Cybersecurity for the Smart Home

0
12

The numbers of the constant growth of technologies for the smart home induce manufacturers and users to find suitable solutions for granting the protection against cyberattacks and the risk of malicious intrusions into the home network

Article by Olivia Rabbi

The Smart Home is a growing trend; driven – also – by state-of-the-art household appliances that from the IoT world increasingly look at artificial intelligence applications. Besides, with the more and more extended availability of products equipped with digital elements, the risk of cyberattacks, intrusions into home networks and theft of personal data increases, too. According to the data processed by the Observatory Internet of Things of Politecnico di Milano, in 2025 the Italian Smart Home market reached the value of 1 billion Euros, with the 11% increment compared to 2024, result in conformity with the primary European markets, where the growth ranges from 8% to 12%. Over 6 Italians out of 10 have smart devices at home. Connected household appliances constitute 20% of the total, they are worth 195 million Euros, accounting for the 15% increment versus the previous year and they rank after security solutions such as cameras, sensors for doors and windows, video intercoms and connected locks, which are worth 305 million Euros (30%, +22% versus 2024). Afterwards, energy saving solutions (142 million Euros, 14%) and smart speakers (112 million Euros, 11%). The remaining market share is made up by audio speakers (7%), dimmers and connected household appliances (6%), lamps (6%), Assisted Living solutions for fragile users’ health (2%), devices to manage curtains and shutters from remote (2%) and smart plugs, (2%). The artificial intelligence is becoming more and more central in Smart Home solutions, especially in the fields of the home automation, of the predictive maintenance and of the optimization of energy consumptions. Concerning household appliances, an important contribution is provided by small appliances, which grow by 20% due to the consolidation of the sales of vacuum cleaner robots and air fryers but also of self-driving lawnmowers and Wi-Fi-enabled pet-food dispensers. The evolution dynamics is less accentuated for big appliances, which score the 5% increment with an enlargement of the connected range, the growing integration into digital eco-systems and the introduction of assisted programming functions, as well as to grant Over-The-Air software updates.

Europe is on the move

The security of digital devices is at the core of the Cyber Resilience Act (CRA), the EU plan that aims at ensuring that all products with digital elements at disposal on the European single market are protected against cyber threats, and of their integrated solutions of data processing from remote. The (EU) 2024/2847 Regulation by the European Parliament and Council dated October 23rd 2024, concerning the horizontal requirements of cybersecurity for products with digital elements, and modifying the (EU) Regulations n. 168/2013 and (EU) 2019/1020 and the (EU) 2020/1828 Directive (Regulation about the cyber resilience), regulates the product security along the whole lifecycle. It requires that devices and software are designed, updated and constantly maintained in order to guarantee users’ protection against intrusions and attacks. The text, which will be fully applied starting from December 11th 2027, is based on three pillars: standardization, reporting obligation and conformity assessment. Harmonized technical standards facilitate the CRA implementation and translate the essential cybersecurity requisites established by the regulation into detailed technical specifications, through a collaboration activity between European standardization bodies and industry representatives. The definition of both horizontal and vertical regulations (or product specifications) pursues the target of supporting manufacturers in the implementation of the essential cybersecurity requisites.

Starting from September 11th 2026 manufacturers are obliged to report actively exploited vulnerabilities (therefore, with a concrete and imminent attack risk) and the serious incidents that affect the security of products featuring digital elements. CRA requires producers to submit a timely notice within 24 hours of discovery and a full notification within 72 hours, with a final report to be submitted no later than 14 days after a corrective measure is available for actively exploited vulnerabilities and within one months for serious accidents. According to the regulation, manufacturers make only one report through CRA’s Single Reporting Platform (SRP). The report is addressed to CSIRT (Computer Security Incident Response Team) at manufacturer’s headquarters and, barring exceptional circumstances, information are simultaneously made available to ENISA (European Union Agency for Cybersecurity). The CSIRT that initially receives the notification shares it with all other CSIRT on whose territory the product has been made available. As far as the conformity assessment is concerned, the vast majority of products, like household appliances, videogames or applications for mobile devices, will be subjected to a self-assessment by the manufacturer. For some products considered important from the point of view of the cybersecurity, such as antivirus software, boot managers or network management systems, producers will be required to apply harmonized standards or undergo an assessment by a third body called notified body. In some cases, products like, for instance, security elements, firewalls or hypervisors, are subjected to mandatory conformity assessments by third parties.

Besides regarding the product manufacturing, the regulation also aims at “creating the conditions allowing end-users to take the cybersecurity into account in the choice and in the use of products with digital elements, for instance improving transparency concerning the assistance period of products with digital elements made available on the market”, looking at a sector regulation on a European scale to ensure a harmonized regulatory framework, introducing horizontal cybersecurity requirements for products with digital elements, besides “ensuring the legal certainty for economic players and users throughout the Union, as well as a better harmonisation of the internal market and proportionality for micro, small and medium-sized enterprises, creating more comfortable conditions for economic operators who intend to enter that market”. Establishing cybersecurity requisites for the release on the market of products provided with digital elements, the regulation intends “to improve the cybersecurity of such products for both consumers and enterprises. Moreover, such requirements will ensure that the cybersecurity is taken into account in all provisioning chains, making final products with digital elements and their components more secure”. This also includes “requisites for the release on the market of consumer products with digital elements intended for vulnerable consumers, such as toys and monitoring systems of newborns. The consumer products with digital elements classified in the present regulation as products with important digital elements feature a higher cybersecurity risk as they carry out a function that implies a significant risk of negative effects in terms of intensity and ability to harm the health, the security or the safety of the users of such products and they should be subjected to a more severe conformity assessment procedure. This applies to products such as smart home products with security functions, including smart locks, newborn monitoring systems, connected toys and personal wearable health technologies”. Furthermore, we can read in the text, “the more stringent conformity assessment procedures, to which other products with digital elements, classified in this Regulation as products with important or critical digital elements, must be subjected, will contribute to prevent the negative effects that the exploitation of vulnerabilities may exert on consumers”.

Conformity assessment for products with digital elements

In particular, data processing solutions from remote “should be defined as a remote data processing for which the software has been designed and developed by the manufacturer of the product with digital elements at stake or on his behalf, whose absence would prevent the product with digital elements from performing one of its functions. Such approach ensures that those products are properly protected by manufacturers in their entirety, irrespective of the fact that data are processed or stored locally on the user’s device or remotely by the manufacturer”. Each product with digital elements must report, in a clearly visible, legible and indelible manner the CE marking that certifies the conformity with the Regulation (article 30). Moreover, before releasing a product with digital elements on the market, manufacturers draw up the technical documentation (article 31), and follow or have the conformity assessment procedures (article 32) executed. “If such conformity assessment procedure demonstrates the compliance of the product with digital elements with the essential cybersecurity requirements as per Annexe I, part I, and the processes implemented by the manufacturer to comply with the essential cybersecurity requirements set out in Annex I, part II – the Regulation reports – the manufacturers draw up the EU conformity declaration in conformity with the article 28 and they put the CE marking in conformity with the article 30”.

Benefits and risks of the Smart Home

The Smart Home, based on IoT and more and more advanced artificial intelligence applications, strongly characterizes the contemporaneous domestic scenario, due to the availability of automated devices and systems, connected in a home network to allow carrying out actions from remote; besides others, they include the control of household appliances, turning on and off home lights, managing the indoor temperature, and much more, everything by means of a single device. Different characteristics characterize it and, specifically referring to household appliances, they deeply influence the equipment of appliance componentry. They are clearly listed by the website of Kaspersky company, specialized in the production of cybersecurity solutions.

Connectivity leads to equip Smart Home devices with sensors, processors and communication technologies such as Bluetooth or Wi-Fi, which enable either the mutual connection or to a central hub for the remote management of devices themselves (a smart loudspeaker or an app), creating a domestic network. The data sent by sensors and collected allow understanding the home structure and inhabitants’ habits to improve the user experience of devices and to optimize, for instance, energy saving and security performances. Automation functionalities allow Smart Homes to act automatically according to users’ requirements, whereas the interaction of smart devices with other services permit to improve security or efficiency performances. In addition to the benefits brought to daily life in a domestic environment, the Smart Home also involves numerous risks of security and user protection, since the connected devices constantly collect and process huge amounts of data that concern users’ personal habits, preferences and activities within the house. The list includes the privacy violation, intrusions, hacking and theft of personal data. As Kaspersky.it reports, the primary threats that the Smart Home must face include hacking, malware, phishing, DDoS attacks, botnet IoT and “man-in-the-middle” attacks. In the creation of possible conditions and damages, a contribution may be given by compatibility problems among devices and platforms and by the difficult management of manifold apps and control interfaces for the different devices, especially for the least expert users, as well as the reliability of the Internet connectivity and of operational protocols, even in the face of problems such as network outages, technical issues or service anomalies; another weakness can be the dependence on third-party’s servers and cloud services.

How to protect the home network

What can we do to implement efficacious defence and protection practices for our home network, our connected devices and appliances? The first step, according to Kaspersky.it, is the protection of the Wi-Fi network by using a strong and unique password (possibly also through a password manager programme), enabling the WPA2 or WPA3 encryption. Moreover, it is important to update constantly devices and apps to the recent firmware and software versions, which include security patches, to enable the two-factor authentication (2FA) for Smart Home accounts, which include not only our password but also a verification code sent to our smartphone, to segment our network by separating Smart Home devices from computers and smartphones, to review the permissions granted to the apps of Smart Home devices, thus granting the access only to really necessary data and functions, and to monitor the network traffic to identify unusual or suspicious activities. This is not enough, it is also necessary to ensure that devices are installed securely, by evaluating the possibility of adopting specific security measures the make the devices in the domestic space physically inaccessible from the outside, even with locks or security cameras, as well as regularly checking and updating the settings and configurations of Smart Home devices by deactivating unnecessary functions or services that could pose potential risks to privacy or security. Finally, it is necessary to assess our requirements by evaluating whether or not we really need to add new smart devices to our home network that might increase the potential risk of cybersecurity attacks.

What companies do

Manufacturing companies comply with the provisions of Article 13 of the EU Regulation on Cyber Resilience, which requires the clear indication and the provision of contact details and contact points – both digital and otherwise – for users, to request any information or to report vulnerabilities in products with digital elements. This is the goal of the establishment, inside companies, of teams dedicated to cybersecurity, together with the prearrangement of adequate contact forms by users for reporting vulnerabilities detected in systems and in the use of products and services, as well as in cyber security incidents. A service that can be joined and integrated by updates and security notifications constantly updated, addressing users, as well as by the broader collaboration among the manufacturing company and other internationally renowned centres and offices operating in the field of the protection against cyber risks. A contribution to the protection against cyberattacks and the theft of personal data for connected household appliances with AI and IoT functions is given by a development process of the finished product, from design to use, which integrates dedicated devices and systems, also with the connection to digital platforms, which preventively block any attempt of access to the network and to appliances by hackers and cybercriminals.

LEAVE A REPLY

Please enter your comment!
Please enter your name here