Genetec Inc. has issued a call to action for organisations to reinforce credential governance within their connected physical security systems, highlighting the need for stronger measures in light of AI-driven cyber threats.
As artificial intelligence enhances the potency and precision of cyber-attacks, entities overseeing connected cameras, access control mechanisms, and cloud services face heightened vulnerability if credentials are not adequately safeguarded.
Increasing credential-based threats
AI-powered tools have intensified credential-based attacks by enhancing their speed and complexity. Weak or mismanaged credentials in devices provide direct access points, posing significant risks if they are not effectively managed.
Relying solely on periodic password updates or basic cyber measures is now considered insufficient in this context.
The AI challenge in cybersecurity
Mathieu Chevalier, Principal Security Architect at Genetec Inc., emphasized the rapid evolution of cyber threats with AI, stating, "AI is changing the speed and scale of cyber risk. Attackers can now move faster and are using AI to impersonate people, tailor social engineering attacks, uncover vulnerabilities at scale, and evade detection." Chevalier advocates for a proactive approach to managing access and identity across systems rather than relying on static controls. Research revealed that 58.7% of organisations experienced a rise in phishing and smishing attacks
Recent insights from Genetec's research, "Enterprise Physical Security in the Cloud Era," which surveyed over 7,300 security professionals globally, revealed that 58.7% of organisations experienced a rise in phishing and smishing attacks. Furthermore, 41% noted an increase in both physical and cyber incidents, with social engineering identified as a primary threat by 43.5% of respondents.
Focusing on identity management
In anticipation of World Password Day, Genetec advises organisations to transition from isolated credential controls to a governance-centric approach to identity management in physical security settings. Key strategies include:
- Strengthening Identity and Credential Controls: Organisations should eradicate default and shared credentials and optimise strong authentication methods, such as passkeys and multi-factor authentication (MFA), to minimise common attack avenues. This should extend to devices, with static passwords replaced by certificate-based authentication where possible, coupled with centralised credential management and regular updates.
- Aligning IT with Physical Security Teams: Integrating IT and physical security teams is essential for applying consistent security protocols, enhancing access risk visibility, and coordinating incident responses. As physical security systems become integral to enterprise networks, cross-functional collaboration is crucial to identifying vulnerabilities and mitigating credential-based attacks effectively.
- Governance-First Management of Security Systems: Physical security infrastructure should be managed with similar diligence as other critical systems, involving routine access reviews, regulated updates, and collaboration with reliable technology partners for enduring security and operational resilience.
