Site navigation

IT and Security Leaders Admit Hardware Cybersecurity Gap

Elizabeth Greenberg

,

hardware cybersecurity
Around two-thirds (68%) of IT and security leaders admit that their cybersecurity posture does not cover every stay of their hardware’s life cycle. 

The cybersecurity gap seems to be a hardware problem, as new research from HP reveals that platform security is often overlooked, weakening cybersecurity posture for years to come.

The report from HP Wolf Security, based on over 6,000 employees and 800 IT and security decision makers from across the globe, shows that platform security is a growing concern, with 81% of these leaders agreeing that hardware and firmware security must be prioritised.

However, over two-thirds (68%) report a shortfall in hardware and firmware security investment, leading to costly security headaches, management overheads and inefficiencies further down the line.

The HP report detailed security failings throughout the five stages of device life, from supplier selection, configuration, management, monitoring, and decommissioning.

Supplier Selection

60% of IT and security decision makers say the lack of IT and security involvement in device procurement puts the organisation at risk.

In addition, 34% say a PC, laptop or printer supplier has failed a cybersecurity audit in the last five years, with 18% saying the failure was so serious that they terminated their contract.

Further, 52% of IT and security leaders say that procurement teams rarely collaborate with them to verify supplier’s claims, with 48% calling procurements teams “lambs to slaughter” for trusting vendors claims wholeheartedly.

Onboarding and Configuration

More than half (53%) of IT and security leaders say BIOS passwords  – system set up passwords -are shared, used too broadly, or are not strong enough. Moreover, 53% admit they rarely change these passwords over the lifetime of a device.

The majority (78%) of leaders want zero-touch onboarding via the cloud to include hardware and firmware security configuration to improve security, with 57% feeling frustrated that they cannot onboard and configure devices via the cloud.

Ongoing Management

Over 60% of leaders do not make firmware updates as soon as they’re available for laptops or printers.

A further 57% of leaders say they get FOMU (Fear Of Making Updates) in relation to firmware. Yet, 80% believe the rise of AI means attackers will develop exploits faster, making it vital to update quickly.

One in four employees would rather put up with a poor-performing laptop than ask IT to fix it as they cannot afford the downtime, which about half (49%) say takes over 2.5 days.

This has driven 12% to unauthorised third-party repair providers for work devices, which could compromise platform security.


Recommended reading


Monitoring and Remediation

Monitoring and remediating hardware and firmware threats to prevent threat actors accessing sensitive data and critical systems is vital. However, 79% of ITSDMs say their understanding of hardware and firmware security lags behind their knowledge of software security.

Every year, lost and stolen devices cost organisations an estimated $8.6bn (£6.7bn). One in five work-from-anywhere employees have lost a PC or had one stolen, taking an average 25 hours before notifying IT.

Second Life and Decommissioning

Nearly half (47%) of IT and security decision markers say data security concerns are a major obstacle when it comes to reusing, reselling, or recycling PCs or laptops, while 39% say its a major obstacle for printers.

This leads to 59% of leaders destroying devices as giving them a second life can prove too difficult.

“Buying PCs, laptops or printers is a security decision with long-term impact on an organization’s endpoint infrastructure,” warned Boris Balacheff, chief technologist for security research and innovation at HP Inc.

“The prioritization, or lack thereof, of hardware and firmware security requirements during procurement can have ramifications across the entire lifetime of a fleet of devices – from increased risk exposure, to driving up costs or negative user experience – if security and manageability requirements are set too low compared to the available state of the art.

“It’s essential that end-user device infrastructures become resilient to cyber risks. This starts with prioritizing the security of hardware and firmware and improving the maturity of how they are managed across the entire lifecycle of devices across the fleet.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data