
Insights · IT security
Attacks via removable storage media
- Published
- 26 April 2024
- Author
- Dr. Andreas Pagiela
- Reading time
- 6 min read
USB sticks are high explosives for company IT. Because of the high cyber risks, the NIS2 Directive demands greater security awareness from businesses. How companies can act.
Curiosity often allies itself with illegal activity. This was shown by a study by the University of Illinois, Michigan and the company Google. The researchers distributed 297 USB sticks on the university campus. The result: virtually all of the storage devices left out were taken by passers-by. Almost half connected the sticks to their computers. Only 13 per cent of the people who answered the researchers’ questions said that they “took special precautions before they opened the USB stick”. Two thirds of those surveyed clearly did not care. They accessed the data from the removable storage “without being suspicious of the contents of the sticks”. This still current study from 2016 shows that users, without suspicion, pick up USB sticks they find by chance and even use them without checking. The high risk: sticks infected with malware contaminate computers with viruses and siphon off confidential data.
By now, such dangerous carelessness in companies should no longer be an issue in view of hacker attacks, paralysed IT networks and security and data-protection breaches. Nevertheless, USB sticks are still very popular as promotional gifts or inserts in customer mailings. Consumer advocates and IT experts were concerned because such USB sticks often give the appearance of particular trustworthiness.
Too practical to do without?
There is no doubt that, even in the cloud age, USB sticks are still in high demand. Data can be exchanged on them quickly and straightforwardly. Employees in companies like to use them in day-to-day work because they appear, in the truest sense of the word, more tangible than data in the cloud. As a result, many users’ subjective sense of security is also markedly higher than when accessing data stored online. But this sense of security is deceptive. The small helpers can become a genuine threat to business operations. Cyber criminals use USB sticks to penetrate company networks.
Curiosity weakens IT security
Small and medium-sized enterprises (SMEs) in particular should be on their guard. The weak point is the human factor. A USB stick “lost” on the company premises (in reality placed by an attacker) can quickly enable cyber criminals to gain targeted access to a company network. Attackers exploit weaknesses such as curiosity. Employees must therefore be informed about the risks, and binding rules for handling USB sticks must be put in place in the company.
This also includes knowing how cyber criminals use USB interfaces. They can program a stick so that the manipulated USB device, when connected, falsifies its technical information to the network — for example in stating what type of device it is (stick, keyboard or smartphone). This is a technically inherent security gap in USB interfaces, because the point here is functioning communication, less so identification. The network computer therefore has to trust that the connections actually are what they claim to be.
What the NIS2 Directive requires of companies
Such risks have prompted the legislator to act. From October, small and medium-sized enterprises too are obliged to manage their cybersecurity professionally and to report security incidents. Anyone who fails to comply faces penalties of up to ten million euros or 2 per cent of annual turnover. That is what the NIS2 Directive requires. For SMEs this means: if companies are active, directly or indirectly, in a sector of societal relevance, they fall under the NIS2 Directive. They will therefore soon be under a much more far-reaching statutory obligation than before to introduce risk management with regard to cyber attacks.
How should firms now manage removable data storage in order to be on the legally safe side? A practical piece of advice would be: USB sticks yes — but only as company hardware. That means IT provides registered and password-protected USB sticks for all employees. Ideally accompanied by a works instruction that other USB sticks may not be used.
USB sticks are a cybersecurity risk
Attackers can set up a USB stick so that it presents itself to the IT network as a keyboard. Certain key combinations are stored on the stick which, after insertion, automatically transfer malware to the device. In this way any conceivable form of malware can be smuggled into the company network. Scenarios include the sabotage of production facilities or the installation of malicious programs used for espionage or to encrypt data across the entire company network and demand a ransom. A single virus-infected USB stick can thus seriously threaten the existence of small and medium-sized enterprises.
Neglected IT security also entails considerable liability risks, however. Attacks on company data almost always also affect personal data, at least that of the company’s own employees. If the company enabled the data leak through inadequate IT security, it becomes liable in damages to the people affected. Because as a rule the incident also has to be reported to the Land data protection commissioners, fines are threatened at the same time. Through the NIS2 Directive, liability is expanded considerably further. In addition to data protection and the German IT Security Act, a new legal basis has thereby been created that now brings its own reporting duties and fines. All of this also entails considerable effort in the legal handling of an incident.
These risks have led many firms to deactivate the USB interfaces on their company devices. However, the use of USB sticks is a fixed part of operating procedures in numerous companies. A general deactivation of the interface is therefore of little help. It is better to rely on hardware-encrypted USB storage that has an approved hardware ID or has been checked by an internal security team.
USB device management
The central point for IT security is therefore centralised USB device management. This is where the removable media are administered. Loss, theft and manipulation of data can thus be prevented. IT should set up an encrypted backup for each USB storage device and protect the sticks with a password against being opened by unauthorised persons. A further aid is anti-virus software that scans USB devices plugged into the company network for malicious files before employees can open the files. Malicious programs are thereby prevented from reaching the systems in the company.
Besides the technical measures, the most important security method is to raise employees’ awareness of the risks and dangers of a USB stick. Whether a promotional gift or a conference giveaway: every unknown USB storage device is a security risk, of at least as high a significance as phishing e-mails or password security. At most, therefore, it is suitable for private use.
How can this be implemented in a practice-oriented way?
We are glad to support you in designing compliance for IT security.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


