Written evidence submitted by the Department for Digital, Culture, Media and Sport

 

Written evidence from the Department for Digital, Culture, Media and Sport (DCMS) to the DCMS Select Committee Inquiry into Connected Tech

 

Introduction

1.      DCMS is pleased to respond to the Select Committee’s Call for Evidence requesting views on the impacts of the increasing prevalence of smart and connected technology and what needs to be done to ensure it is safe and secure for its users.

 

2.      Connected technologies, often referred to as the Internet of Things (IoT), are increasingly common in our homes, workplaces, and communities. This technology is transforming the way we live and work, and has further potential to improve productivity, efficiency, and connectivity. As set out in the recent UK Digital Strategy, this Government is committed to ensuring that the benefits of digital technologies are felt across the UK and has invested in providing skills for the existing workforce and for future generations, to ensure that all can share in the success of our digital economy.[1] We are working with industry to maximise growth and innovation in this area, including through the recent BEIS led consultation ‘Enabling a national Cyber-Physical Infrastructure to catalyse innovation’.[2] However, we need to ensure these technologies can fulfil their potential while protecting citizens and enterprises from malicious misuse. This response sets out the interventions and levers that the Government is using to reduce risk across the connected technology landscape.

 

3.      The Integrated Review of Defence, Development and Foreign Policy (2021) set out the need to improve the UK’s overall resilience to cyber attacks.[3] This includes developing a national capability in digital twinning to improve national resilience, of which IoT would be a critical enabler. This goes further in the recent National Cyber Strategy (2022), which commits to a robust and comprehensive plan to secure connected technologies across the UK.[4] This will be achieved through a range of activities that look to enable the UK to take the lead in technologies vital to cyber power, build resilience and a prosperous digital UK, and strengthen the UK’s cyber ecosystem.

 

Impact of smart and connected technology across the economy and society

4.      The positive benefits of connected technologies cannot be understated. Devices such as smartphones and smart speakers are used everyday by consumers, with on average nine of these products in every household.[5] Our offices increasingly benefit from connected office printers to conference calling facilities. The array of internet-connected sensors, cameras, and managed services have been vital throughout the COVID-19 pandemic to enable effective business continuity. There are also massive industrial applications, with the global IoT market for manufacturing applications expected to grow to $200 billion by 2030.[6] Our connected places use these technologies to manage traffic, reduce pollution, and deliver more efficient local services.

 

5.      Ofcom estimates there were 13.3 million IoT connections in the UK in 2016, of which 5.7 million were products such as consumer wearables and smart home devices. This is estimated to increase to 39.9 million connections by 2024. There were also an estimated 58 million smartphone users in the UK in 2019, expected to increase to 61 million by 2024.[7] In many cases these technologies rely on, or are augmented by, applications. For example, a virtual assistant can create a shopping list through voice command and an application can be used to purchase these items.

 

6.      These technologies will continue to make substantial strides forward over the coming years with more computing power, better internet connectivity and increased automation across our society and essential infrastructure. This progress is not limited to the devices themselves, but also the wider enterprise network infrastructure. This will vastly increase the volume of data generated to support connected technologies and the need to secure this data to enable an innovative economy, protect our national security interests, and our way of life. Further to this, our connected places are buying these technologies and embedding them across their infrastructure, and there is a need to make sure this is done effectively and securely.

 

7.      The cycle of more devices allowing greater connectivity, information and data is being mirrored by an increasing number of digital services (including managed services) and it is important to ensure that these areas of the ecosystem have appropriate security to allow continued growth.

 

Risks and threats

8.      The number of attempted cyber attacks in the first half of 2021 was double the 2020 figure for the same period.[8] The estimated cost to the consumer, from insecure consumer IoT alone, over the next ten years is £14.8 billion.[9] It is difficult to accurately gauge the economic impact of insecure connected technology. For example, an owner of a compromised device may not know that the device has been attacked and therefore not report the crime. The economic cost will increase with increased connectivity, and increased reliance on technology within operational technologies and information control systems. We have set out the key risks below:

 

9.      Consumer risk. Insecure products can be used in ways not intended by the consumer, such as internet-connected security cameras being hacked in Singapore.[10] Footage from the hacked cameras in Singapore was shared online and uploaded to adult websites. Insecure products can also act as the ‘point of entry’ across a network, enabling attackers to access valuable information. In 2017 and 2018, a range of vulnerabilities were identified that allowed attackers to access personally identifiable information including the linked mobile phone number and GPS coordinates for smart watches of around 1 million people and intended to be used by children.[11]

 

10.  Consumer connectable devices can also be compromised at scale as part of distributed denial-of-service (DDoS) or ‘botnet’ attacks. For example, in 2016 cyber criminals compromised 300,000 products with the Mirai malware. The attackers utilised the collective computing power to successfully disrupt the service of many news and media websites including the BBC and Netflix.[12]

 

11.  When these vulnerabilities were found in children's smart watches, the users and the security researchers who found the vulnerabilities were unable to contact the manufacturer to report their concerns and so the vulnerabilities could not be addressed. If manufacturers do not have a vulnerability disclosure policy, there is a risk that users continue to be exposed, without reassurance or clarity on whether this will be addressed.

 

12.  If we do not support and encourage international alignment around cyber security standards for consumer connectable products, there is a risk of a fragmented global approach. This would result in UK consumers being at risk of buying insecure devices from overseas.

 

13.  Enterprise risk. We are aware of the significant concerns about the security of IoT products used in an enterprise setting. These potential vulnerabilities may provide a route for hostile actors to attack enterprise systems. For example, attackers accessed a US casino’s customers’ details via initially hacking a connected fish tank thermometer.[13] The Product Security and Telecommunications Infrastructure (PSTI) Bill, currently before Parliament, addresses some of the risks to businesses from connected technologies but the legislation is not designed or intended to fully protect enterprises. As such, DCMS published initial research into enterprise IoT area and key findings include:

○        enterprise connected devices, such as enterprise printers, and room booking systems, are being deployed and relied on by many organisations and  there are significant concerns from IT professionals about the security of these devices.

○        vulnerabilities are regularly found in enterprise connected devices which have put large numbers of organisations at risk.

○        organisations lack clarity on how to monitor and protect themselves from vulnerable connected devices.[14]

 

14.  Without international agreement on necessary cyber security measures for connected products, there is a risk to trade. International partners and organisations could establish differing baseline expectations for connected product security. A lack of international alignment would impact UK enterprise. In a situation where there is inconsistency, UK enterprise would potentially not be able to either import products to the UK or sell products abroad, if security expectations were different. 

 

15.  Risk to critical national infrastructure. A single insecure device can be used as a route into wider systems, including those in critical national infrastructure, and disrupt essential services. For example, attackers gained access to Israeli water treatment facilities in 2020 and tried altering water chlorine levels before being detected and stopped. Further to this, in May 2021, the operators of the US’s largest fuel pipeline, Colonial Pipeline, suffered a ransomware attack. This led to Colonial having to shutdown the pipeline that delivers an estimated 45% of the East Coast’s supplies of diesel, gasoline and jet fuel. The shutdown was necessary to prevent the malware spreading to Colonial’s systems that monitor and control the actual physical operation of the pipeline.

 

Government approach to ensuring the security of devices and its users

16.  There is no single intervention available that will address all the risks created by connected technology. Instead a range of interventions are required. The National Cyber Strategy sets out the full range of objectives that the government is seeking to deliver. In particular, to secure connected technology, the government is focussed on:

○        Designing security into digital products and services, applying essential security standards and security principles.

○        Robust organisational security, securing access, maintaining, monitoring and having access to the right capabilities to respond to incidents.

○        Greater awareness amongst consumers, organisations deploying this technology, and the manufacturers and developers of this technology.

 

Designing security into digital products and services

17.  Consumer devices.  At the forefront of the Government response is the PSTI Bill: legislation that will embed basic security across connected devices made available to UK consumers. This removes the onus from UK consumers and places responsibility on manufacturers to design products that are appropriately secure.

 

18.  Enterprise and other devices. While the PSTI Bill is focussed on consumers, the Government has used other statutory powers to enforce better security design across the economy. For example, smart vehicles will be covered by the existing Road Traffic Act 1988, and smart charge points are covered by the Automated and Electric Vehicles Act 2018. The Telecommunications (Security) Act 2021 gives national security powers for the Government to impose controls on public communications providers' use of designated vendors' goods, services and facilities in UK public telecoms networks. More generically, the Government has launched an initial set of security principles for enterprise connected devices, to be tested and challenged by industry partners.[15]

 

19.  Funding game-changing semiconductor design. These devices, and anything that uses a semiconductor (which is most digital technology), also require game-changing technology to ensure they are secure by design. Vulnerabilities in these products can be due to design flaws within the semiconductor chips themselves. To address this, the Digital Security by Design challenge was announced in January 2019 as part of the Government’s industrial strategy. Building on research from the University of Cambridge, the BEIS-led Digital Security by Design programme partnered with ARM to develop a processor prototype. The new technology will block many existing vulnerabilities, lower costs in cyber security, increase business productivity, and increase consumer trust.

 

20.  Securing digital services. Cloud or managed service providers who enable, facilitate or manage connected devices in their clients also need to design security into their systems. These service providers enable important growth and innovation across the economy but open the users of these devices, and third parties, to additional cyber security risks through a shared digital supply chain. The Government's proposed amendments to the Network and Information Systems (NIS) Regulations ensure that digital service providers are required to take adequate security measures.

 

21.  Securing apps. Connected devices are often controlled by apps. The UK app market, worth £18.6bn[16], needs to ensure that security is designed into their products. However, there are few rules governing the app development and the app stores where they are found. To provide better protection for consumers, the Government has launched a Call for Views on enhanced security and privacy requirements for app developers and app store operators.[17] The main proposal is a new Code of Practice setting out baseline security and privacy requirements. This would be the first such measure in the world.

 

22.  International standards. As part of our efforts to mitigate long term risks, we are working with international partners and organisations. Ensuring smart and connectable technologies are secure is a global problem that requires global alignment. The Government worked with the European Telecommunications Standards Institute (“ETSI”) to create the first international standard (EN 303 645) on cyber security for consumer IoT devices in 2020, based on the UK’s Code of Practice.[18] The Government is also building an international consensus to better secure consumer connectable products. Following close engagement, Australia’s Department of Home Affairs (2020) and India’s Department for Telecommunications (2021) have published Codes of Practice that align with the UK’s work.[19] There is further international alignment to the UK's approach, including work from Germany, Singapore, Finland and others.

 

23.  International industry support. In February 2022, the World Economic Forum published a Statement of Support (2022) highlighting the ETSI standard and emphasising the importance of internationally aligned consumer IoT security. This was endorsed by 103 organisations, including Microsoft and Google.[20]

 

Robust organisational security

24.  Building resilience across the wider economy and society. The procurement from and management of suppliers, and devices, is critical for organisations to manage the risks of connected technologies they use. The NCSC offers a range of support to help organisations secure their networks. This includes Cyber Essentials which is a government backed standards certification scheme to recognise minimum levels of security within a supply chain.[21] The Cyber Essentials technical standard was updated in early 2022 to reflect the use of connected devices where connected to an enterprise network. This reflects the growing need to ensure an organisation’s security through focus across all their connected technological estate. The government also intends to introduce a range of measures aimed at improving the UK’s audit, corporate reporting and corporate governance systems. This will include a resilience statement, which will require the largest companies registered in the UK to have regard to cyber when making disclosures in their annual report.

 

25.  Supporting Critical National Infrastructure. The benefits and risks of deploying connected technologies must be considered in relation to critical national infrastructure. IoT devices can be integral parts of the network and information systems that support the critical or essential service that such organisations provide. These organisations are regulated by the Network and Information Systems (NIS) Regulations and are required to put appropriate and proportionate security measures in place for connected devices, and consider and mitigate the threats and risks to their systems from insecure IoT devices. Also relevant is advice on identifying business-wide cyber security risks and vulnerabilities such as the Cyber Assessment Framework, and specific Supply Chain Security Guidance.

 

26.  Developing Secure Connected Places. The Government is working to consider and manage the security risks associated with the deployment of connected places technologies, enabling the country and its citizens to benefit safely from the opportunities that they bring. Sometimes referred to as ‘smart cities’, a connected place is a community that uses a system of sensors, networks, IoT devices, and applications to collect and analyse data to better deliver services to the built environment, including transportation, buildings, utilities, environment, infrastructure, and public services. To support this, the NCSC cyber security principles were developed to help local authorities understand, design, and manage their connected places securely.[22]

 

27.  Data protection. Many of the principles in the Data Protection Act 2018 and the General Data Protection Regulation are closely linked to guidelines within the UK Code of Practice for Consumer IoT. These regulations have had a positive impact on cyber security, with 82% of organisations saying the improvements they had made were influenced by the introduction of the UK General Data Protection Regulation.[23]

 

Greater awareness

28.  National Cyber Security Centre guidance. Until the PSTI Bill comes into force, owners of consumer connectable products are encouraged to take action to ensure that they are using their devices safely. This includes through the successful Cyber Aware campaign and specific guidance from the National Cyber Security Centre (NCSC) on improving online security.[24]

 

29.  Digital literacy and cyber awareness. Across Government, we are supporting people through initiatives such as the DfE Digital Entitlement to provide essential digital skills training for adults and the DWP Claimant Commitment to support claimants develop their digital skills. We are also providing free advice on what people and small businesses can do to protect themselves from cyber attacks through the successful cross-government Cyber Aware campaign.[25] Cyber Aware has run on TV, radio, outdoor and digital channels over the past two years, with well over one million people visiting the website for advice.

 

30.  Protecting against harms and vulnerabilities. We are also taking a number of steps to improve the safety and trustworthiness of the online space for groups, such as older people, who are hesitant to access online services and use connected technologies, including increasing online safety through the Online Safety Bill, which will set a global precedent and equip the UK with the powerful regulatory and legal tools to keep internet users, especially children and vulnerable individuals, safe.

 

Going forward

31.  The policy and legislative work set out above is doing a vast amount to secure connected technology and protect users across the UK, enabling them to safely benefit from this technology. However, connected devices will continue to become increasingly widespread due to innovations in areas such as the metaverse, human augmentation, and industrial control systems. We are improving our ability to anticipate, assess and act on these emerging and critical connected technologies. This improved understanding will inform our cyber security efforts going forward, allowing us to take a more proactive approach to realising opportunities, mitigating risks, and developing appropriate policy responses.

 

June 2022

 


[1] UK Digital Strategy - GOV.UK

[2] Closed consultation: (BEIS) Enabling a national Cyber-Physical Infrastructure to catalyse innovation

[3] Global Britain in a competitive age: The Integrated Review of Security, Defence, Development and Foreign Policy

[4] National Cyber Strategy 2022-25

[5] Average number of connected devices in UK households 2020 | Statista

[6] IoT in Manufacturing Market Research Report: 2022

[7] Review of the latest developments in the Internet of Things, Ofcom, 2017 and  S. O’Dea, 2020, Forecast of smartphone user numbers in the United Kingdom (UK) 2018-2024

[8] Tech Republic - IoT device attacks (2021)

[9] PSTI Bill Impact Assessment (May 2021)

[10] The Straits Times (2020)

[11] Norwegian Consumer Council, press release (October 2017)

[12] Mirai botnet: Three admit creating and running attack tool - BBC News

[13] How a fish tank helped hack a casino - The Washington Post

[14] Cyber security in enterprise connected devices - GOV.UK

[15] NCSC Blog Post - Laying the new foundations for enterprise device security

[16] App Development in the UK - Market Size | IBISWorld

[17] Open consultation App security and privacy interventions 

[18] UK Code of Practice for Consumer IoT Security 2018

[19] Code of Practice: Securing the Internet of Things for Consumers, Australian Government. 2020 and  Code of Practice for Securing Consumer Internet of Things TEC 31318, Government of India. 2021.

[20] Joint statement of support on consumer IoT device security (February 2022)

[21] About Cyber Essentials - NCSC.GOV.UK

[22] NCSC Connected Places: Cyber Security Principles

[23] Impact of GDPR on Cyber Security Outcomes (August 2020)

[24] Top tips for staying secure online (NCSC)

[25] Cyber Aware - NCSC.GOV.UK