Cybersecurity should be a priority when building Smart Cities

Published Mon, Feb 17, 2020 · 09:50 PM

CIVIC leaders around the world are looking to automate the infrastructures that make their cities run in a drive to reduce costs and cope with rising populations. From transit networks and utilities to refuse collection and street-lighting, connecting services to the Internet is proving an appealing prospect for those in charge of cities and large towns.

In fact, UBS predicts that Asia's smart city market could reach US$800 billion in 2025, leading the continent's fourth industrial revolution. The United Nations projects that 66 per cent of the population in South-east Asia will be living in urban areas by 2050, and many of its cities are looking to smart solutions to address their challenges.

However, in their rush to automate their cities, civic managers need to ensure that they also build in cybersecurity that will protect them from threat actors wishing to create chaos for their own nefarious ends.

Looking to connect any of the infrastructure under their jurisdiction will be an unknown territory for many civic leaders. In order to understand the types and scale of threat their newly connected networks could face, city managers should look at what has happened elsewhere. For example, North Korean hackers have managed to retrieve nuclear reactor designs from power plants in South Korea and India using software vulnerabilities and phishing attacks. This should be of concern as it doesn't take long once a threat actor is in an IT network to move laterally into the operational technology (OT) that a smart city runs on if there is not proper segmentation between the two.

This is a lesson that other sectors have learned, to their cost. In Asia Pacific, 88 per cent of organisations have experienced at least one Internet of Things (IoT)-related security breach, the highest rate in the world. A joint study by Microsoft and Frost & Sullivan also found that 67 per cent of organisations across Asia Pacific have experienced layoffs following cyber attacks.

Even if they are aware of these risks, civic leaders have a major hurdle to jump, in that much of the technology they would use to create smart cities has been built with maximum connectivity in mind, and security researchers are expositing a lot of vulnerabilities in those IoT-connected devices.

SIGNIFICANT VULNERABILITIES

Once these devices are active, they often run on operating systems that have significant vulnerabilities that are in many cases challenging to patch or no longer supported. For instance, IPnet is still an integral part of the operating systems of smart devices used in connected cities, despite having not been supported since 2006. When combined with the reality that there are likely to be hundreds of thousands of these devices connecting to an OT network, this presents a huge, exposed attack surface for threat actors to exploit. The situation is likely to be exacerbated by the rollout of 5G networks, as it not only provides a better way for devices, but also cyber criminals, to connect to the OT network.

More or less anything that is under the jurisdiction of civic managers can be made more efficient and cost effective through automation and connectivity. However, with each service that is brought online, smart cities are exposing themselves and their citizens to the potential risk of catastrophic events that could have a devastating and long-lasting impact.

Take street-lighting, for example. By 2026, the Asia Pacific region is set to be home to a third of all smart streetlight installations worldwide, the bulk of which includes central management systems. Streetlighting is vital for towns and cities as it helps enhance quality of life, improve public safety, and reduce traffic accidents. Studies show that in areas where street-lighting has been improved, road collisions fall by 30 per cent and the severity of injuries is reduced by a factor of three. Conversely, in the event of a cyber attack knocking out the street-lighting system, the wellbeing, or even the lives, of commuters could be in danger.

There is also the reality that alongside the potential to cause chaos across a city, cyber criminals are likely to want to break into these systems to steal the significant amount of data, including personally identifiable information, on which they run.

TRAINING "CYBER-AWARE" STAFF

While connectivity and automation have the potential to drastically change how cities are managed, and people's experience of living and working there, these advantages can be wiped out by a single cyber attack. As such, civic managers must make cybersecurity a priority when looking to make any infrastructure "smart".

However, public servants often lack cybersecurity expertise. In 2018, Singapore faced what authorities dubbed the "most serious personal data breach" in its history when the personal information of 1.5 million patients was leaked in a cyber attack, which has been attributed to system vulnerabilities and weak passwords.

If they want to create smart cities, local authorities must, as a matter of urgency, ensure existing staff are trained to be "cyber aware", so that their actions don't endanger the security of its networks. They must also recruit or train a cybersecurity team that is able to understand the difference between managing and protecting IT and OT networks.

The other piece of the puzzle is to invest in technology that provides detailed oversight into everything that is on a city's IT and OT networks. Knowing granular details from a device's make, model, OS and IP address to risk level and update schedule will enable the IT security team to identify and mitigate any vulnerabilities on their networks. As IoT and OT environments use unique communication protocols, this requires specialised solutions that can recognise them.

Once they know what is running on the network, security professionals also need to know how assets should be running so that they can detect any anomalies. This requires continuous automated monitoring that can present contextualised alerts ranked by level of severity, providing security teams with all the information they need to tackle potential risks in priority order.

Such solutions also help to reduce the amount of time wasted dealing with false positives and low-risk alerts. When building physical infrastructures, a key consideration for civic managers and leaders has always been safety and security. The same now has to be true when building OT infrastructures. In this way, smart cities can be created that provide all the advantages to its citizens rather than to cyber criminals.