enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Arcelik Global

Challenges in Establishing IoT Security

Cagatay Buyuktopcu, Head of IoT Cyber Security, Arcelik Global

IoT security is not IT security. They look similar, but the similarity between them is not more than the similarity of ‘car’ and ‘carpet’. Although there are many different estimations about the total possible number of deployed IoT devices in the coming years, it is obvious that there will be billions of them around. So actions should be taken very carefully for the cyber security infrastructure of IoT systems and it should be managed with a different mindset from the IT world.

There is no plug-and-play solution to create an end-to-end cyber-secure IoT infrastructure. There are no quick-win solutions. There is no miraculous solution that can make your IoT infrastructure secure by just adding a component or library into your system, whereas you can find many examples on the IT side.

In an IoT device, processors are not as powerful as in an IT infrastructure. You may have to work with a resource-constrained microcontroller with limited ROM/RAM capacity. As a result, you will have to work with lightweight cryptographic algorithms tailored for an embedded device. Whereas on the IT side, you can deploy complex algorithms easily and one after another.

In addition, the heterogeneity of the IoT ecosystem is much bigger compared to IT. Some IoT devices may have bare metal embedded software, some may have embedded Linux or Android operating systems. Some of them may have Bluetooth connectivity, others may have Wi-Fi, Lora, and Zigbee. Apart from these wireless communication protocols, embedded system wired communication diversity is also very broad in IoT devices with UART, SPI, I2C, and CAN. After downloading your OTA software image into your IoT device, installation of that package should be handled via one of those different kinds of wired protocols. So, it is not straightforward to establish a secure software update mechanism in an IoT device.

"Your IoT devices can run in millions of houses located in more than 140 different countries around the World. However, in a server or a smart factory, OT/IT network is under your control."

Furthermore, an IoT device is mostly running in an open environment in which the network is not under your control. Your IoT devices can run in millions of houses located in more than 140 different countries around the World. However, in a server or a smart factory, OT/IT network is under your control. In case of an incident, you may take action easier in such a controlled environment than in a distributed IoT ecosystem. We have created a tailor-made IoT Incident Response policy for our products running in different locations of the World.

To solve these challenges and sustainably manage them, creating or working together with a talented IoT security team is very critical. The talent pool problem is very big in the IoT security ecosystem compared to IT security. It is not easy to find an embedded system expert who is also willing to gain expertise in cyber security and become an embedded security expert. It is also not so easy to find a native iOS and Android mobile application developer who knows what OWASP Top 10 is and can design mobile security solutions in different native languages. Sama's challenge applies to developers in the cloud domain as well. IoT means edge, mobile, and cloud altogether. You should be well qualified in every domain individually and also in end-to-end communication between them.

Some IT-based companies who want to get a share of the IoT security market, are trying to solve this with mergers and acquisitions. That is because the IoT security market is expected to reach $40 billion in 2026 with 22 percent YoY. This is attracting most of the IT security solution providers to enlarge their product portfolios and market share. However, to create a sustainable workforce for IoT security, the bottom-up approach can be the most efficient way instead of the top-down approach as IT security companies are trying to do. If you can create a Blue Team, who started their career in embedded software (whether with MCU or MPU) and then continue to learn cyber security basics, they will be able to design required cyber security solutions more efficiently. For the mobile security side of Blue Team, developers should be an expert in mobile application development in different native domains. With such developers at hand, it will be more efficient to create seamless cybersecurity libraries for different platforms without degrading the UX or any other performance metric of the application itself.

It is also the same in Red Teaming activities. Currently, most of the usual Red Teaming activities are being done in the IT world. But IoT Red Teaming should be more than that. IoT devices’ vulnerability analysis and pen testing require many additional actions compared to the IT side. Otherwise, you may not be able to find actual vulnerabilities that are hidden in your system.

In Arçelik Group, one of the biggest home appliance manufacturers in the World, we created an IoT Security Team which includes 3 virtual teams: Red Team, Blue Team, and Purple Team. These teams specialized only in IoT security side. We are periodically making IoT Red Teaming activities for our connected home appliances. The Purple Team is following different international standards and regulations and gives related technical feedback to the Blue and Red Teams. They are also responsible for following Secure by Design checklists, and Software Bill of Material creations. With the help of all these efforts, we are trying to create a sustainable and end-to-end IoT cyber security infrastructure for our connected product ecosystem, which we call HomeWhiz™.

Solving all these challenges will not be sufficient. Some IoT standards will be mandatory, especially for European countries and the UK. Your end product will have to be tested by an accredited cyber security laboratory and get IoT Security approval for these coming regulations. For now, the most popular candidate for this is ETSI EN 303 645 standards with August 1st, 2024 deadline. As producing more than 1 million connected home appliances in a year, our aim is not just to be fully compatible with upcoming regulations but also to lead the industry to set the standards to a higher level.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.