Feature: Consumer electronics
security issues in IoT, making it easier for hackers to access devices through easily- guessed and universal default values. By discontinuing this practice and using randomised pre-installed passwords unique to each device, as well as requiring the user to choose a password that follows best practice during setup – including multi- factor authentication, device security can be further strengthened.
2. Implement a means to manage reports of vulnerabilities Te EN standard states that the IoT device manufacturer should make a vulnerability disclosure policy publicly available, to offer an avenue to inform companies of security issues, putting companies ahead of the threat of malicious exploitation and giving them the opportunity to respond to and resolve vulnerabilities in advance of public disclosure. To do so, the policy made available by the manufacturer should include, at a minimum, contact information for issue reporting, and information on timelines for acknowledgement of receipt and status updates on the resolution. A Coordinated Vulnerabilty Disclosure (CVD) – a set of processes for dealing with and resolving the potential security vulnerability disclosures – can be defined to allow companies a framework for managing this process. ETSI provides an example CVD process in TR 103 838 that specifically targets SMEs that have no CVD schemes in place.
3. Keep software updated Developing and deploying security updates in a timely manner is one of the most important actions a manufacturer can do to protect its customers and the wider technical community. With the implementation of regular, easy to apply and, where possible, automated updates, companies can reduce the risk surrounding the IoT devices. Also, updates can be issued as a preventative matter, which can remove security vulnerabilities before they are even exploited. Tis can be a complex process to manage, hence a clear management and deployment plan is beneficial to the company to promote transparency to its consumers.
[Image: Tim Kabel for Unsplash]
The price of IoT security It goes without saying that security comes at a cost and with many challenges for the manufacturer. Te value of implementing cybersecurity IoT processes is mainly to protect end users, to keep them and businesses safe, yet organisations tend to forget that ensuring consumers remain safe from cyberattacks also protects their brand integrity, too. Because, when that integrity is called into question, consumer buy-in can falter and ultimately affect the business. As studies suggest that over 25% of
all cyberattacks will involve the IoT, it is imperative that organisations across the globe work toward ensuring optimal protection against consumer IoT device attacks. As technology advances, so do vulnerabilities; if countries across the world continue to recommend and enforce compliance to cybersecurity standards, IoT device manufacturers can ensure that they have a strong foundation for protection, providing a stronger defence against cyberattacks and keeping homes and businesses safe.
[Image: Towfiqu Barbhuiya for Unsplash]
www.electronicsworld.co.uk October 2022 25
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40