The following sections provide a narrative of the current state of cyber security in the smart streets industry. While no two authorities are the same, a general picture can be formed of what current cyber security practices look like from the perspective of local transport specialists working in authorities. This narrative was compiled based on interviews with stakeholders from authorities, suppliers and institutions from across the UK.

Most authorities have an IT security team functioning within their IT department. This team focusses primarily on traditional enterprise security. They promote cyber security hygiene amongst staff and set and enforce policies for enterprise workstations and networks. Many run an information security management system (ISMS) in line with ISO 27001. However, this team tends to have only limited understanding of and involvement in smart streets operational systems. Where major projects are involved (typically £100k+), the IT security team at some authorities may be involved with the setting of cyber security requirements. However, these supplier assurance questions and contractual clauses are not necessarily tailored to operational technology (OT) and the transport engineering lifecycle.

For smaller projects, budgetary constraints usually mean that cyber security considerations are often overlooked altogether. This is a concern because many smart streets solutions start as small trials, but then evolve into larger, more permanent systems. Organisations typically want to take a proportionate approach to managing purchasing (procurement) risk but often attempt to achieve this through an initial triage of projects that need to undergo formal supplier assurance activity based solely on project spend (e.g. min of £100k procurement cost) which does not adequately consider other types of risk, such as cyber security, which could potentially far exceed the expected procurement cost. When security is not considered from the outset, it can be more difficult and expensive to address it later.

The teams responsible for the planning, delivery and operation of smart streets solutions in local authorities tend to be small. In some cases, the entire team may consist of a sole project or programme manager with no dedicated engineering resource on the side of the authority. Authorities generally lack governance structures and policies that compel these teams to consider cyber security outside of a limited number of cases where it is necessitated by regulation (e.g. the Data Protection Act 2018, i.e. GDPR). Currently, cyber security considerations within smart streets teams are driven primarily by cognisant staff who have already recognised that cyber security is a concern with these types of projects. However, these staff have expressed that, while generally cognisant, their lack of cyber security experience means they do not fully understand the risks and how to address them. This highlights two key issues:

  • Neither IT-focussed security staff nor transport-focussed project staff tend to have a system security engineering experience, thus there is a lack of capability.
  • Current local authority security risk management and governance is not fit for smart streets.

Due to the lack of system security engineering capability, system security tends to be mostly reliant on the supply chain. Some large system integrators now have dedicated cyber security officers for product and system security engineering and governance with specific considerations for product and system engineering lifecycle (though this is not universal). While this is a positive development, there are still concerns. Most importantly, cyber security does not end at delivery. It must be maintained throughout the lifecycle of the system. There are different operational models, but the most common ones involve either the whole system being handed over to the authority as a turn-key solution, or the system integrator operating only certain parts of the system. Thus, a major concern is the current lack of security considerations and ongoing assurance in the relationship between authority and supplier:

  • There is limited formal definition of security requirements by the supplier for maintaining the cyber security of the system throughout its operational life and acceptance and compliance of these by the authority as part of handover.
  • On-going product support from suppliers, e.g. incident reporting, incident response support, patching, is often missing.
  • Projects do not identify the support systems for maintaining cyber security (e.g. testing patches before pushing to a live system, plans for patch deployment, or disclosure of vulnerabilities by the supplier).

Addressing these issues can raise upfront costs, and so performing full lifecycle costing during planning and procurement, including cyber security maintenance, is important.

Example of an appropriate split of responsibility for an authority owned use case

Example of an appropriate split of responsibility for an authority managed use case

Even if the security relationship between authorities and the main system integrators were addressed, the smart streets industry is also full of small and medium enterprise (SME) suppliers. While these small suppliers often contract through a system integrator, there are perhaps just as many cases where authorities work directly with small suppliers, particularly on smaller projects. There are trade-offs between promoting innovation and competition by not burdening SMEs with security assurance costs and the authorities managing their security risks. Governments, both local and national, should consider this. Initiatives by authorities in other transport industries have aimed to address this. Network Rail, for example, judges large suppliers on whether they support SME suppliers in areas such as building security maturity.

Smart streets infrastructure is often hosted on cloud servers run by smart streets suppliers (though they may use a third-party cloud platform, e.g. Amazon Web Services), as opposed to servers run by the authority. There are pros and cons to such arrangements. Large cloud suppliers may have a greater cyber security capability than the authority and can offer economy of scale. However, large cloud suppliers may also be more attractive targets for attackers. Regardless of the supplier, if the authority is not involved in security risk management activities with the supplier, incidents could be more likely to arise. The authority needs to ensure that the supplier is in fact adequately secure through third-party assurance and commercial terms.

Industry Lessons

A UK local authority was left with severe congestion due to a loss of traffic optimisation after servers hosting its traffic management platform went down. These servers were hosted by a major intelligent transport systems (ITS) supplier. Although this incident was not necessarily the result of cyber-attack, it demonstrates the importance of good business continuity planning with the supply chain, which includes reducing the impact of cyber-attacks.

Managing security risks in the supply chain is one of the most universal challenges faced by all authorities. Procurement staff involved in smart streets generally have only limited security awareness. While some authorities do specify cyber security requirements, these requirements are often copied without specific consideration to whether they are suitable. As mentioned previously, supplier selection is either not influenced by the supplier’s security capability, or the wrong capabilities are considered. For example, if procuring a product or system, judging a supplier solely on whether they implement ISO 27001 or Cyber Essentials is not sufficient. Compliance with these standards indicates that the organisation keeps data secure, but not that they understand or follow good practice around product or system security engineering.

Industry Lessons

A UK train operator reportedly suffered a cyber-attack due to a lack of security measures implemented on a mobile telecoms product. Security capability considered during the procurement process focussed only on the supplier’s ISO 27001 compliance. As a result, suppliers with products that may have offered more appropriate security capability were not recognised.