Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New UK laws to protect IoT devices amid sales surge

Manufacturers of smart devices will need to be upfront about longevity of security updates

by The Gurus
April 22, 2021
in Cyber Bites
New UK laws to protect IoT devices amid sales surge
Share on FacebookShare on Twitter

New figures published by the UK government show that almost half (49%) of UK residents have purchased at least one new smart device since the beginning of COVID-19. As a result, manufacturers of smart devices such as phones, speakers, and doorbells will need to provide customers with information about how long they will be guaranteed to receive crucial security updates. Everyday devices such as these (or smart watches, TVs, cameras, etc.) have many positive benefits, yet they are extremely prone to being targeted by threat actors. Therefore, this groundbreaking plan is aimed at protecting individuals and companies from cyber attacks.

It’s important to remember that your network is only as strong as your most vulnerable device. According to Andy Norton, European Cyber risk officer at Armis, this new legislation “will raise the bar against the potential for attack, from a wide variety of threat actors, especially as we know advanced threat actors have invested in attack tools such as Fronton, that target IoT devices.” He also believes that “Smartphones are additionally a challenge, not just because of supportability during the lifecycle, but because they are used by people like, Dave. Dave doesn’t install updates anyway because they ruin his battery life. Dave also randomly installs apps on his phone from any store or market, Dave´s PIN number is 2580, which is also his burglar alarm code. Expanding legislation to support secure by design principles is a great addition to the security jigsaw, but, it is only a piece of the overall picture.”

Only 4 years ago, attackers managed to steal data from a North American casino using an internet-connected fish tank. More worryingly, other groups have succeeded in taking advantage of poor security features to access people’s webcams.

In an attempt to counter this persistent threat of cyberattacks, the UK government plans to make virtually all smart device manufacturers meet certain requirements:

  • Customers must be informed of the duration of time for which a smart device will receive security software updates
  • Banning the use of universal default passwords, such as ‘password’ or ‘admin’, that are easily guessable
  • Manufacturers must provide a public point of contact to make it simpler for users to report vulnerabilities
Niamh Muldoon, Global Data Protection Officer at OneLogin believes that “This new standard coming into effect establishes a baseline and guidance for manufacturers who need to be held responsible for following the best practices when designing ‘connected’ devices. Although such standards won’t eliminate all vulnerabilities, they could bring order to what is right now the ‘Wild West’ of IoT.

There remains an urgent need for education and awareness on access control and secure configurations for IoT devices, including cameras. IoT device manufacturers should deploy IoT devices with the highest security and privacy configuration possible so that it would be the end-users who are then making a conscious decision themselves to alter and change device settings. User-guide manuals should also outline associated threats and vulnerabilities for making these changes.”

ShareTweet
Previous Post

PRODUCT REVIEW – Edgescan makes fullstack vulnerability management easy

Next Post

Signal CEO hacks mobile-hacking firm

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol