The PSTI (Product Security And Telecommunications Infrastructure) Act became effective on April 29th, 2024, following a one-year grace period. This vital piece of legislation affects every manufacturer dealing in smart-connected devices within the UK. Now that the grace period has ended, any company found violating this law will face legal action. For consumers, this legislation represents a significant move towards safeguarding them from the impact of non-compliant devices on their online safety. Manufacturers of non-compliant products are now compelled to recall such products and may also incur substantial fines; such non-compliance is regarded as a criminal offence.
All IoT manufacturers that wish to market their products in the UK are now obliged to meet the standards set forth by the ETSI (European Telecommunications Standards Institute), which are also encapsulated in the UK law. The three primary stipulations are:
- Elimination of default passwords – manufacturers must assign unique passwords to each device/product set or allow users to create their own passwords.
- Implementation of a vulnerability disclosure policy for every device to facilitate swift remediation of any discovered vulnerabilities.
- Provision of information regarding the duration of product support at the point of sale, detailing the period during which the device will receive updates from the manufacturer.
This legislation highlights the growing awareness of the importance of adopting best practices in the development and protection of IoT devices. At The Cyber Scheme, we are expanding our training programs to include more skilled hackers in the fields of IoT, IIoT, and ICS. Our CSII course offers hands-on training in IoT hacking, culminating in a detailed accredited assessment that evaluates the practical skills of the participants. Targeted at intermediate testers, it also acts as a gateway to more advanced IoT examinations that are currently under development.
For additional information about The Cyber Scheme’s training and assessment offerings in IoT, visit: https://thecyberscheme.org/iot-ics-training/
