ChannelLife New Zealand logo
Industry insider news for New Zealand's technology resellers
Story image

Firmware attacks significant threat in age of hybrid work

By Shannon Williams
Thu 30 Jun 2022

Changing workforce dynamics are creating new challenges for IT teams around firmware security, according to new research released by HP from HP Wolf Security.

According to the research, as business workforces become increasingly distributed, IT leaders say its harder than ever to defend against firmware attacks.

The shift to hybrid work models has transformed how organisations manage endpoint security, while also highlighting new challenges for IT teams around securing device firmware. 

The HP Wolf Security global survey of 1,100 IT leaders reveals that:

The threat of firmware attacks is a growing concern for IT leaders now that hybrid workers are connecting from home networks more frequently
With hybrid or remote work now the norm for many employees there is a greater risk of working on potentially unsecure home networks meaning that the level of threat posed by firmware attacks has risen. More than eight-in-ten (83%) IT leaders say firmware attacks against laptops and PCs now pose a significant threat, while 76% of ITDMs said firmware attacks against printers pose a significant threat.

Managing firmware security is becoming harder and taking longer in the era of hybrid work, leaving organisations exposed
More than two-thirds (67%) of IT leaders say protecting against, detecting, and recovering from firmware attacks has become more difficult and time-consuming due to the increase in home working, with 64% saying the same of analysing the security of firmware configuration. As a result, 80% of IT leaders are worried about their capacity to respond to endpoint firmware attacks.

"Firmware attacks are very disruptive and much harder to detect or remediate than your typical malware often requiring expert and even manual intervention to fix," says Dr. Ian Pratt, global head of security for personal systems at HP Inc. 

"This increases the cost and complexity of remediation considerably, particularly in hybrid environments where devices are not on site for IT teams to access," he says. 

"Having more endpoints sitting outside of the protection of the corporate network also reduces visibility and increases exposure to attacks coming in via unsecured networks.

"At the same time, we are seeing a rise in destructive attacks such as wiper malware," says Pratt. 

"Last year, our research team saw attackers conducting reconnaissance on firmware configurations, with the likely intent of exploiting unsecured configurations to weaponise for financial gain. 

"Once an attacker has gained control over the firmware configuration, they can exploit their position to gain persistence and hide from anti-malware solutions that live in the Operating System," he says.

"This gives them an advantage, allowing them to stealthily maintain persistence on target devices, so they can gain access to infrastructure across the enterprise and maximise their impact."

Despite the clear risks that firmware attacks pose to organisations, device security is not always a major consideration in the hardware procurement process, with many organisations continuing to use technologies that are not built with security in mind. 

This issue is being exacerbated by the new shadow IT whereby employees are purchasing and connecting devices outside of IT purview while working remotely. HP Wolf Security's Out of Mind and Out of Sight report found that 68% of office workers that purchased devices to support remote work said security wasn't a major consideration in their purchasing decision. Furthermore, 43% didn't have their new laptop or PC checked or installed by IT or security.

Boris Balacheff, chief technologist for security research and innovation at HP Labs, says security must become part of the procurement process when purchasing new IT devices. 

"Organisations need to play the long game, because the devices you procure today will be the environment you have to manage and protect tomorrow," he says. 

"State-of-the-art device security delivers protection for firmware against malware as well as physical tampering, with detection both below and above the OS and autonomous self-healing recovery from the hardware up but this will only help address the issue for organisations that know to ask the right questions when they procure new devices."

HP warns that one of the key issues that businesses face is that many organisations are still reliant on legacy devices that were built to older industry standards, where design for manageable security and resilience at scale was not a focus for hardware and firmware design. This is leaving a gap in enterprise security that could take years to close.

Balacheff says, "As attackers continue to invest in the capability to attack and disrupt PCs and other OT and IoT devices at the firmware level, organisations also need to learn how to monitor the state of the art in device security to keep updating procurement security requirements accordingly. 

"This is what will enable leading organisations to stay ahead of emerging threats and protect, detect and remediate firmware attacks at scale in the era of hybrid work."

Related stories
Top stories
Story image
SmartWatch
Hands-on review: Huawei Watch D smart watch
The Huawei Watch D is the latest flagship smart watch from the Chinese tech giant, and it's further proof that the company is more than capable of competing with the likes of Samsung and Apple in the highly competitive wearable market.
Story image
Smartphone
Hands-on review: OPPO Find X5 smartphone
With the release of the new OPPO Find X5 in March, we got the opportunity to explore another one of their premium devices.
Story image
Review
Hands-on review: JBL Flip 6 portable speaker
Once you switch it on, and listen away for up to 12 hours, you will quickly realise that this is a little speaker looking for a party.
Story image
Tech job moves
Tech job moves - Fastly, INX, Kinly, SmartBear & Vectra AI
We round up all job appointments from July 29 - August 12, 2022, in one place to keep you updated with the latest from across the tech industries.
Story image
Smartphone
Samsung introduces new generation of foldable smartphones
Samsung has unveiled its new range of Galaxy Z smartphones, bringing new developments to the company’s foldable smartphone portfolio.
Story image
Dicker Data
Dicker Data brought on as Acronis partner for A/NZ
The news about the partnership comes in as cyber criminals continue to exploit gaps in traditional solutions and strategies in NZ and across the APAC region.
Story image
Red Hat
Red Hat announces 2022 awards winners for A/NZ region
Red Hat recently acknowledged Australia and New Zealand partners with its annual awards, highlighting partners across various categories.
Story image
Financial results
Jade Software’s plan to get back to surplus in 2022
Jade Software has released its latest financial report, revealing that the company has kept its loss low from $567,000 in FY 2020 to just $153,000 in FY 2021.
Story image
Charity
SnapLogic teams up with meetmagic for charity and children
SnapLogic has announced its partnership with meetmagic, an online Australian platform that combines business and philanthropy.
Story image
Home Entertainment
Hands-on review: TCL 65″ C835 Mini LED 4K Google TV
We introduce you today to a TV that brings the height of immersion to your viewing experience: The TCL 65″ C835 Mini LED 4K Google TV.
Story image
Surveillance
Ministry will no longer accept equipment from Chinese firm Hikvision
The Ministry of Business, Innovation and Employment (MBIE) says it will no longer accept equipment from a major Chinese surveillance camera maker.
Story image
IDC
High level of Customer Identity & Access Management adoption
The study from Okta revealed that the pandemic has either accelerated or highlighted the need for digital-first strategies.
Story image
Samsung
New range of Samsung Smart Watches announced with health focus
Samsung has announced new additions to its SmartWatch portfolio, with the Galaxy Watch5 and Galaxy Watch5 Pro to be released in late August.
Story image
Arlo
Hands-on review: Arlo Go 2 security camera
In my humble opinion, Arlo Go 2 offers security for anyone needing to keep a remote eye on prized possessions or premises at different locations.
Story image
Artificial Intelligence
Exclusive: NZ-based DEFEND offers global cyber protection
DEFEND supports customers in 66 countries across the globe with a relentless focus on ensuring that every dollar spent on security provides a meaningful return on investment and reduces cyber risk.
Story image
Compliance
Why security needs to shape your journey to the cloud
It's estimated that 80% of workloads could be in the cloud in the next few years. How can you make all that data secure?
Story image
Document Management
TrustRadius gives M-Files two document management awards
TrustRadius has recognised M-Files with both a 2022 Best Feature Set and a 2022 Best Relationship award in document management.
Story image
Microsoft
Spectralink DECT devices now integrated with Microsoft Teams SIP Gateway
Spectralink DECT devices are now integrated with Microsoft Teams SIP Gateway to help create better results for business-critical frontline workers.
Story image
Neat
Workplace design a crucial factor for better employee experience - report
The key to a successful workplace could be its design, according to research from Ecosystm and Neat.
Story image
Economics
9 in 10 retailers prepared for economic challenges this year
Some 9 in 10 retailers (86%) are prepared for continued inflation, higher interest rates and potentially lower consumer spending, according to new research.
Story image
SaaS
Cloud and data protection big challenges for NZ businesses
"This surge towards a cloud-first approach meant security and safety became afterthoughts - there's no point being the fastest car on the racetrack if you crash.”
Story image
Web application firewall
Radware recognised in KuppingerCole’s 2022 Leadership Compass report
Radware has been named a Product, Innovation, Market and Overall Leader in the 2022 KuppingerCole Leadership Compass report for Web Application Firewalls.
Story image
Developers
Snyk announces plans to expand partner network in APJ
Recognising that partnerships are critical for growth, Snyk is building an entire partner ecosystem that will drive its expansion across APJ.
Story image
ExtraHop
Organisations exposing highly sensitive protocols to public internet
More than 60% of organisations expose remote control protocol SSH to the public internet, while 36% of organisations expose the insecure FTP protocol.
Story image
Sustainability
NZ program recovers and recycles more than 177 tonnes of e-waste
The TechCollect NZ pilot program says its milestone of recovering and recycling more than 177 tonnes of ICT e-waste recognises the efforts of many.
Story image
Ingram Micro
Ingram Micro NZ sees $74 million revenue growth in 2021
Ingram Micro New Zealand's latest financial report reveals that its revenue from contracts with customers increased by almost $74 million in 2021.
Story image
Cyber attacks
Dramatic uptick in threat activity with exploits growing nearly 150%
"While it’s not a surprise given increased attack opportunities like remote work, it’s still a worrying development and one we cannot ignore."
Story image
LG Electronics
LG Electronics’ revenue in NZ grows by 57% in FY 2021
The New Zealand branch of LG Electronics Australia's total revenue shot up by nearly NZD $45 million reaching a total of $123.7 million for FY 2021.
Story image
CyberCX
Nozomi Networks adds nine partners to its MSSP program
OT and IoT security company Nozomi Networks has added nine new members to its MSSP Partner Program, and the list includes CyberCX and Deloitte.
Story image
Gaming
Attacks on gaming companies more than double over past year
The State of the Internet report shows gaming companies and gamer accounts are at risk, following a surge in web application attacks post pandemic.
Story image
Hybrid Cloud
The essential guide to digital transformation by SolarWinds
Digital transformation is a buzzword thrown around all the time by companies, but what does it actually mean and why is it important? SolarWinds breaks it down.
Story image
Gigabit
Keysight Technologies and Nokia’s public test of 800GE success
Keysight and Nokia have successfully demonstrated the first public 800GE test, validating the readiness of next-generation optics for service providers and network operators.
Story image
Dark web
Beware the darkverse and its cyber-physical threats
A darkverse of criminality hidden from law enforcement could quickly evolve to fuel a new industry of metaverse-related cybercrime.
Story image
Privileged Access Management / PAM
The importance of stopping identity sprawl for cybersecurity
The 2021 Data Breach Investigations Report (DBIR) shows that 61% of all breaches involve malicious actors gaining unauthorised, privileged access to data by using a compromised credential. Unfortunately, it is often too late when the misuse of a credential is detected.
Story image
Home security
Hands-on review: Eufy Wire-Free Dual Cam Video Doorbell 2K
We have had our house secured by Eufy products for over seven months now. We love the brand, and it has never let us down.
Story image
Application Performance Monitoring / APM
New Relic integrates offering with Atlassian’s Jira Software
New Relic has integrated errors inbox with Jira Software to allow developers to easily access and set up complete stack error tracking and software performance monitoring from within the tool.
Story image
Machine learning
Sysdig releases CDR offering to combat cryptojacking
Sysdig has unveiled a cloud detection and response (CDR) offering powered by machine learning to combat cryptojacking.
Story image
Google Cloud
Google Cloud to open first cloud region in NZ - among others
Google Cloud has announced plans to bring three new cloud regions, one each in New Zealand, Malaysia and Thailand.
Story image
Distribution
Garmin expands NZ footprint with new Auckland distribution centre
The facility at Goodman’s Highbrook Business Park will be fully operational from October 2022 and features 3,586sqm of warehouse space.
Story image
New Zealand
2degrees announces appointments to newly established board
2degrees has announced Liz Coutts as the board chair, while Russell Stanners and Kathy Meads join her as directors.