Menu

Call us on 03450 21 21 51

The UK has introduced a new Internet of Things cybersecurity bill: here’s what your organisation needs to know
The SRM Blog

The UK has introduced a new Internet of Things cybersecurity bill: here’s what your organisation needs to know

Andrew Linn

Written by Andrew Linn

15th December 2021

Share this article

Internet of Things cybersecurity bill

The Product Security and Telecommunications Infrastructure (PSTI) bill is the latest piece of legislation to hit the sector. It promises great things when enhancing the security of the ever popular Internet of Things (IoT) devices consumers and businesses alike rely on day in, day out.

As the popularity of connected devices – from smart home gadgets to wearables – continues to explode, cyber security issues are also growing.

According to the latest research from Kaspersky, cyber-attacks on IoT devices almost doubled (increasing from 639 million in 2020 to 1.5 billion during the first half of 2021), so it’s no wonder that the government has stepped in with this new legislation.

But what do you need to know about the Product Security and Telecommunications Infrastructure bill? And is it really all it’s cracked up to be?

The Internet of Things cybersecurity bill: A step in the right direction for passwords

The Product Security and Telecommunications Infrastructure bill focuses on three different areas to ensure the organisations manufacturing, importing and distributing IoT devices comply with a better standard of cyber security and in turn better protect consumers.

The legislation specifically bans the use of default passwords – which although simple, is deemed to be a significant step in the right direction for electronic goods. This common sense move is long overdue, but also presents a series of issues for manufacturers.

With unique passwords for every device, there’s a question of who will be responsible for managing each and every private password.

If the end-user forgets this password, manufacturers may need to develop and utilise super-user accounts or backdoor access to gain admission to devices, which could open up a whole heap of new vulnerabilities.

A middling response to vulnerability reporting

On the face of it, the PSTI provides a significant improvement for the reporting of security vulnerabilities. Under the legislation, it’s now mandatory for IoT manufacturers to provide a clear, public point of contact to end-users so security vulnerabilities can be reported more efficiently.

Yet whilst the contact and reporting procedures are clearer, nothing is mandatory about the fixing of reported flaws and bugs. With no specified lead time for fixing bugs, security flaws could become common knowledge and with this, be easily exploited by hackers and fraudsters on the lookout for an easy way into IoT devices.

A security support nightmare in the making

The third and final area that the PSTI aims to improve is the clarity surrounding just how long security updates will be provided by manufacturers for their IoT devices.

Before legislation, identifying this security support window was very much a guessing game for users. With clearer guidance around security updates, users can (in theory) be better prepared to protect their devices even after manufacturer security support has expired.

With end-of-life dates set to be in the mainstream however, the prospect of manufacturers selling off their outdated, almost expired tech could become a reality. Shifting IoT stock at a discounted price is better than not making a sale after all! Discounted IoT devices are certain to be attractive to consumers, which means a lot of tech without the security support it needs to protect the precious data within.

IoT manufacturers, importers and distributors have up to 12 months to make the changes they need and become compliant with the PSTI. Only time will tell if the bill will make the difference the government thinks it will or actually negatively impact IoT security standards.

Not sure how IoT devices might be affecting the risk posture of your organisation? Whether you feature an array of devices and smart tech in your office or have a remote workforce using digital assistants, smart doorbells and other connected devices, we can help you identify issues and necessary safeguards.

Contact us today to discuss your requirements.