MAC jusqu’à l’utilisation d’une clé de chiffrement des échanges pour les installations les plus sophistiquées.</p>
<p><img loading="lazy" decoding="async" class="wp-image-4845 alignright" title="des objets et des hommes" src="http://www.solucominsight.fr/wp-content/uploads/2014/01/des-objets-et-des-hommes.png" alt="" width="343" height="241" /></p>
<p>Les objets connectés sont maintenant non seulement émetteurs de données de plus en plus complexes mais également destinataires de commandes et d’action à réaliser, de correctifs et patches de sécurité, etc.</p>
<p>Dernier cas d’usage classique à la mode : la voiture connectée informe directement le constructeur ou le concessionnaire qu’un sous-composant est en mauvaise santé ou qu’une révision est nécessaire.</p>
<p>Ces objets doivent pouvoir être joints depuis n’importe où (et ne plus être masqués par une passerelle) et par ailleurs, les capacités d’attaques cybercriminelles ayant fortement augmentés ces dernières années, la sécurité des échanges et l’authentification préalable des objets est devenu un prérequis. Et nous voilà donc avec des milliers d’objets disposant d’une identité !</p>
<div>
<h2>Challenges</h2>
<p>Nous sommes maintenant face à des millions d’identités pour ne pas dire des milliards d’identités à gérer. Et soyons honnêtes un instant : pas un seul système de gestion des identités traditionnel ne sait traiter une telle volumétrie. C’est bien une toute nouvelle façon d’approcher la problématique de l’identité qui s’impose :</p>
<ul>
<li>Le cycle de vie de ces identités inclus désormais des notions comme la revente, le prêt, le partage entre plusieurs utilisateurs, etc. Il faut donc adapter leur modèle de relations avec leur environnement : utilisateur(s), entreprise, autres objets connectés, etc.</li>
<li>La sécurité passe par des moyens d’authentification à l’état de l’art mais également par des mécanismes de mise à jour robustes. Et il ne s’agit pas simplement de bien protéger l’objet lui-même, il faut également sécuriser les services qui les pilotent. Vous ne voudriez pas que votre brosse à dents change subitement et de manière incontrôlée sa vitesse de rotation n’est-ce pas ?</li>
</ul>
<p>Les outils de gestion d’identités traditionnels vont donc devoir évoluer très rapidement pour s’adapter à ces nouvelles identités, maîtriser leur imposante volumétrie et traiter des cas d’usage très innovants.</p>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/01/des-objets-et-des-hommes/">Des objets et des hommes</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
