Government seeks secure IoT

The Department for Digital, Culture, Media and Sport has issued a demand that companies making products that connect to the internet should design security measures into them.

Estimates show every household in the UK owns at least 10 internet connected devices and this is expected to increase to 15 devices by 2020, meaning there may be more than 420 million in use across the country within three years, says DCMS.

Update: BSI is first to offer IoT security certification

Poorly secured devices threaten individuals’ online security, privacy, safety, and could be exploited as part of large-scale cyber attacks. Recent high-profile breaches putting people’s data and security at risk include attacks on smart watches, CCTV cameras and children’s dolls.

Developed in collaboration with manufacturers, retailers and the National Cyber Security Centre, the Government’s Security by Design review lays out plans to embed security in the design process rather than bolt them on as an afterthought.

The Government will work with industry to implement a rigorous new Code Of Practice to improve the cyber security of consumer internet-connected devices and associated services while continuing to encourage innovation in new technologies.

“We want everyone to benefit from the huge potential of internet-connected devices and it is important they are safe and have a positive impact on people’s lives. We have worked alongside industry to develop a tough new set of rules so strong security measures are built into everyday technology from the moment it is developed,” says DCMS minister Margot James (pictured), “this will help ensure that we have the right rules and frameworks in place to protect individuals and that the UK continues to be a world-leading, innovation-friendly digital economy.”

“The NCSC is committed to ensuring the UK has the best security it can, and stop people being expected to make impossible safety judgements with no useful information,” says NCSC technical director Dr Ian Levy, “we are pleased to have worked with DCMS on this vital review, and hope its legacy will be a government ‘kitemark’ clearly explaining the security promises and effective lifespan of products. Shoppers should be given high quality information to make choices at the counter. We manage it with fat content of food and this is the start of doing the same for the cyber security of technology products.”

The Security by Design review outlines practical steps for manufacturers, service providers and developers. This will encourage firms to make sure:

All passwords on new devices and products are unique and not resettable to a factory default, such as ‘admin’;

They have a vulnerability policy and public point of contact so security researchers and others can report issues immediately and they are quickly acted upon;

Sensitive data which is transmitted over apps or products is encrypted;

Software is automatically updated and there is clear guidance on updates to customers;

It is easy for consumers to delete personal data on devices and products;

Installation and maintenance of devices is easy.

Alongside these measures for ‘Internet of Things’ manufacturers, the report proposes developing a product labelling scheme so consumers are aware of a product’s security features at the point of purchase. The Government will work closely with retailers and consumer organisations to provide advice and support.

“With connected devices becoming increasingly popular, it’s vital that consumers are not exposed to the risk of cyber-attacks through products that are left vulnerable through manufacturers’ poor design and production,” says Alex Neill of Which? “companies must ensure that the safety of their customers is the absolute priority when ‘smart’ products are designed. If strong security standards are not already in place when these products hit the shelves, then they should not be sold.”

“BT shares the Government’s ambition to make the UK the safest place to work and do business online. We are proud to have played a key advisory role in the development of the draft Code of Practice, having shared our technical insight with the Government in our capacity as a global network operator, UK broadband provider and as a global provider of cyber security and IoT services,” says Mark Hughes, CEO BT Security, “from the development of the world’s first Cleanfeed filter to block child abuse images, free parental controls for broadband products and devices, to warning or blocking our customers from known malware and phishing sites, BT has been at the forefront of keeping consumers and families safe online for many years. BT is actively involved in driving standards, interoperability and security across the IoT market and will continue to provide guidance to the Government and industry around best practice for securing internet connected devices.”

This initiative is a key part of the Government’s five-year, £1.9 billion National Cyber Security Strategy which  claims to be making the UK the most secure place in the world to live and do business online.

 


Comments

One comment

  1. Phew, that’s ok then; the Government are sorting it out…
    What was it that Ronald Reagan said?
    ‘The most terrifying words in the English language are: I’m from the government and I’m here to help.’

Leave a Reply

Your email address will not be published. Required fields are marked *

*