+44 (0)203 88 020 88

Menu

Search

Cyber Security News & Articles

 

Cyber Security
News & Articles

Trusted Cyber Security Experts
25+ Years Industry Experience
Ethical, Professional & Pragmatic

New law to make IoT devices more secure

The UK Government has introduced new legislation which will improve the security of smartphones, IoT devices and connected appliances.

The Product Security and Telecommunications Infrastructure (PSTI) Bill will require the manufacturers, importers and distributors of consumer connectable products to comply with cyber security good practices. According to the Government the regulations that flow from the new law will:

Ban default passwords. Products that come with default passwords are an easy target for cyber criminals.

Require products to have a vulnerability disclosure policy. Security researchers regularly identify security flaws in products, but need a way to give notice to manufacturers of the risk they have identified, so that they can enable the manufacturer to act before criminals can take advantage. The Bill will provide measures to help ensure any vulnerabilities in a product are identified and flagged.

Require transparency about the length of time for which the product will receive important security updates. Consumers should know if their product will be supported with security updates, and if so, what the minimum length of time is that they can expect that support to continue.

The average UK household currently has 9 consumer connectable devices, many of which lack basic cyber security protections. The government estimates that the UK economy loses £1billion a year through cyber attacks such as DDoS – and poorly secured consumer and IoT devices make up much of the botnet infrastructure that powers these attacks.

This new legislation has just started being considered by Parliament and is not yet in force, and the Government has said at least 12 months’ notice will be provided for the precise regulations to give suppliers time to comply.

Failure to comply with the new regulations could be costly, attracting fines of up to £20,000 per day.  This new legislation applies only to consumer products, not those aimed at businesses.

Another new piece of legislation which has now come into force (in November 2021) is the Telecommunications (Security) Act 2021.  This new law places a duty on telcos to take security measures both in terms of following good practice and specific instructions defined by the NCSC. It also requires them to take action in the event of a security compromises – including the ability to require them to take specific actions through new regulations.   OFCOM is the regulator with the powers to monitor and enforce this new law and fines for non-compliance can reach £100,000 per day or 10% of turnover for the business.

While any reasonable Security Manager may shake their head in wonder that telcos need a law to force them to follow appropriate cyber security practices – the resulting regulations may end up defining a useful benchmark of ‘the minimum cyber security required’ that other large organisations may be able to use to help justify their own cyber security budgets.

 

 

Subscribe to our monthly newsletter today

If you’d like to stay up-to-date with the latest cyber security news and articles from our technical team, you can sign up to our monthly newsletter. 

We hate spam as much as you do, so we promise not to bombard you with emails. We’ll send you a single, curated email each month that contains all of our cyber security news and articles for that month.

Why Choose SecureTeam?

CREST
CCS
ISO9001
ISO27001
CE-PLUS

Customer Testimonials

“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”

Aim Ltd Chief Technology Officer (CTO)

"Within a very tight timescale, SecureTeam managed to deliver a highly professional service efficiently. The team helped the process with regular updates and escalation where necessary. Would highly recommend"

IoT Solutions Group Limited Chief Technology Officer (CTO) & Founder

“First class service as ever. We learn something new each year! Thank you to all your team.”

Royal Haskoning DHV Service Delivery Manager

“We’ve worked with SecureTeam for a few years to conduct our testing. The team make it easy to deal with them; they are attentive and explain detailed reports in a jargon-free way that allows the less technical people to understand. I wouldn’t work with anyone else for our cyber security.”

Capital Asset Management Head of Operations

“SecureTeam provided Derbyshire's Education Data Hub with an approachable and professional service to ensure our schools were able to successfully certify for Cyber Essentials. The team provided a smooth end-to-end service and were always on hand to offer advice when necessary.”

Derbyshire County Council Team Manager Education Data Hub

“A very efficient, professional, and friendly delivery of our testing and the results. You delivered exactly what we asked for in the timeframe we needed it, while maintaining quality and integrity. A great job, done well.”

AMX Solutions IT Project Officer

“We were very pleased with the work and report provided. It was easy to translate the provided details into some actionable tasks on our end so that was great. We always appreciate the ongoing support.”

Innovez Ltd Support Officer

Get in touch today

If you’d like to see how SecureTeam can take your cybersecurity posture to the next level, we’d love to hear from you, learn about your requirements and then send you a free quotation for our services.

Our customers love our fast-turnaround, “no-nonsense” quotations – not to mention that we hate high-pressure sales tactics as much as you do.

We know that every organisation is unique, so our detailed scoping process ensures that we provide you with an accurate quotation for our services, which we trust you’ll find highly competitive.

Get in touch with us today and a member of our team will be in touch to provide you with a quotation. 

0

No products in the basket.

No products in the basket.