IoT Security: Not Ripe for Regulation

Media reports regularly offer frightening stories about security vulnerabilities in the emerging “Internet of Things,” from the hack of a Jeep to the specter of bad guys accessing “smart homes” or exploiting industrial IoT to compromise utilities.

Not surprisingly, regulators are focusing on security, both in industry verticals (think medical devices and cars) and more generally.  The Federal Trade Commission identified cybersecurity issues related to consumer-facing IoT, and proposed possible best practices.  The White House, through the National Telecommunications and Information Administration, is asking for input by May 23 on various aspects of IoT, including cybersecurity concerns and whether IoT security is somehow unique.  Congress is looking closely at IoT as well, wary of regulation but concerned about consumers.

As a general matter, cybersecurity for IoT is a poor fit for prescriptive regulation – as the FCC Chairman said last year, “[t]he pace of innovation on the Internet is much, much faster than the pace of a notice-and-comment rulemaking.” So much remains uncertain about IoT use cases, consumer demand, device and application supply chains, and the 5G wireless networks that will support them.  Trying to codify any approach, standard or best practice in the Code of Federal Regulations guarantees near-instant obsolescence.

Policymakers should be vigilant but, in the words of one FTC Commissioner, exercise “regulatory humility.” Regulation threatens to lock in technology, prematurely predict consumer preferences, and stymie efforts to innovate and ensure global harmonization.

Luckily, collaboration between industry experts and standards groups is robust and productive.  An alphabet soup of domestic and international groups are examining security in the next generation of connected devices and services.  The National Institute of Standards and Technology has a Communications Technology Laboratory examining security in IoT and 5G networks. Groups as varied as the International Standards Organization, Underwriters Laboratory, ATIS, IEEE, and 3rd Generation Partnership Project (3GPP), to name just a few are working the issues collaboratively. And industry groups are not waiting for regulation either, choosing to develop best practices, such as the Auto Alliance developing a “Framework for Automotive Cybersecurity Best Practices” and the Online Trust Alliance releasing its “IoT Trust Framework.” It is an understatement to say, as a federal advisory group recently did, that “[t]here are numerous efforts underway to enhance” IoT security “within multiple standards organizations.”

Where government’s role is most appropriate and impactful is in the commitment of federal and state investments and actions necessary to upgrade and remove regulatory barriers to modernizing infrastructure – the highway system, mass transit, smart grid, telecommunications networks, government services and other utilities upon which IoT will depend for innovation and growth.  Otherwise, the United States should continue to lead by example, and carefully weigh the costs and benefits of premature intervention.  As the federal regulatory apparatus turns its gaze to “the next big thing,” it should check its natural inclination to micromanage, and defer to the market and technology to lead the way.

Wiley Connect

Sign up for updates

Wiley Rein LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek