{"id":6803,"date":"2025-01-06T09:00:00","date_gmt":"2025-01-06T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/iot-regulatory-reckoning-overdue"},"modified":"2025-01-06T09:00:00","modified_gmt":"2025-01-06T15:00:00","slug":"iots-regulatory-reckoning-is-overdue","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/06\/iots-regulatory-reckoning-is-overdue\/","title":{"rendered":"IoT&#8217;s Regulatory Reckoning Is Overdue"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4b7d3fb3b8f15857\/677ae02575fa3b1a33363565\/IoT_%281800%29_Panom_Bounak_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The regulatory clock is ticking on the Internet of Things (IoT). In October, European lawmakers officially adopted the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/eu-cyber-resilience-act-regulate-internet-of-things\">Cyber Resilience Act<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, ushering in much-needed security thresholds for connected devices across the region. Meanwhile, United Kingdom makers are already navigating world-first <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.techradar.com\/computing\/cyber-security\/the-uk-is-banning-weak-passwords\">device security and privacy rules<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and the United States is preparing to launch its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/fcc-approves-voluntary-cyber-trust-labels-iot-products\">Cyber Trust Mark<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s about time. For too long, default passwords and weak authentication practices were accepted as the status quo in connected devices, wreaking post-pandemic botnet and hacker havoc. But now, amidst the rapid rise of endpoints powering the smart home and office, governments are finally taking a stand and setting standards.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For manufacturers, this regulatory reckoning is unavoidable across the world&#8217;s most lucrative markets, forcing them to get up to code or fall behind. What&#8217;s clear is the sooner companies evolve, the better the outcome for troubleshooting, performance, and users. Let&#8217;s explore the urgency and opportunity for connected device creators heading into 2025.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Profits Over Protection\">Profits Over Protection<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Device makers haven&#8217;t done themselves any favors over the past few years. Many are cutting corners and abandoning cybersecurity cornerstones in a race to the lowest price. Default passwords, non-existent software updates, and zero vulnerability testing are creating bigger attack vectors ripe for exploitation. Botnets, for example, are booming, with botnet-driven distributed denial-of-service (DDoS) devices increasing by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nokia.com\/about-us\/news\/releases\/2023\/06\/07\/nokia-threat-intelligence-report-finds-malicious-iot-botnet-activity-has-sharply-increased\/\">five times in the past year<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Even more concerning? Device numbers will double over the next 10 years, to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.statista.com\/statistics\/1183457\/iot-connected-devices-worldwide\/\">more than 40 billion worldwide<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, quadrupling the pre-pandemic figure. Something&#8217;s got to give, and governments know it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Europe, in the footsteps of the General Data Protection Regulation (GDPR), is again leading the tech regulation charge. The Cyber Resilience Act is the most comprehensive suite of coming changes, with an obligation for manufacturers to protect their Internet-connected products from unauthorized access throughout their life cycle. This demands products without known exploitable vulnerabilities \u2014 a tall order requiring design, development, and production that ensures an appropriate security level at all times.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, the UK&#8217;s Product Security and Telecommunications Infrastructure Act tackles many of the same themes but with a lower bar to clear. Passed in April, the act requires minimum security update periods (rather than lifetime) and mandatory security issue reporting back to consumers. The best part of this act is the ruling on passwords \u2014 devices must either have a randomized password or generate a unique one during initialization. This is a great step that goes a long way to stopping hackers from accessing smart devices, infecting local networks, and creating botnets.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, the US is betting on market forces. The Cyber Trust Mark, similar to Energy Star, offers voluntary certification for products meeting &#8220;robust&#8221; security standards. The hope? Consumer choice will drive industry change. One thing is evident across markets: Governments are taking this threat seriously and acting accordingly. It&#8217;s now up to makers to meet the moment and move in kind.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Move Now or Move Aside\">Move Now or Move Aside<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">My advice to connected device makers? Prepare now. If you want access to the world&#8217;s largest markets (and I suspect you do), there&#8217;s only a short window to get up to code. Sure, Europe&#8217;s act is now in a three-year transition before taking full effect, but getting this right demands investment, time, and troubleshooting. These are big hurdles, and 2027 isn&#8217;t far away.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is something we learned from the GDPR. The new rules didn&#8217;t just require writing a report \u2014 they demanded system adjustments and subsequent costs. On average, firms spent more than \u20ac1 million ($1.06 million) on readiness initiatives, but justified the investment by retaining access to the bloc and avoiding business-threatening fines (not to mention better protecting consumer data).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, what does this say to device makers? Simple \u2014 start getting up to standard now with best practice authentication, encryption, and communication. Make sure security updates are part of your product planning, reconsider your approach to passwords, and implement consistent testing, patching, and reporting. Yes, this takes valuable resources, but the payoff is clear \u2014 better products, stronger security, and lasting consumer trust.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"This Is Beyond Compliance\">This Is Beyond Compliance<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I&#8217;m relieved to see these regulations come into force. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.helpnetsecurity.com\/2024\/10\/31\/connected-device-privacy\/\">Device makers have lacked respect<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for their creations, consumers, and \u2014 frankly \u2014 themselves for several years. The rise of cheap and lazy products isn&#8217;t an accurate reflection of IoT ingenuity. Sincerely, I hope these regulations weed out the bad apples, set an acceptable bar of baseline requirements, and give confidence back to consumers and enterprises.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Device makers, it&#8217;s now up to you. Don&#8217;t just treat these new regulations as mere compliance hurdles, but seize them as opportunities to build better products, restore trust, and lead the next chapter of our sector&#8217;s innovation.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/iot-regulatory-reckoning-overdue\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The regulatory clock is ticking on the Internet of<\/p>\n","protected":false},"author":12,"featured_media":6804,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/iots-regulatory-reckoning-is-overdue.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6803"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6803\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6804"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}