Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Four Steps to Securing Your IoT Identity from Employees current page
Link copied

Four Steps to Securing Your IoT Identity from Employees

Sep 11, 2018
Author:
Rob Black
CISSP, Founder and Managing Principal of Fractional CISO
Blog banner default
Four Steps to Securing Your IoT Identity from Employees
Rob Black
CISSP, Founder and Managing Principal of Fractional CISO

blog-four-steps-to-securing-your-iot-Identity-from-ex-employees.jpg

When you see one of those cybersecurity stories about how an ex-employee hacked a company with terrible consequences, do you think that could never be us? Or do you think, I’m glad we don’t have anyone like that around!

Many companies are exposed to the former insider risk, they, fortunately, haven’t been tested by a bad employee. Last year, a Pennsylvania man was sentenced to more than a year in prison for “hacking” remote water meters at his company. Local municipality customers couldn’t send out their bills because the water meters weren’t reading anything. This “sophisticated hacker” still had credentials to the water meters of his former employers. He logged in and performed a variety of configuration changes to mess up the meters. Even though he was fired the company didn’t think to change the passwords to any of the base stations. The ex-employee telneted in from his home computer with existing credentials.

You may think that your employee off-boarding process is much better than that. But the reality is that employees may have 25 credentials or more issued by your organization. It is difficult to get rid of them all. I was recently reviewing the access controls on the servers of a client of mine who had good security controls. They still had a former employee enabled on one of their servers. Even though they removed his credentials in the many other places. This is a client with strong security practices and even an off-boarding checklist. Imagine what the situation is for organizations with less formal processes!

Additionally, managing IoT credentials is very difficult. Because there are so many devices and often not under central control, when an admin leaves, it can be difficult to change credentials in all of the locations. Also, in an IoT system each device has different sets of credentials for integration with different local and cloud-based systems. If your ex-administrator knows these credentials then all of these have to change.

We have identified four actionable steps that will help your organization improve its cybersecurity posture as it relates to identity.

  1. Disable ex-employee accounts. This one is so obvious but somehow, companies miss it. As soon as an employee leaves, all of his or her accounts should be turned off. Especially those accounts that can be accessed remotely. Organizations often construct a departure checklist with all of the accounts that an employee has. If you don’t have one, you should.
  2. Change system passwords upon administrative employee departure. When your administrative employees leave, do you change the shared passwords on all infrastructure and devices? Good chance that your organization doesn’t. If those devices are Internet facing or the ex-employee can VPN in then you could be next for a humiliating headline!
  3. Audit authorized VPN users. Many other mistakes can be caught by having strong controls over your authorized VPN users. These are the users that can access your network and systems remotely. If you do a good job making sure that only authorized users can VPN in then you can reduce your risk of ex-employee attack. Make sure that your tech support team checks for active employment before enabling or re-enabling access to your VPN. Yes, this attack really has been successful.
  4. Use Privileged Access Management (PAM). PAM is a tool for managing the accounts in your organization that have administrative access to important systems. These tools can allow secure access to all authorized employees without forcing them to remember many passwords. They can allow for multiple people to access the same account but who accessed the system is audited. When employees leave, they can be turned off on the PAM system without causing a disruption to operations for each individual system.

Where to learn more?

If it seemed that we just scratched the surface for how to secure IoT identity then you are right! We are about to release a white paper in conjunction with Beyond Trust about managing identity for your IoT system. Stay tuned for its imminent release.

But you don’t need to wait for the white paper to learn more. Next Thursday, September 13, Fractional CISO and Beyond Trust will be hosting a webinar on The 5 Crazy Mistakes Administrators Make with IoT System Credentials. Yes, we will cover the threat from ex-employees. But you will have to tune in to find the other four crazy mistakes.

For help with your cybersecurity strategy and execution contact us at Fractional CISO. We’ll be happy to help you get on a path to better cybersecurity decision making.

This article originally appeared on the Fractional CISO blog.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • Rethinking Endpoint Security: The Role of AI in Threat Detection
    Dec 2, 2024 Rethinking Endpoint Security: The Role of AI in Threat Detection
    Blog
    6m
  • I Spy with My Little Eye – Using Threat Analytics as Your Secret Weapon
    Sep 27, 2018 I Spy with My Little Eye – Using Threat Analytics as Your Secret Weapon
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.