Lindy Cameron at Singapore International Cyber Week

Good morning everyone and thank you for inviting me to speak at Singapore International Cyber Week.
It’s great to be here in Singapore, one of the world’s smartest cities. I am going to talk to you today about the Internet of Things and smart cities as ‘connected places’.
Singapore and the UK have a shared vision of how we can improve the security of our nations’ internet-connected devices. This was set out in the Strategic Partnership agreement, signed in 2019.
And our collaboration to drive improvements in the security of smart consumer products continues to this day, with Singapore and other nations represented here.
The rapid spread of inter-connected devices has also increased government and industry partnership, focused on ensuring that the benefits of a connected world are not overwhelmed by the abuse of this technology.
We in the UK are proud of the strong framework we have developed for managing the future security of the Internet of Things. This includes new legislation called the Product Security and Telecommunications Infrastructure (PSTI) Bill.
I will talk about that in a moment but first ‘What, exactly, is the Internet of Things?’ And ‘Why does it matter?'
Defining IoT (and opportunity)
The Internet of Things is about automation, connectivity and efficiency. Leveraging these to improve our lives, boost our economies and free our time to be more productive. This is a huge opportunity.
The sheer range and number of applications for these technologies is vast:
From the control of a building’s access systems and air conditioning to the monitoring of your sleeping baby. More infamously described by our former Prime Minster, Boris Johnson, at the UN General Assembly as a future with ‘Fridges beeping for cheese’ and ‘mattresses which monitor your nightmares’.
What is certain, is that these connected devices, from smart homes to smart cities, are now part of our everyday lives.
In fact, a study by global consultancy firm, McKinsey, found that by 2025, consumer IoT could contribute some £155-£270 billion per year to the global economy, as a result of more efficient energy management, labour saving automation, and the avoidance of injuries and fatalities through improved home security.
IoT at scale
We think about the products and associated services that make up the internet of things on different levels - ‘Consumer’, ‘Enterprise’ and ‘City’ as convenient shorthand.
Consumer level IoT has exploded in scale over the last decade or so. There were 8.4 billion devices or ‘things’ connected to the Internet in 2017 and it is estimated that there will be a staggering 75 billion by 2025.
At an enterprise level, the story is very similar. The proliferation of IoT has been rapid and very broad-based. Network printers, smart building management systems and security products are being used to boost productivity and automate repetitive tasks.
And at a city level, we see the growth of technology to manage transport, waste, CCTV, streetlights, traffic lights, parking and public services such as health and social care or emergency services.
At every level, individual households, businesses, cities and local governments are keen to reap the benefits of ‘smart devices’. The benefits are obviously compelling. They provide a range of critical functions and services to us all. This should be an opportunity, not a threat.
The threats
But the sheer scale of changes that we are talking about, and our growing dependency on technology also brings risks. That is why now is the time to make sure we're designing and building them properly.
We all know that connected places are an evolving ecosystem, comprising a range of systems that exchange, process and store sensitive data, as well as controlling critical operational technology.
Unfortunately, this makes these systems an attractive target for a range of threat actors. The threat posed by nation states is particularly acute.
Some countries will seek to obtain sensitive commercial and personal data from other nations, including from us in the UK. These countries may also seek to influence a supplier or cause disruption to overseas services.
Suppliers that are part of corporate groups based in these countries may be subject to influence from the host government to access and exfiltrate data from connected places, in support of that government’s security and intelligence services.
Such suppliers may also be used as a vector for an attempt to take down an essential service overseas, causing possible destructive impacts and endangering local citizens, if systems were switched off.
NCSC approach
So we in NCSC have sought to lay bare the threats and risks in the work we have done on how to secure ‘connected places’.
We believe in an approach that builds resilience at scale. Based on principles that allow states and citizens to encode the values they want. Building standards that let us get ahead of the problem, rather than responding to decades of legacy challenges later.
Standards / legislation
So for IoT we started with a 13-point Code of Practice that we, in the NCSC, developed for the IoT industry in 2018, with the express goal of creating a more easily manageable cyber security picture for connected technology. What we call ‘Secure by Default’ – influencing design of IoT from the start.
Then in 2020, the UK shaped and then adopted a new ETSI Standard on Connected Product Security; EN 303 645 for those of you who want to look it up!
Finally, the UK Product Security and Telecommunications Infrastructure Bill, which is currently working its way through Parliament is seeking to enshrine in law the ‘secure by design’ principles.
The Bill places new cybersecurity standards on manufacturers, importers and distributors of internet-connectable devices. It was developed jointly by NCSC and the UK Department of Digital, Culture Media and Sport, in collaboration with industry, and welcomed by them as a proportionate approach.
It ensures the security of connected devices on the market and holds device manufacturers to account for upholding basic cybersecurity standards, such as discontinuing default passwords and other blatant security short comings in their devices.
‘PASSWORD’ does not count as a password... Nor does ‘Admin’ or ‘12345’!
It also asks manufacturers to maintain a vulnerability disclosure programme and explain how long devices will receive security updates.
None of these measures are revolutionary, or super technical. Indeed, for the rest of the IT world, they are cyber security 101.
These guidelines, combined with the availability of new international IoT standards mean that legislation is now much simpler to put in place and for industry to follow.
However, if they are going to have effect then we need the commitment of governments and manufacturers around the world to enforce these standards.
We believe this approach is foundational to the security of future IoT.
And that’s why we’ve not just focused on the UK - we’ve worked with others to take a similar approach that shapes the market for this tech. I’m delighted to say one of those countries was Singapore.
Securing the foundations - semiconductors
Another specific area requiring government and business focus is a concerted effort to make technology harder to exploit in the first place. We can secure our foundations by building resilient semiconductors.
The UK government is investing in exactly this via the Digital Security by Design programme, which is developing pioneering UK academic research into real hardware developers can use, tackling the buffer overflow problem that enabled Heartbleed and has been with us since the dawn of computing.
Technology and digital service providers need to work with government and academic partners to make connected systems more secure at source and behind the scenes, reducing the burden on end users.
And again, it is fantastic to see collaboration on this kind of hardware security between universities here in Singapore and those in my home nation of Northern Ireland – where our flagship conference Cyber UK will be held on April 19-20 next year.
Smart cities / connected places
And IoT at scale – in Connected places or smart cities (depending on your preference) is a clear example of how IoT technology can become a matter of national resilience.
The possibilities for improved standards of living, sustainability and growth are huge. But this potential gain must be balanced against the threat of compromise, which is equally immense, especially at this scale. In recent years, we saw indications that local governments in the UK understood the opportunities but not the risks.
In recognition of this trend, my organisation has been working with government, academia and international partners to agree cyber security principles for the technological developments around connected places.
These principles are ultimately about the balance between security, safety and functionality.
NCSC action
So in May last year, following joint research with the Centre for Protection of National Infrastructure (CPNI) and industry, the NCSC published a set of principles on our website.
These ‘Connected Places Cyber Security Principles’ - believed to be the first in the world - outline how governments and organisations can securely design, manage and build ‘smart cities’. Again, our approach is to get ahead of the problem.
Our aim with these Principles and our wider support for the sector is to help the designers, vendors and operators of connected places to make informed decisions about the high level security requirements that should govern smart cities in a way that reflects their values. And to do so right from the design phase.
In this, I am especially grateful to Singapore’s Smart Nations Digital Government Office (SNDGO) who are seeking to test these principles in the field – something they are able to do because Singapore is one of the leaders in putting this technology into practice.
International cooperation
Collaboration, cooperation, and the ability to learn from each other, while reflecting our own cultures and values in our use of technology – this will all help to keep us safer and secure. We make faster progress and produce longer lasting results together.
I encourage you to read these Principles and think about how to apply them in your own contexts, build on them further, and take them forward together.
Sum up
To sum up, I reiterate my call for clear, workable international standards which shepherd technology towards a safer and secure future so that we can fully grasp the incredible advantages which these emerging technologies promise.
Unless we design them properly, things like smart cities could bring with them an ever-increasing attack surface and proliferation of vulnerabilities for our adversaries – both states and criminals – to exploit. Over time I believe this could stifle growth and eventually, national prosperity – as indeed could overly heavy handed regulation that stifles markets and prices the poor out of having choices in technology.
The stakes are so high that we must make sure our devices are designed, built, deployed and managed with security as a first class concern. Not added on as an afterthought.
We must also be certain that malicious actors cannot find ways to circumvent our defences. This means being clear and tough about the requirements we place on those devices and the standards we apply when using them.
There’s no point in hoping this problem will go away. Without swift, decisive and ongoing action, it will only get harder – and more expensive – to break nations of their dependence on insecure connected devices.
Together we can create a world which benefits from the huge promise of connected technologies while protecting them from cyber threats.
Thank you.