Skip to main content

How cyber security, personal safety and consumer trust are becoming increasingly interconnected

The connected world has changed

Connected technology has transformed the way we live. Smart homes, connected workplaces, and mobile apps now manage everything from unlocking our front doors, answering the doorbell, controlling our heating, accessing healthcare, managing our finances and keeping in touch with family and friends. They are an integral way of life, providing us with connections, convenience, efficiency, independence and reassurance.

As these technologies become embedded into our daily lives, so too have the challenges of cyber security. Businesses and consumers are all too familiar with the threats faced by phishing, ransomware, data breaches, identity theft, and online scams. Organisations spend millions each year in cyber security measures to protect their systems, data and customer information to reduce the risk of data breaches, financial costs and reputational damage.

Cyber security is about more than cyber attacks

For many years cyber security has focused on protecting systems from external attacks. Increasingly though academic researchers, frontline organisation and policing warn of another challenge, the misuse of technology to facilitate stalking, intimidation, harassment and coercive control. Technology-enabled abuse can affect anyone, but women and girls are disproportionally affected, making it increasingly important for designers and developers to consider when creating connected products, services or apps.

According to the National Police Chief’s Council (NPCC) more than 123,000 offences of Violence Against Women and Girls (VAWG) involved technology or took place online. Between 2018-2024, the charity Refuge reported a 207% increase in tech abuse referrals, which along with online harassment and grooming, included new emerging cyber-crimes such as cyberflashing, image-based abuse, AI-generated deepfakes, sextortion, and doxxing.

Research at the UCL University’s Gender+Tech Research lab is helping shape policy and improve understanding of how technology-facilitated abuse happens in practice. It’s often not about sophisticated cyber-attacks or using specialist spyware, but rather the connected technology found in millions of homes such as smart doorbells, lighting systems, wearables and the apps that manage them. In the wrong hands these become tools for surveillance, intimidation and control.

With Violence Against Women and Girls (VAWG) declared a national priority by the UK Government, manufacturers, IoT developers and mobile app developers are being encouraged to consider not only traditional cyber threats, but also how every day tech is now being used and harnessed to cause harm.

Technology-enabled abuse is fast becoming an important crime prevention challenge, and the design of products, alongside independent security assurance has an important role to play.

What does this mean for industry?

The challenge is not the technology itself, but ensuring that it is designed, developed and maintained securely. Weaknesses in security, privacy or account management create opportunities for misuse if they aren’t built in from the outset, it’s like trying to add locks to windows that have been left open.

For IoT developers, manufacturers and mobile-app developers, cyber security is no longer just about protecting against hackers. It means looking at how to protect the people that are using connected products and apps with appropriate measures and safeguards such as:

  • Strong authentication
  • Appropriate permissions and access controls
  • Secure account recovery
  • Encryption of sensitive information
  • Secure software updates
  • Privacy controls

 

The Secured by Design (SBD) Secure Connected Device scheme has been developed with the simple ethos that ‘designing out crime’ is far more effective than trying to protect against it later.  After accrediting security products that have met tough physical standards, it was the next natural step to ensure that IoT (internet of things) devices also met robust, industry-recognised cyber security standards.

Smart products, devices and services are independently tested and certified against ETSI EN 303 645, which meet and exceed the requirements of the UK Government’s Product Security and Telecommunications Infrastructure (PTSI) Act introduced to ensure products met basic security standards to protect consumers.

Independent testing identifies vulnerabilities and provides recommendations for improved security. This ensures cybersecurity has been considered and designed in from the earliest stages of product development, reducing future costs and future fixes while strengthening consumer trust.

New mobile app accreditation

As manufacturers and developers increasingly use apps to operate smart products, it is important to understand that those apps are often the gateway to connected devices, storing account credentials, location data, personal and financial information. Ensuring these are developed securely is as important as securing the connected products they control.

Standalone apps also should be assessed to help app developers identify and address vulnerabilities that could expose users and their personal information. This is even more important for apps aimed at supporting women and girls, such as personal safety apps, lone-worker platforms, health or tracking apps, community or dating apps. Many of these have features such as personal profiling, image sharing, real-time check in, and geo location sharing, but the very features that make these apps useful could also increase the risk of tech-enabled abuse if they are not properly secure.

The new SBD Secure Connected Device app accreditation is tested against the globally recognised OWASP ASVS/ MASVS standard and looks at:

  • Unauthorised access
  • Compromised accounts
  • Privacy breaches
  • Misuse of personal information
  • Defences against common cyber attacks

Technology we trust

As connected technology continues to evolve at a pace, from AI assistants, connected vehicles, smart cities, digital healthcare and robotics, it is important that regulations and security standards evolve too. Cyber security is no longer just about protecting organisations and systems from attack, it is also increasingly about protecting people from harm, particularly women and girls.