Cybersecurity Baseline for IoT – Grace Burkard, ioXt Alliance
Grace Burkard, director of operations for ioXt Alliance, explains why having a cybersecurity baseline for Internet of Things (IoT) devices used by consumers represents a significant step forward.
Transcript
This is Textron TV. Hey guys. Thanks.
The throw we're here with Grace burkert who is director of operations for the io XT Alliance, which is a Consortium of folks who are getting together to figure out what's going on with security as it relates to Edge Computing and anything connected to the internet These Days Grace welcome to show Yeah, great to be here. Thanks for having me. For as long as I remember, every time we have a quote unquote new paradigm, we go running down the road.
We build these applications. We throw all this stuff up there and then about a year or two later. Somebody goes.
Hey, you know, we didn't think about security. So my question to you is is that changing this time or is this going to be yet another instance where we're really chasing the horse hats when it's out of the barn already. Yeah, you know that's a good question.
I think there's definitely shift happening. When we first started a few years ago. There was that kind of sense where you know manufacturers would say, oh security right?
Well, we're going to put it in when our customers ask for it, you know, and it wasn't by default necessarily now some did so I don't want to throw everybody on the bus, but it was kind of this afterthought or a nice to have and I think you're starting to see that change because customers are starting to ask for it. Right you're hearing a lot more especially around privacy specifically in the cloud. And so I don't I wouldn't say customers know necessarily what to ask for, but they're definitely want more Security in their devices.
You know, there's a lot of issues that have come up with insecure devices a lot of hacks lots of vulnerabilities and customers To become aware. So they are saying give us more security and manufacturers are starting to listen now. It's still I think a slow process again.
It's There are certain things that are starting to become default. You're starting to see this within some of the regulations right with the UK where they came out and said, hey, you must have no Universal passwords have a vulnerability disclosure program have security expiration dates and you know all around the world you're starting to see more regulations with it. So we're getting there.
It's a slow process, but I think we're headed in the right direction. Do you think that folks are responding to impending regulations or are they seeing actual more attacks in their kind of responding to the attacks and saying we need to do a better job on security? I think it's a little bit of both.
We haven't dealt with anybody. I would say probably I haven't dealt with anybody too bad of vulnerabilities, you know for the most part we have our own VDP program. So if there are any legitimate ones that come through we work with manufacturers, they'll go and fix it.
I would say probably maybe only had one where they did have a pretty devastating attack in the past and you know, it hit them really hard. They lost a lot of customers. They lost a lot of Revenue they lost a lot of trust in their brand and so now they're scrambling to crawl out of this whole right?
They're going out and getting every certification their implementing every type of security measure which you know, they could have just avoided from the get-go if they had implemented it from the beginning so I think there's a lot of the mentality of oh this won't happen to me. Right and so people are slowly responding to the regulations that are coming out because oh now I have to there are others who are saying the big guys, you know, we're saying hey, we need to get ahead of this. It's going to be a differentiator right between each other and the other ones will learn eventually one way or another.
The School of Hard Knocks can be a rough teacher is he your sense that there is a baseline for cybersecurity that will be implemented across all of these devices or do different classes of devices require different baselines. You know, we do have a baseline profile where it's the most basic security any device could come in and certify against it. But we have seen that different devices have different security threats and different vulnerabilities.
And so we have other profiles that are specific to those devices and I think that's the better route in my opinion. But for at least bare minimum, I think there should be kind of these basic security requirements that people are meeting and by people sorry, I mean manufacturers so I would say there's there are regulations that are gonna that are coming that you know are going to be pretty basic but they might be at a higher level than what manufacturers are used to so, I think that's something to be aware of and to look into if the manufacturers are aware of executive order 14028 that's around our cybersecurity and then National Institute of Standards and technology or nist. They've been tasked with going out providing recommendations.
There's a US national label that is planning on being rolled out to the nation regarding consumer products. So I think that's going to cause some big impacts in the coming year. Are you at all worried that maybe people will just check the box on compliance or to achieve some sort of mandate, but they won't really do the full security nine yards and we'll just result in additional issues later on and I think you know, there's a tendency among companies at least it just kind of say well, what are we going to do with the bare minimum?
Yeah, I think with the new security standards that are coming out that's not really going to be an option. You know with these Securities schemes that are already existing such as Idaho XT there are ways to do. Different processes for certification so you have your third party Labs, you know, very trusted everybody is very aware.
And then you've got self-certification which is more scalable. Right? It's a little bit more affordable.
It's quicker easier to update but either way you have these checks and balances in place where it's not really possible to just say, oh, yes, I have this, you know, there are technical review teams that are making sure that you're providing enough documentation or evidence to prove that you say. Oh, I have a b and c they're checking and seeing that you actually have a b and c and there are with the labs. They're doing the same so With the new standards and the US label that's coming out.
The standards are a lot higher. So I think manufacturers need to be more prepared for what's to come if they want the label. I don't believe it's going to be mandatory in that sense.
But I believe there's enough big players in the field who want this to succeed or both government and private sector that you're going to see this become very successful and I think it's just going to go down the chain and I think that that's going to have a lot of impact for people to look into what do I need in order to reach those requirements in order to get the national label. I mean if it's backed by the US government, you know, it's not going to be some easy check mark where you can just say. Oh, yeah, I have the label.
So I think there's some research that needs to be done. There's obviously still stuff in the works. But if you know anybody was interested to learn more they can obviously reach out to ioxt or nist and we're happy to provide more information.
Do you think they'll be a marketing effort to educate people about what that label means and the go look for because there's a lot of labels on a lot of different things and most people don't even know what they mean. Yes, I think that's going to be one of the most critical points. Actually.
They're still deciding who's going to take that over. Is it missed? Is it the FTC?
Is it another department? But yes, they're planning on it being this two-part label. So one is binary they really want it to be very simple such as an energy star so that when it comes out people don't necessarily need to know all the details, but if they see it they kind of have an overall picture that this means it this product is safe, right, but then they also want it to be layered so such as a QR code and then that means they can scan it if they have the time or where with all to go and research it and then they can see the security levels that the product needs.
So yeah, I think there's a lot of marketing and consumer awareness and education that needs to happen. So they know what to look for when to look for it what they're supposed to be understanding if they do look into A security levels, so it will be a big push and there's definitely more information to come on that but I think the private sector will also want to take a stab at it as well and help so that their consumers understand that. Oh, I have reached this very hard certification to reach right and we have the all the information so that the customer understands as well and they will pick our product over someone who doesn't have this label.
Are there different labels for different types of folks who are creating these devices because I may be a consumer goods company and I'm creating some sort of iot device that we're selling into somebody's home. And then there's all the folks who are creating some sort of iot device for an industrial use case. And is that going to be a different set of specifications or are they similar or you know, how do I bifurcate this?
For the US label, it's going to be focused just on consumer goods at this point for the iOS tea label specifically, we don't really differentiate from that. But we do have different profiles and those different profiles have different requirements. So we have a network lighting controller profile versus say our residential camera profile.
So not necessarily at different Mark, but they will have different requirements. If somebody wanted to they could scan the QR code that we have and go and learn more about what those requirements are and what levels it takes to meet those requirements. So yes, I think there could be a little bit better maybe down the road but I think they first need to figure out what does the US label look like?
What do these other labels look like once iost mean, you know people are familiar with you. Well a little bit but what does it really mean? How are they going to be involved?
So there's little bit more education just starting at the basics first. Do you think people appreciate the nuances of security here? Because it's not just somebody hacking into their device and kind of taking over their household cameras.
A lot of those devices wind up being used as drones and botnet attacks that are elsewhere that they average consumer may never see so we'll they understand that you know, and to a certain degree. They have a responsibility to the larger Community to secure their environment on behalf of everybody else. Yeah, I think it's a little bit too part there needs to be more education for the everyday consumer for sure.
But I think there needs to be some education for the companies who are going out and buying this technology because yes, they can buy this technology and that can impact the millions of customers that they serve there's a lot that goes into it and I think it can get very technical which is a big part of the issue. So I think there needs to be more education on and just simple terms to really help both sides understand what's coming and what they should be looking for. You know, there's plenty of Articles out there that say, oh don't have a password, you know across all of your devices and for every account that you have but there's a lot more that goes into it, right and so we have our eight pillars pledge items.
That we base all of our test cases and our security around just to name a few, you know, it gets into proven cryptography. You're automatic updates verified software. So it's more than just passwords.
Right? And I think it's it's hard to provide that information in simple terms because it can get really Technical and complicated but I think that should be where the industry is headed. So that all consumers across the board really understand and can better protect themselves and their customers down the line.
All right, folks. You heard it here. If you connect something to the internet you were assuming great responsibility.
Hey Grace. Thanks for being on the show. Yeah, thank you so much.
Love being here. All right back to you guys in the studio.