A recent attack on a French ferry, where an attacker allegedly connected a small computer, known as a Raspberry Pi, to the network in an attempt to compromise the ship's operations, offers an important lesson for enterprise CISOs: one analyst estimated that half of all businesses would likely be compromised by the same attack in their physical environment.
See also: Raspberry Pi and Sony created a “Raspberry Pi AI Camera module”

The ferry “was grounded Saturday in the southern French port of Sète as it prepared to sail to Algeria” due to the attempted attack, according to a Bloomberg report. The Raspberry Pi device “was paired with a cellular modem, allowing remote access to the ferry’s internal computer network and external connections.” The good news was that the attempted attack was stopped due to good security procedures on the ship, the story said.
The question for corporate cybersecurity executives is how well their land-based buildings — offices, stores, gas stations, bank branches, manufacturing facilities, etc. — would withstand a similar physical attack. Analysts and other security experts were not optimistic about how they would fare.
“A Raspberry Pi-class device with a cellular modem isn’t just a smart gadget, it’s a way to create a new perimeter from inside your building.” An attacker “doesn’t have to fight your firewalls if they can bypass them. They don’t have to defeat your VPN if they can bring their own internet connection into your wiring closet. This is the part that should keep CISOs awake, because it means a lot of the controls we celebrate are monitoring the wrong paths. If traffic is leaving via cellular, it’s not crossing your monitored gateways. Your SOC can do everything right and see nothing.”
See also: How to create a Smart Home with Raspberry Pi

Too many security experts look at what shady devices, like fitness trackers, are supposed to do and don't focus on the access the device could gain as the start of a backdoor attack. "You shouldn't be able to walk up to an Ethernet port and plug anything in. This device needs to be certified."
The proliferation of cheap and very capable single-board computers like the Raspberry Pi has made this problem much more difficult. Network intrusion detection should have detected behavioral anomalies, but that's easier said than done if you have a large, complex network and the Raspberry Pi looks like a regular IoT device.
Trying to send false information is even more difficult, because you would have to identify the protocols the device uses to know what to send. A bigger problem is if the device is perhaps connected to another device and could cause a destructive action if compromised.
See also: Raspberry Robin hits Windows systems

CISOs need to go beyond simply monitoring their internal LAN. They need continuous external infrastructure monitoring. If a device starts communicating with a network block known to host state-sponsored malware, or if a new shady asset appears on your perimeter, that’s a trap.
