Regulation is the only way to control the IoT cyber-security threat, says Databarracks

The Internet of Things (IoT) will be the source of more data breaches, as we see mass adoption and rapid growth in the number of connected devices, both in consumer products and the Industrial Internet of Things (IIoT). This is according to business continuity and disaster recovery firm, Databarracks.

The scale of vulnerability of IoT was recently highlighted by Trend Micro, which found flaws in two of the most popular IoT protocols with hundreds of thousands of exposed public-facing IPs uncovered by the study. Additionally, recent research by Databarracks found that 57 per cent of organisations are concerned about the security of IoT.

The government has been proactive in addressing IoT security risks publishing the Secure by Design report in March of 2018 and introducing a Code of Practice for consumer IoT security. Peter Groucutt, managing director of Databarracks, argues that while the introduction of a Code of Practice is a positive step, it is not enough to sufficiently address the issue of IoT security:

“The content, guidelines and recommendations in the Code of Practice are excellent. It addresses the most fundamental cyber security practices in order of criticality and importance. But the scheme doesn’t prohibit non-compliance. We should take inspiration from countries such as the US and Thailand in seeking to make these requirements legally enforceable.

“Expert estimates vary in total quantity, but agree we’re now seeing sharp, hockey-stick growth in the number of connected devices. A lack of diligence and care now will lead to trouble later.

“Our lack of regulation means we see instances as serious as insecure children’s smartwatches. The Code of Practice will be adhered to by the diligent parties in the IoT supply chain, but it won’t prevent less committed companies favouring profit over security and pushing insecure products to market. The same company that produced these smartwatches was also found to be making insecure video baby monitors earlier this year.”

Groucutt continues, “We often talk about digitalisation and digital transformation in business.  From banking to healthcare, more of our lives are digital and online. There is a real difference between the relationship we used to have with technology and the world of IoT. As users, we were more involved with our desktop computer, installing antivirus software and making decisions about how we use it. With IoT devices, we are far less involved, we have less control over settings and we have many more devices to manage. Changes must be made to make the makers of these devices more responsible.

“The Code of Practice is currently only for consumer devices such as health trackers, smart home assistants and children’s toys and monitors. We recommend extending this reach.

“IoT devices aren’t just found in the consumer world. They are used on corporate networks which are only as strong as their weakest links. For example, earlier this year it was revealed that a casino was hacked via a thermometer in a fish tank. We advocate making the Code legally enforceable which is thankfully something the government is already considering and is an approach supported by several cyber experts.

“There is the argument that government interference might limit the UK’s ability to compete with other less regulated markets. But device security is now so fundamental that better regulation could be a competitive advantage and differentiation point for our manufacturers, service providers, developers and retailers.” concludes Groucutt.

www.databarracks.com

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

i-PRO

NHS Hospital Transforms with i-PRO Camera System

i-PRO announced that a teaching NHS hospital in Northeast England, has enhanced its security infrastructure with i-PRO X-Series cameras…
Gallagher Security

Gallagher Security empowers Channel Partners

Gallagher Security is proving its commitment to empowering its UK and European Channel Partners with the launch of its new Channel Partners..
Skills for Security

Skills for Security Partners with Videcon, EEN and Paxton

Skills for Security is proud to announce strategic partnerships with Videcon, Eagle Eye Networks, and Paxton Access Control…
Abloy UK

Abloy UK appoints new Digital Access Solutions Academy Manager

Carl Bridgwood has been appointed as the new Manager of Abloy UK’s Digital Access Solutions Academy, a purpose-built facility…
Skills for security

Skills for Security Announces Charity Partner for 2025

Skills for Security is proud to announce Footprints Conductive Education Centre as its official charity partner for 2025.

Skills for Security Celebrates Winners of the WorldSkills UK Finals

Skills for Security proudly celebrates the winners of the WorldSkills UK Finals in two categories…
Matt Humby website

Raising awareness on lithium-ion battery fires

Leading experts scheduled to present at Anticipate London, bringing together insights from the Safety and Health Expo, FIREX, Facilities Show and IFSEC.
BSIA

BSIA appoint new non-executive directors to Association Board

The British Security Industry Association (BSIA) has appointed Pauline Norstrom and Uzair Osman as new non-executive directors…
Scroll to Top