New guidelines have been released by the European Union Agency for Cybersecurity (ENISA), which recommends that all stages of the lifecycle of an IoT device be taken into account to ensure the security of the devices.

The supply chain around the Internet of Things (IoT) has become the weak link in cybersecurity , potentially leaving organizations open to cyberattacks through vulnerabilities they are unaware of. However, a recently released set of guidelines aims to ensure that security is part of the entire lifecycle of IoT product development
The IoT security guidelines set out recommendations across the IoT supply chain to help organizations protect themselves from vulnerabilities that may arise during the manufacturing of “connected things.”
One of the key recommendations is that cybersecurity expertise should be further integrated at all levels, including engineering, management, marketing and more, so that anyone involved in any part of the supply chain has the ability to identify potential risks – identifying and addressing them early in the product development cycle prevents them from becoming a major issue.
It is also recommended to adopt “Security by Design” at every stage of the IoT development process, focusing on careful design and risk management to ensure that any potential security issues are identified early.
“The first decisions made during the design phase usually have implications at later stages, especially during maintenance,” the report said.
Another recommendation is for organizations throughout the product development and deployment cycle to better forge corporate/operational relationships in order to address security gaps that can arise when there is a lack of communication between those involved.
These include design errors due to a lack of visibility into the component supply chain – which can happen when there are misunderstandings or a lack of coordination between component manufacturers and the IoT vendor.
However, not all responsibility to IoT manufacturers, the report also states that both customers and end-user organizations need to play a role in supply chain implementation and can “benefit significantly from dedicating resources to studying the current landscape and adapting existing best practices to their own case.”
