This week, the Biden Administration convened a meeting at the White House to discuss Internet of things (IoT) ratings, with the intention of improving the cybersecurity of Internet-connected devices. Launching in 2023, representatives from the public and private sectors intend to form a labeling system where products are rated based on their cybersecurity. Ultimately, the administration’s goal is to implement a barcode-like label that consumers and organizations can scan to learn more about a device’s security performance.
The initiative comes at a time when IoT devices present unprecedented threats to organizations and consumers alike. IoT devices currently exist in a sort of “Wild West” environment – organizations and consumers are largely in the dark when it comes to the security of these devices. As recent events have shown, the consequences of using and deploying vulnerable IoT devices can be disastrous and even life threatening.
The Status Quo Explained
The proliferation of IoT devices has presented security challenges to their users. Too often is security performance for these devices ignored or inadequately addressed; and much of this is due to a market-driven need to hit the market quickly, cheaply, and with as little friction as possible. The IoT market is a fast-paced, profit-focused industry where security is often an afterthought.
As such, the status quo of IoT device security is lacking at best. This means organizations and consumers are likely to at some point use – individually or at scale – a vulnerable IoT device. For an organization this could mean deploying a vulnerable GPS device to hundreds or thousands of delivery vehicles; and from the consumer side of things, this could mean personal information is easily intercepted by hackers given a device’s poor communications security.