Connected Places Cyber Security Principles
Pages
Page 1 of 19

Introduction
This guidance will help authorities build awareness and understanding of the security considerations needed to design, build, and manage their connected places (often referred to as smart cities).
More specifically, it recommends a set of cyber security principles that will help ensure the security of a connected place and its underlying infrastructure, so that it is both more resilient to cyber attack and easier to manage.
This guidance is primarily for UK local and national authorities responsible for the design, build, and operation of UK connected places. It is particularly relevant for risk owners, CISOs, cyber security architects and engineers, and other personnel who will be running the day-to-day operations of the connected places infrastructure.
Note: Within this document, the terms connected place, public realm technology and data-rich environments cover the wider connected infrastructure, including local areas where data is collected through sensors and Internet of Things (IoT) devices. Within these connected areas, this guidance supports singular or multiple service functions. Such examples could include:
- traffic light management
- CCTV
- waste management
- streetlight management
- parking management
- transport services
- public services (such as health/social care, or emergency services)
What is a connected place?
The fundamental aim of a connected place is to enhance the quality of living for citizens through collaborative, interactive, and connected technology. For the purpose of this guidance, a connected place can be described as a community that integrates information and communication technologies and IoT devices to collect and analyse data to deliver new services to the built environment, and enhance the quality of living for citizens.
A connected place will use a system of sensors, networks, and applications to collect data to improve its operation, including its transportation, buildings, utilities, environment, infrastructure, and public services.
The challenges
A connected place provides a range of critical functions and services to its citizens. The systems that these functions and services rely on will be moving, processing, and storing sensitive data, as well as controlling critical operational technology. Unfortunately, this makes these systems an attractive target for a range of threat actors. A connected place will be an evolving ecosystem, comprising a range of systems that exchange data, which will only add further risks.
If connected systems are compromised, the consequences could impact the local citizens. Impacts could range from breaches of privacy to the disruption or failure of critical functions. This could mean destructive impacts, which in some cases could endanger the local citizens. There could also be impacts to the local authorities that are attacked. These could include a loss of reputation that could affect citizen participation, or the financial impacts of dealing with the aftereffects of an attack.
With this in mind, the NCSC has developed a set of cyber security principles to guide you in designing, building, and operating your connected place's systems securely. These should be read in conjunction with advice from the National Protective Security Authority (NPSA), focusing on physical and personnel security with a Security Minded approach to Smart Cities.
Engagement with other stakeholders
As the national technical authority for cyber security, the NCSC's focus includes providing guidance designed to allow local authorities to better understand and manage the totality of their connected places ecosystems and technologies. The NCSC is prioritising engagement with local authorities, wider HMG, industry, and academia to ensure the cyber resilience of UK connected infrastructure. This includes:
- providing assurance for citizen privacy, through analysing and managing the threats and vulnerabilities that could compromise the confidentiality, integrity, and availability of citizen data
- enhancing the wider cyber resilience of UK connected places in order to protect the services they provide
- working with our partners (including NPSA) to help support central government, local and regional authorities to secure the UK’s connected places
System design
These connected place principles have been designed to be applicable to both digital systems and cyber-physical systems.
Throughout this guidance, we use the term system, by which we mean 'a collection of digital components that are connected using communication technologies to perform a business function.' A good example of this type of system is described in the NCSC's Operational Technology Design principles with Admin Corp. Admin Corp have to design and operate their systems to produce business assets, but must also protect these production mechanisms from cyber attacks.
We also use the term cyber-physical system, by which we mean 'a system that measures or controls the physical world to achieve a particular goal.' A good example is a smart traffic control system, which senses and measures the traffic patterns and conditions within a local area. The system can autonomously apply commands to the traffic signals to orchestrate and manage the movement of vehicles within that local area to meet prescribed objectives
Downloads

- 2.63 MB
Connected Places infographic
These principles will help ensure the security of your connected place and its underlying infrastructure, so that it is both resilient to cyber attack and easier to manage.
- 1016.44 KB
Connected Places: Cyber Security Principles
pdf version of the Connected Places Cyber Security Principles. Updated 2024.


