Smart cities has been a trend for a few years now, but questions always crept up as to how to keep a smart city secure.

After all, smart cities may create safer, more efficient, resilient communities through technological innovation and data-driven decision making. However, as it is with digitalization in the manufacturing sector, increased connectivity also introduces potential vulnerabilities and weaknesses that—if exploited—could impact national security, economic security, public health and safety, and critical infrastructure operations.

That is why agencies from around the world, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), United Kingdom National Cyber Security Centre (NCSC-UK), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS) and the New Zealand National Cyber Security Centre (NCSC-NZ) released a joint guide called “Cybersecurity Best Practices for Smart Cities.”

Cyber threat activity against OT systems is increasing globally, and the interconnection between OT systems and smart city infrastructure increases the attack surface and heightens the potential consequences of compromise, according to the report.

Smart cities are an attractive target for criminals and cyber threat actors to exploit vulnerable systems to steal critical infrastructure data and proprietary information, conduct ransomware operations, or launch destructive cyberattacks, according to the report. Successful cyberattacks against smart cities could lead to disruption of infrastructure services, significant financial losses, exposure of citizens’ private data, erosion of citizens’ trust in the smart systems themselves, and physical impacts to infrastructure that could cause physical harm or loss of life. Communities implementing smart city technologies should account for these associated risks as part of their overall risk management approach.

Schneider Bold

Integrating a greater number of previously separate infrastructure systems into a single network environment expands the digital attack surface for each interconnected organization, according to the report. Like a manufacturing enterprise, the expanded attack surface increases the opportunity for threat actors to exploit a vulnerability for initial access, move laterally across networks, and cause cascading, cross- sector disruptions of infrastructure operations, or otherwise threaten confidentiality, integrity, and availability of organizational data, systems, and networks. For example, malicious actors accessing a local government IoT sensor network might be able to obtain lateral access into emergency alert systems if the systems are interconnected.

Additionally, as a result of smart cities integrating more systems and increasing connectivity between subnetworks, network administrators and security personnel may lose visibility into collective system risks, according to the report.

This potential loss of visibility includes components owned and operated by vendors providing their infrastructure as a service to support integration. It is critical system owners maintain awareness and control of the evolving network topology as well as the individuals/vendors responsible for the overall system and each segment, according to the report. Ambiguity regarding roles and responsibilities could degrade the system’s cybersecurity posture and incident response capabilities. Communities implementing smart city technology should assess and manage these risks associated with complex interconnected systems.

Some recommendations the agencies suggest for secure planning and design include:

  • Apply the principle of least privilege
  • Enforce multifactor authentication
  • Implement zero trust architecture
  • Manage changes to internal architecture risks
  • Securely manage smart city assets
  • Improve security of vulnerable devices
  • Protect Internet-facing services
  • Patch systems and applications in a timely manner
  • Review the legal, security, and privacy risks associated with deployments

Click here for more on the “Cybersecurity Best Practices for Smart Cities” report.

ISSSource

Pin It on Pinterest

Share This