- 16/03/2017
- Category: Commentaries
In this digital era, privacy has been perceived as essential rights for every citizen. Recognition of privacy rights also gives people a choice to allow or disallow their personal data and sensitive information to be accessed by other parties. Sensitive information refers to privileged or proprietary information that only certain people are authorized to see, and that is therefore not accessible to everyone.[i] If sensitive information is lost or used in an unintended way, the result can be severely damaging for people or organization that possess such information.
In the smart city, technologies capture data that relate to all forms of privacy and expand the range to integrated people and places. In a smart city environment, where all the data integrated altogether, either the government, corporation, and other relevant stakeholders (e.g. vendors) could have the privilege to access and watch, listen to, or even record and track someone’s activities.[ii] It means personal privacy is vulnerable to be threatened or violated by a party who has direct control in the management of the system. Smart city operations utilize network assembly of ICT (Information and Communication Technology) infrastructure to manage various services. Any device that is connected to the network is vulnerable to get hacked, and the potential to get hacked is multiplied in Smart Cities. By integrating them into a single system, it is possible to attack the entire system or network. The vulnerability of systems is exacerbated by some issues including the weak security system and poor infrastructure maintenance in some cities.
For instance, recently San Francisco Municipal Transport Agency computer system got attacked by hackers who encrypted all of the data and was demanding 100 bitcoin ($73.000) for ransom. According to The Guardian,[iii] the hackers succeeded to infect and take over more than 2000 computers. SMTA refused to pay the demand but forced to open the fare gates as a precaution to protect their customer and allow passengers to ride for free. The hackers themselves declared that they did not intend to harm people. Instead, they warned people about the vulnerability of company’s obsolete IT security system that can easily got hacked.[iv]
It turns out that various threats on privacy or data security do not necessarily mean that smart cities administrator would invest more on security and privacy protection aspects. According to research published by CNBC in 2016, the percentage of cities spending on security and privacy protection technology is the lowest compared to another spending on another fields such as business application, mobile devices, or even cloud application that increases by 86%. It is a prove that smart city administrators are not yet putting concerns on security and privacy protection.
There is no organization or government who can predict a cyber attack, But they can reduce the possibility of risk and increase their resilience. Control Risks have analyzed how to ensure a smoother implementation process and, ultimately, more secure infrastructure.[v] Firstly, by prioritizing security of critical assets. Contemporary networks are already impossible to protect in their entirety, a problem which will apply equally to smart cities. Some components of the system will have to be made more secure than others. Public and private sector organizations will need to work together to identify the city’s critical assets and oversee the institution on appropriate security measures.
Second, emphasizing behavior based security. Auditing millions of separate devices for signs of malware is simply not feasible. A more workable approach should be developed to evaluate the behavior of smart city components, systems, and users against an established baseline of normal functionality or network behavior. Any significant deviation from the norm – above a determined threshold – would trigger an investigation into the possible presence of malware on the subcomponents.
Third, rapid component replacement. Given the potential for component failure or attacks compromising these components, an automated replacement system will enhance the security of the whole system. Although it is difficult to apply to critical components without full redundancy, such measures would be suitable for low-level, relatively isolated components.
Fourth, segmenting key assets of private organizations from the city’s system. What is paramount to the security of organizations in the smart city environment is the segmentation of their critical assets from the city’s network. Although it is costly and potentially reducing the effectiveness of the organizations, this policy will enable organizations, especially government, to contain and mitigate any threat actors exploiting vulnerabilities in the smart city network to reach their assets.
Governments may not be able to control when information security incidents occur, but they can control how they respond to them — expanding detection capabilities is a good start. A well-functioning security operations center (SOC) can form the heart of effective detection. Managing cyberthreats according to strategic priorities must be the focus of the SOC. By correlating relevant information against a secure baseline, the SOC can produce proper reporting, enabling better decision making, risk management, and business continuity. A SOC can enable information security functions to respond faster, work more collaboratively and share knowledge more effectively.
picture: pixabay
[i] Techopedia. (2017). Sensitive Information. [online] Techopedia. Available at: https://www.techopedia.com/definition/25260/sensitive-information [Accessed 14 March 2017].
[ii] EY. (2016). Cyber Security a Necessary Pillar of Smart Cities in 2016. [online] EY. Available at: http://www.ey.com/Publication/vwLUAssets/ey-cyber-security-a-necessary-pillar-of-smart-cities/$FILE/ey-cyber-security-a-necessary-pillar-of-smart-cities.pdf [Accessed 14 March 2017].
[iii] Gibbs, S. (2016). Ransomware Attack on San Francisco Public Transit Gives Everyone a Free Ride. [online] Available at: https://www.theguardian.com/technology/2016/nov/28/passengers-free-ride-san-francisco-muni-ransomeware [Accessed 14 March 2017]
[iv] Galbraith, R. (2016). SF’s Transit Hack Would’ve Been Way Worse – And Cities Must Prepare. [online] Wired. Available at: https://www.wired.com/2016/11/sfs-transit-hack-couldve-way-worse-cities-must-prepare/ [Accessed 14 March 2017].
[v] Reys, N. (2016). Smart Cities and Cyber Threats. [online] Control Risks. Available at: https://www.controlrisks.com/en/our-thinking/analysis/smart-cities-and-cyber-threats [Accessed 14 March 2017]