UPDATED 13:00 EST / MARCH 07 2019

SECURITY

Fresh look at building automation security exposes network vulnerability

Engineers at Forescout Technologies Inc. call it the “wow effect.”

When they meet with a client and present a complete overview of a network, the response is invariably a jaw-dropping, forehead-slapping exclamation. Many surprised customers often had no knowledge of how many devices were online or the threat exposure that created.

“They had no idea that a camera was directly connected to the internet,” said Elisa Costante (pictured), senior director of industrial and operational technology innovation at Forescout. “We basically bring light on the dark side of the network. We are looking at all of those tiny devices that you do not expect to be on your network and what they can do.”

Costante spoke with Jeff Frick (@JeffFrick), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, during the RSA Conference in San Francisco. They discussed the challenge facing many buildings with legacy systems today and the need for network visibility to prevent the spread of viruses in critical institutions. (* Disclosure below.)

Lack of security in legacy systems

In many facilities, building systems are legacy-driven, using older technology that was developed without security in mind. Facilities managers are often reluctant to replace their legacy systems, and information technology is bolted on top.

This is where things can go seriously wrong. “Sixty percent of buildings today are controlled and managed by systems that are 20 years old,” Costante explained. “But you’ve made an investment and you don’t want to change.”

The result can be an attack such as the WannaCry virus, a ransomware worm that spread like wildfire across global computer networks in 2017. WannaCry victimized many hospitals, including the National Health Service in Great Britain.

The vulnerability of public health organizations as a result of one virus highlighted the need for network visibility in an operational technology grid, understanding what devices are connected in real-time.

“You could have the controller for your heating, ventilation and air conditioning exposed to the internet and pull down all of the air conditioning in a hospital, for instance,” Costante said. “WannaCry put down a lot of hospitals.”

Watch the complete video interview below, and be sure to check out more of SiliconANGLE’s and theCUBE’s coverage of the RSA Conference. (* Disclosure: Forescout Technologies Inc. sponsors theCUBE’s coverage of the RSA Conference. Neither Forescout nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.