enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Arcelik Global

Securing the Digital Connectivity with Cutting-Edge Technologies

Cagatay Buyuktopcu, Head of IoT Cyber Security, Arcelik Global

During his 10 year designer period, Çağatay has designed many different embedded software first with assembly language, and then with C for different types of microcontrollers. Then he designed Qt GUI software with C++, and continued with embedded Linux&Android u-boot design running on microprocessors.

In an interview with Enterprise Security, Cagatay Buyuktopcu, Head of IoT Cyber Security at Arcelik Global, highlights the technological advancements transforming the IoT cybersecurity domain. He highlights the future of IoT appliances and how cybersecurity will play a role. He also highlights the various challenges associated with the field and how the company, with its years of experience, has improved people's living standards.

What were your Roles in The Previous Organizations you have Worked for, and How Does that Experience Augment your Role and Responsibility at Your Current Organization?

I started my career dealing with embedded systems, including software and hardware. I made software and embedded hardware designs for different projects during my engineering period. After that, we created a platform to connect to the IoT and added some connectivity levels to the products. We took cybersecurity as an input from scratch and embedded related hardware and software security features into our products. We also created our cybersecurity levels in both mobile applications and websites.

We are now experiencing a bottom-up approach and coming directly into the design of electronics, software, and embedded systems. We can change our products to connect the IoT platforms, and now we are dealing with the cybersecurity infrastructure.

After making this connectivity platform of connected appliances, the quantities of the products are increasing every year. We are producing more than 1.3 million connected products yearly, and the amount is growing exponentially.

In 2025, we expect more than 10 million connected IoT products in the field. In the meantime, the technical heterogeneity of these IoT devices is increasing rapidly, which is why we are focusing on cybersecurity infrastructure with an individual team in our company.

Looking at the global numbers, 127 new IoT products are coming live and connecting to the internet every second. In the 2030s, it will have more than 50 billion IoT products globally. These devices will start to communicate with electrical grids and smart vehicles. The related attack surface they should manage will increase exponentially because of the interoperable verge in coming years.

This is where IoT cyber security is differentiating from IT and OT security. In IT and OT environments, the network is under our control. By isolating the network restart and getting a reset, these IoT devices will work in more than 150 countries simultaneously and in millions of houses separately.

It is challenging to manage this in the coming years, and because of these challenges, governments are trying to create national and international IoT cybersecurity regulations. The most famous one is the ETSI EN 303645-based directive, active after 2024. Another regulation, the cyber resilience act, will be active in 2028. Some discussions are still going on for IoT products to have cybersecurity labeling on them to inform the consumers about the cyber resilience of the product before the purchasing process.

Assessment organizations like Which magazine from the UK have started to evaluate products to assess them for cybersecurity cases. The magazine selected one of our connected ovens best because of its cyber resilience features. The increasing awareness enables universities, magazines, and some private companies to undertake experiments and research.

Research done by the NCC Group and Which magazine in the UK found that in every 14 successful attacks, one attack is made on smart home appliances and will increase yearly.

IoT devices are being attacked in three ways. They are— IoT as a tool, IoT as a target, and IoT as a witness.

One example of IoT as a tool can be a malignant attack, the Mirai botnet attack of 2016. It was one of the biggest milestones in IoT security, with some positive and negative effects. The hackers wanted to use IoT devices to attack some other main target, and millions of appliances were used as a tool.

" We are Experiencing a Bottom-Up Approach and We can Change our Products to Connect to the IoT Platforms by Dealing with the Cyber Security Infrastructure of those "

In 2017, hackers hacked a Cayla toy in Germany, and they could communicate with children playing with it. The German government immediately decided to collect all the toys from the field. It was a good example of IoT as a target because attackers just wanted to take the device's contents towards the attack mechanism.

In a scenario that can be summarized as IoT as a weakness, hackers aimed to get critical information from the device or server where the device is sending data. The hackers are trying to use it as a ransomware issue, and because of these reasons, we believe that in the next five to 10 years, IoT security will be a huge need for consumers, companies, and governments.

What are the Current Challenges that you see in the Enterprise Security Sector?

In IoT cybersecurity, no plug-and-play solution will help you be secure. We will have to embed the latest cybersecurity solutions in the implanted device, the mobile application, and the cross-site. We should create a tailored solution for the microcontroller-embedded operating system, iOS, Android site, and cloud services to create an entrenched security ecosystem.

This is one of the biggest challenges, and more is needed to get an IoT cybersecurity certification for the product. Mobile application security will be critical since mobile will be the main computing platform. There is no cybersecurity awareness, especially on the IoT and consumer electronics side, so every application should have a cybersecurity solution.

What are Some of the Technological trends which Excite you for the Future of the Enterprise Security Sector?

The upcoming IoT cybersecurity regulations are affecting the future majorly because the forthcoming regulations will ask for a hardware security module for IoT products, which means that we will have to hide private keys in the IoT device in secure hardware. This hardware can be a part of the microchip as a peripheral safe zone. It can also be a separate chip in the embedded code, and that is why every IoT device will have to have such an embedded IC, and it is affecting semiconductor companies.

Through a portfolio, for example, Arcelik Global is one of the first home appliance companies to embed such a hardware security module in 2016. At those times, few IoT[1]based HSMs were in the field, and we were using microchips ECC 508.

In the long term, quantum computing and post-quantum cryptography will impact IoT security sites. NIST has decided which PQC algorithms can be used in the upcoming years. In four to five years, the semiconductor companies will release new chips, and the new peripheral chips will come to the scenario where products should be designed accordingly. Since there will be a transition period, whenever those new semiconductor ICs go into the market, the companies that will quickly change the infrastructure with new solutions will be more beneficial after 2030.

What is your Advice for Other Senior Leaders and CXOs Working in the Industry?

We experienced a lot in IoT and cybersecurity at Arcelik Global and are starting to provide our solutions and services to other IoT device designers and manufacturers to create more value that increases consumer awareness in the market. All of these embedded security, mobile application security, and cloud security solutions can be used by others.

We are willing to increase the synergy of helping the users in case of any need. We are an experienced firm since our product range is very broad. We are using more than a dozen IoT services now in the Amazon Web Service for our cloud services. We experienced a lot of making such complex IoT services, cloud services, and security configurations. To summarize, we are willing to share our experience, solutions, and services with other companies who may need help with IoT cybersecurity.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.