How peripheral devices become a gateway for critical systems
A comprehensive analysis by the National Cyber Security Test Institute (NTC) shows that peripheral devices in the digital workplace are an often underestimated attack surface. Around 30 devices from established manufacturers that are widely used in Switzerland were tested - with alarming results.

A confidential video conference at a critical infrastructure operator is well protected against hacker attacks - the network, server and laptop are up to date with the latest security standards and the connection is end-to-end encrypted. However, an attack is still possible: using an antenna in the nearby parking lot, an attacker intercepts the inadequately secured radio traffic of the wireless table microphone. Within a few seconds, he can listen in on the confidential conversation. This scenario is not fictitious - it shows how existing protective measures can be circumvented via an insecure peripheral device.
In a comprehensive technical analysis, the National Cybersecurity Test Institute (NTC) examined around 30 keyboards, headsets, webcams and conference systems from established manufacturers that are widely used in Switzerland - devices that can be found on every Swiss desk. The result: the NTC identified over 60 vulnerabilities, including 13 serious and 3 critical findings.
Critical interface for sensitive information
Peripheral devices form the critical interface through which sensitive information flows. For example, passwords are entered via keyboards and confidential conversations are transmitted via microphones and webcams. There is a dangerous asymmetry: the cost of professional security analyses often exceeds the purchase price of such devices many times over.
«In practice, peripheral devices are often regarded as mere accessories and are therefore not systematically tested or consistently integrated into existing safety concepts,» says Tobias Castagna, Head of Test Experts at the NTC.

Systematic safety analysis uncovers risk patterns
In order to systematically assess the security level of widely used peripheral devices in Switzerland, the NTC subjected around 30 wired and wireless devices to a comprehensive technical security analysis over the course of a year. The selection included products from established manufacturers, including devices from Logitech, Yealink, Jabra, HP, Eizo and Cherry, which are also used in critical infrastructures in particular.
The analysis shows that modern peripheral devices can achieve an acceptable level of security with secure configuration and up-to-date firmware. However, the risks increase with increasing device complexity, for example in conference systems or other IoT devices, as well as when using outdated wireless technologies.
The vulnerabilities identified were reported to the manufacturers concerned and most of them were quickly rectified. In one individual case, however, a manufacturer did not respond: in the case of a wireless presentation system, the NTC referred the case to the Federal Office for Cybersecurity (BACS), which then published a public warning.
Five recommendations for minimizing risk
The public report deliberately avoids technical details and product-related vulnerabilities. Instead, it highlights overarching risk patterns, including insecure default settings, weaknesses in device pairing, inadequately secured wireless communication and deficits in firmware and lifecycle management. The study makes it clear that the security of peripheral devices is not just a product characteristic, but depends largely on configuration, operation and clear organizational guidelines.
Based on the results, the NTC has formulated five general recommendations for reducing the risks associated with the use of peripheral devices, particularly for operators of critical infrastructures and organizations with increased security requirements:
- Standardization and secure procurement via trustworthy channels,
- Inclusion of peripheral devices in IT lifecycle and asset management,
- Network segmentation for network-compatible devices such as conference systems,
- Preference for wired solutions in areas with increased protection requirements and
- Raising employee awareness of physical and organizational risks.
The investigation was carried out as part of a joint initiative by the National Cyber Security Test Institute (NTC) with the support of federal and cantonal authorities and organizations from the financial sector. In order to ensure the independence of the results, the manufacturers of the tested devices were neither involved in the selection nor in the execution of the tests and were only contacted as part of the confidential notification to rectify the vulnerabilities.
More information: www.ntc.swiss
