US National Cybersecurity Strategy targets IoT

  • March 15, 2023
  • William Payne

The Biden Administration has released a National Cybersecurity Strategy that highlights the need to improve the security of IoT devices, adopting security practices aligned with the National Institute of Standards and Technology cybersecurity framework, and places liability for security breaches on manufacturers and developers of devices and apps.

The new strategy replaces a 2018 national cybersecurity strategy that was created by the Trump Administration. The Trump Administration strategy was effectively laissez-faire, promoting voluntary public-private partnerships and data sharing. By contrast, the new Biden Administration strategy is more aggressive, prescriptive and comprehensive.

At the heart of the new strategy is the aim of defending critical infrastructure. This includes not only military and security networks and systems, but telecommunications, transportation networks, energy grids, utilities, oil and gas production plants and pipelines, healthcare, logistics and supply chains, city infrastructures, critical manufacturing, such as electronics, semiconductors, life sciences and medicines, and food production, distribution, and retail outlets.

Perceived threat actors are not only groups of activists, organised crime and terrorists, but also nation-state threat actors, particularly countries such as Russia, China, North Korea and Iran, who would seek to attack critical infrastructure during times of heightened tension, or simply to take advantage of national crises. Western hospital networks came under series of cyberattacks during the Covid crisis with attackers believed to be from government-sponsored groups in both North Korea and Russia. European healthcare networks have come under record levels of cyberattacks from Russian government-sponsored groups following the invasion of Ukraine.

In response to the rising level of cybersecurity threats to critical infrastructure, including to critical embedded IoT networks, the Biden Administration is establishing a new Cybersecurity Regulation to Secure Critical Infrastructure. This will set out minimum expected cybersecurity practices. The strategy also outlines the goal of reducing the cost for firms to comply with tighter cybersecurity standards and protocols.

The strategy also sets out plans for Federal bodies to assist and coordinate increased cybersecurity of national critical infrastructure. The US Government will invest in developing sector specific risk management agencies to oversee and regulate improved cybersecurity across different industrial and service sectors.

The Administration has also set out plans in the strategy to shift the burden of cybersecurity and its costs from customers, both consumers and business, to large owners and infrastructure operators. This shift also will include new legislation placing new liabilities and obligations on manufacturers, developers and operators of devices, apps and infrastructure, including consumer and non-critical IoT devices and apps. The strategy also envisions improved data minimisation and privacy regulations coming into force in US law.