A large chunk of the internet went down in October 2016. Not in a single nation, but throughout the United States and in waves that also impacted several regions of Europe. Twitter was not loading. Netflix went out. The New York Times, Reddit, and Spotify were all unavailable for periods of time that Friday. A sophisticated nation-state attack on government infrastructure was not the cause. It included digital video recorders, webcams, and routers. Malware known as Mirai had surreptitiously infected hundreds of thousands of common consumer devices, using them as cannon fodder to flood one business, Dyn, a DNS provider, with enough traffic to render a significant portion of the internet unavailable.
The Mirai botnet was made feasible by inexpensive, useful gadgets that came with default passwords that their owners never changed. “admin/admin” was frequently used. And so was “123456.” These devices left the factory as potential weapons, ready for someone to point them at a target, because the manufacturers had placed security low enough on the priority list. The purchasers of those webcams were not asked to consider global DNS infrastructure. All the cameras had to do was capture the driveway.

It was in 2016. Since then, the number of linked devices has increased significantly, and while security procedures controlling their construction and deployment have improved, they have not done so consistently or at the same rate. An estimated fifteen billion or more IoT devices are currently in use worldwide, ranging from smart speakers on people’s kitchen counters to industrial sensors in power plants. Every one of them is an endpoint. Every device that is shipped without a significant security architecture or that has out-of-date firmware that its owner is unable to update could be a point of entry into the network to which it is connected.
Beyond disrupted streaming services, the risk becomes truly serious in the critical infrastructure dimension. Over the past fifteen years, power grid control systems, water treatment facilities, and hospital patient monitoring equipment have all been progressively connected to networks due to the significant operational advantages that come with connectivity. centralized control, predictive maintenance, and remote monitoring. Those benefits are all genuine. They also carry a real security risk. An attacker can remotely access a connected medical gadget, which is more than just a privacy issue. It’s a patient safety issue at an intensive care unit of a hospital.
Because it consistently shows up in breach investigations, the network infiltration vector is the one that most corporate security teams find themselves returning to. The photocopier in the corner of a company with strong enterprise security—firewalls, endpoint detection, and cautious access control—still has firmware from 2019 that the office manager was unable to upgrade. or the intelligent HVAC system installed by the building management firm. or the guest network, which isn’t as cut off from the primary network as the IT staff thought. Any of these can be used as a point of entry to get around the costly security system that keeps everything else safe. This is how an HVAC vendor’s network credentials were used in the 2013 Target hack. The number of possible access sites has increased, but the premise remains unchanged.
There is no voluntary solution to the structural issue of manufacturer incentives. The cost of integrating security into a consumer item includes engineering effort, component prices, testing time, and the ongoing infrastructure needed to provide patches and upgrades after the product is sold. These expenses appear to be a competitive disadvantage for a business selling a $15 smart plug in a market where a competitor’s $12 substitute is available. The market has consistently chosen cheaper over safer in the absence of regulatory requirements that establish a minimum security floor.
With mandated criteria for connected devices sold in the EU market, Europe’s Cyber Resilience Act is the most direct attempt to alter that calculation. According to the theory, manufacturers must adhere to minimum security standards in order to gain access to European consumers. Since it is typically more expensive to develop two distinct product lines than one secure one, the regulation has the potential to raise standards worldwide, not just within European borders.
