THANK YOU FOR SUBSCRIBING


Morgan Hung General ManagerSuch incidents are bound to rise. With 5G about to pour rocket fuel into the hyper-connected engine steered by IoT devices, hackers are chomping at the bits. Why? It’s simple. When almost every conceivable object is hooked up to lightning-fast internet, the consumption and due collection of data will multiply infinitely, incentivizing hackers to attempt more data breaches.
To aggravate the issue, market grade anti-virus software (for IoT devices) is designed to secure only the end-point and not the entire network—where the vulnerabilities truly emanate from. The dearth of quality protocols (in securing IoT devices) was recently acknowledged by a US-Cert Report, which noted that only 22 percent of the IoT manufacturers conduct security audits, and 90 percent cybersecurity issues are from vulnerabilities in applications.
"The complementary services enrich our accreditation procedures, products, and training, and provide a huge boost to our market image"
If anyone can attest to the lack of cybersecurity expertise shared by IoT device manufacturers, it is Onward Security, a Taiwan-based company comprising of engineers who were at the forefront of the IoT explosion that started a little over a decade ago. Starting in 2008, the core members of Onward Security participated in several governmental projects for establishing security standards for mobile apps, cellular networks, IP cameras, smart buses, and the like. The project also involved cooperating with Taiwan’s IoT and IIoT manufacturers (including several global companies outsourcing operations) and conducting in-depth research on software-based cybersecurity issues. During the research, the group discovered 40 new CVE vulnerabilities, realizing that many gaps had yet to be filled with regard to securing IoT devices.
By 2014, the cybersecurity roadblocks faced by IoT device makers were only getting more prominent, spurring the foundation of Onward Security. “We observed that IoT manufacturers were more focused on manufacturing and network-related technology. Cybersecurity was never their priority. Responding to this niche market need, we began as a startup focusing just on cybersecurity for IoT devices,” says Morgan Hung, general manager, Onward Security.
So, why exactly are IoT device manufacturers lagging at the cybersecurity aspect?
The issues permeate all through the design and testing stages. While developing their products, IoT and IIoT device manufacturers don’t take a number of security parameters into consideration. “For starters, they lack security knowledge at the design stage, the capability to implement security testing, and the know-how to find vulnerabilities in the source code,” details Morgan. Furthermore, they don’t utilize conformity assessment tools in regulatory practice, and the monitoring procedure used in the development environment is subpar. “These difficulties result in repeated security issues. At times, they increase the costs of patch-ups or extra compensation for clients. When push comes to shove, it affects reputation,” adds Morgan.
Over the last five years, Onward Security has emerged as a leader in helping Taiwan-based IoT device companies improve their cybersecurity standards. The only company in Taiwan that has tested over 300 IoT devices and discovered over 3,000 vulnerabilities, Onward Security provides comprehensive solutions for network, product, and software development security.
Moving to ‘Secure-by-Design’ Approach
The IoT cybersecurity experts help IoT product companies transition from the “security-by-evaluation” approach to the “security-by-design” principle.
To tackle cybersecurity issues at the design stage itself, Onward Security offers its clients automated assessment tools to meet all global cybersecurity requirements while also enhancing the diversity and competitiveness of their products. “We step into the client’s shoes to help them improve quality of security, raise awareness, and launch a product that is foolproof with regard to cybersecurity,” says Tina Shao, regional sales director, Onward Security.
Onward Security’s core business can be divided into three fragments: enterprise security services, product security evaluation services, and a product line comprising of self-developed testing tools and a security management system.
Through its product security service, Onward Security provides a well-rounded solution for requirement analysis, designing process, program development, security testing, and environment establishment. “We follow corresponding techniques at each stage, to prevent any potential security issues,” asserts Jennifer. The solution includes a whole IoT product such as embedded devices, mobile applications, and cloud, besides hardware hacking and product security consulting. “We also assist our clients in meeting international standards and getting the certification,” she adds.
On the product front, Onward Security offers two SSDLC (Security Software Development Lifecycle) tools titled Hercules SecFlow and Hercules SecDevice. The platform(s) help Onward Security’s clients achieve SSDLC in a fast and cost-effective manner, rather than wasting precious time on redundant documentation.![]()
We step into the client’s shoes to help them improve quality of security, raise awareness, and launch a product that is foolproof with regard to cybersecurity
SecFlow provides a development process management system, a security vulnerability database, proactive product security, and provisioning, to safeguard every phase of the SSDLC cycle—from requirements, design, development, testing, and deployment. The platform is also proficient at allowing users to monitor events. “Based on a customer’s needs, product keywords can be collected for related security vulnerabilities and duly saved in the SecFlow database. SecFlow also delivers proactive notifications via email,” says Tina.
On the other hand, Hercules SecDevice is a security assessment tool designed specifically for connected products. Through a range of automated features, the SecDevice allows IoT manufacturers to save the considerable amount spent on testing. The platform’s key features include a smart connection, which enables automatic target identification, negating a user’s set-up procedure and involvement. Additionally, the platform generates intelligent analyses of vulnerabilities to decrease artificial error and redundant testing efforts. SecDevice also includes a machine learning-based fuzzing tool. Morgan elaborates, “Our R&D engineers leverage the optimal way to let SecDevice find unknown vulnerabilities. This helps our customers eradicate misinformation or omission possibilities.”
Balancing SSDLC and Time-to-Market
Since several IoT device manufacturers are trying to outrace each other to launch their products in the market, Onward Security takes the onus upon itself to automate all security and compliance checklists for a client, allowing them to fast track their time-to-market. Needless to say, a client’s scheduled launch time can’t compromise the security features of the product. “While they are busy meeting security requirements from various governments, their customers, and supply chains, hackers are truly a headache to the product development team and the related departments. This is where we come in,” says Morgan.
To cite an example of Onward Security’s prowess in penetration testing and product security assessment, Morgan refers to an engagement with an international telecom company. The client, which procures hundreds of various IoT devices/equipment, simply didn’t have the time or resources to perform adequate testing. Onward Security provided SecDevice on a one-month trial basis and allowed the client to comprehensively test their web applications, network services, network protocols, and wireless of IoT devices by utilizing various test tools such as a CVE scan, web vulnerability scan, protocol fuzzing, and DoS testing. During the trial period, the telecom received technical reports of where its vulnerabilities, PCAP, and log were specified. “After adopting SecDevice, our client built up its IoT testing capabilities and was able to provide IoT security assessment to its own customers. SecDevice also helped the telecom client to provide fast and effective services and thus increased its revenue in IoT security assessment services,” recalls Morgan.
Another success story entails the value Onward Security brought to an international network facility brand. With its products plagued by vulnerabilities, the client was keen to establish its security processes and technical capabilities. However, the client was budget-strapped and could not afford to train its QA team or procure various testing devices. Add to that, they were burdened by pressing requirements of their international buyers and government regulations.
"In the coming two years, we aim to become one the best product security assessment companies in Asia"
In the aftermath of the product/services deployment, the client reduced the timeframe of tackling security issues from 2-3 months to 1-2 weeks. “SecDevice drastically changed its testing capacity from manual operation for 10 CVE items to automatic operation for about 70 testing items,” he says, before adding that Onward Security’s consulting and assessment services helped the client not only establish the process of SSDLC but also blend SSDLC into its culture and enterprise process. “Now, the security management system has been implemented in all their products. As expected, their product security quality has improved drastically.”
Strategic Collaboration with the International Enterprise
Ever since its inception in 2014, Onward Security has acknowledged the challenges it faces to thrive in Taiwan’s complex technology market. “Investors in Taiwan are very conservative about investing in startups. Also, the resources for international marketing are limited,” says Morgan.
To alleviate these concerns, Onward Security has forged a strategic collaboration with the International Enterprise (IE). By working with an international accreditation/ certification company, Onward Security is able to search for various customer bases and reach different industries and markets. He adds, “The complementary services enrich our accreditation procedures, products, and training, and provide a huge boost to our market image.”
In fact, Onward Security built up a blueprint to target the global market from the very onset in 2014. “As part of the plan, we continuously promoted our security services and products internationally, participated in well-known conferences like Derbycon and CODE BLUE, published security issues in the chipset, and eventually became a qualified testing laboratory for Amazon AVS,” says Morgan. Through the journey, Onward Security obtained ISO 27001 and ISO 17025 dual certification. “These efforts have enabled us to be recognized by our customers in the product security assessment industry,” adds Morgan.
To further its ambitious plans of serving global customers, Onward Security will open a new office in Malaysia by the end of the year and another branch in Japan in 2020.
Keeping that vision intact, Morgan says the company will continue to focus on its market niche rather than competing with bigger cybersecurity companies, “Most of them deal at the enterprise level. However, we want to stick to the product aspect.” Onward Security is admittedly just scratching the surface of its ceiling, especially due to the untapped potential of cybersecurity in the IoT market. “In the coming two years, we aim to become one the best product security assessment companies in Asia,” adds Morgan.
From a product/service perspective, Onward Security is prepared for the aftereffects of the integration of 5G and AI in new IoT products. Since 5G is expected to increase the number of vulnerabilities, and heighten the need for data protection, Onward Security’s R&D team has already started to tackle the impending challenges. The research is taking into account industrial characteristics, application scenarios, and potential cybersecurity risks. Eventually, Onward Security will transfer the results into an industrial standard, risk assessment service. “After a few years of data accumulation, our R&D team can develop these skills into an automated testing tool. We already have this ability in our DNA, owing to past experience of dealing with new communication networks to develop testing tools," informs Morgan.
"Onward and Upward,” the IoT security troubleshooter is determined to change the stereotyping associated with Taiwan being an electronics/hardware manufacturing base. Morgan says, “We want to change this image for our products through the crystallization of our services and software. We want to be recognized globally for our technical achievements."
On a closing note, Team Onward Security compares itself to a flock of geese. “They (the birds) fly together and take care of one another. When the weather goes bad, they migrate. When we began as a startup, we overcame many hurdles by putting our resources together, and eventually meeting our investor’s expectations,” concludes a proud Morgan.
Company
Onward Security
Management
Morgan Hung General Manager and Jennifer Hung Chief Strategy Officer, Tina Shao Regional Sales Director
Description
Provides Secure-by-Design solutions to solve cybersecurity complexities in connected devices across the IoT and IIoT markets. One of the top Enterprise Security Startups in the APAC region, Onward Security helps IoT product companies transition from the “security-by-evaluation” approach to the “security-by-design” principle through a number of enterprise security services and product security evaluation services. Besides its wide range of services, Onward Security offers a product line comprising of self-developed testing tools and a security management system. The two platforms, titled Hercules SecFlow and Hercules SecDevice, help Onward Security’s clients achieve SSDLC in a fast and cost-effective manner