Authorities often outsource the delivery and/or operation of transport services. While operations can be outsourced, organisational risks cannot. While authorities can rely on the cyber security capabilities of third parties, ultimate responsibility for security remains with the authority. An authority that does not build its security posture may face outcomes ranging from unexpected costs to disruption in the community to, in the most extreme cases, charges of criminal negligence.
Industry LessonsA major UK train operator recently procured digital railway systems without organisational awareness of cyber security and under the assumption that cyber security was the responsibility of the system vendor. Cyber security concerns were later identified after the system went into operation. The vendor cited lack of security considerations in the procurement process and declined to take responsibility for the issue. The train operator was thus faced with significant security risks that were previously unknown and high costs to identify and implement appropriate mitigations. |
Before planning and procuring smart streets systems, an authority should ensure the organisation is prepared to identify and manage operational cyber security risks.
It is likely that your organisation already has policies and processes in place to manage more general IT security risk. Many local transport authorities have implemented the NCSC’s Cyber Essentials scheme, and more mature authorities may have implemented the IT security standard ISO 27001. These standards are suited for managing general enterprise IT security, but this does not automatically mean your organisation is prepared to handle cyber security risks posed by operational technology. The guidance in this section will help ensure you have a cyber security management system (CSMS) fit for this purpose.
Smart streets have most of the same characteristics as those systems deemed as critical national infrastructure by the UK Government. Thus, the NCSC Cyber Assessment Framework (CAF) is a useful tool to gauge your local authority’s smart street programme security posture.
Authority Supported ServicesEven where a local transport authority will not be managing services themselves, the authority should still build sufficient security maturity to understand wider security risks posed to transport services within their community and, where necessary, ensure appropriate assurance and management of third-party service providers. |
| Applicable to: | All use cases |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills |
Most authorities have an IT security team. This team is typically part of the IT department, and they usually run an information security management system (ISMS) based on ISO 27001 or otherwise implement the NCSC’s Cyber Essentials scheme, a lightweight derivative of ISO 27001. This team is responsible for the security of information and data across the authority’s enterprise estate. The IT security team will usually have responsibility for the authority’s compliance with data protection regulations, but this responsibility may be split with the legal compliance team.
Good IT security governance is essential to supporting secure smart streets. However, issues can arise from the fact that smart streets systems do not always receive appropriate oversight from the IT security team. Reasons for this vary. One reason is that many smart streets systems have traditionally been operated physically and logically separate from the authority’s enterprise IT. Another reason is that IT security standards like ISO 27001 have insufficient considerations for OT systems and the engineering lifecycles through which they are managed.

Many local authorities have identified that smart streets projects do not receive appropriate cyber security risk management and governance. It also acknowledged that it would be difficult to leave these responsibilities entirely to smart streets engineers, particularly given some projects lack an engineering layer on the authority side altogether.
What is needed in authorities is greater and more structured collaboration between smart streets project staff and the IT security team to ensure that cyber security risk is properly managed for all smart streets projects. IT security and smart streets stakeholders should collaborate to form an initiative that looks at existing security governance and considers whether it is fit for purpose. This section provides guidance around what effective security governance for connected places looks like.
IEC 62443-2-1 is a standard intended to supplement ISO 27001 by extending the ISMS with a CSMS tailored for OT systems. This standard is widely used by transport infrastructure operators around the world to build a CSMS. Many authorities may not feel they are in a position to implement the full IEC 62443-2-1 standard, but the MfSS Cyber Security Guidance includes a lightweight set of security management recommendations that have been derived from IEC 62443 and NIST 800-160.

If you already have a security management system such as an ISMS, we recommend that you first check that it covers smart cities systems and then carry out a gap analysis between these elements and those in your current system.
We recommend a smart streets ready CSMS should include:
| Applicable to: | All use cases |
|---|
| NCSC Connected Places CS Principles: |
| #1 Understanding your connected place and the potential impacts #2 Understanding the risks to your connected place #5 Understanding legal and regulatory requirements |
Establishing cyber security culture within your organisation requires buy-in at all levels, and particularly from executive management. For this, a clear rationale should be defined, which essentially serves as your business case for being cyber secure. The NCSC Connected Places Cyber Security Guidance principles #1, #2 and #5 offer questions that should be considered when developing the cyber security rationale for a connected place.
You should define how cyber security supports the strategic goals of the organisation and how a lack of cyber security harms the goals. You should highlight the high-level risks posed by neglecting cyber threats. Cyber-attacks can have an impact on your authority’s finances, reputation and legal compliance, but can also have an impact on public safety, the environment and the local economy.
The case studies (1A and 2) and Recent Incidents section found in this guidance are intended to help you consider potential cyber risks and develop a rationale for your connected place cyber security management system. Based on the examples provided, you can consider the threat landscape at your own authority.
When identifying risks that you are trying to protect against, it is additionally important to understand your regulatory environment, particularly around cyber security, data privacy, safety and the environment. Individual smart streets systems may have specific regulatory and standards considerations. Some of these will be directly cyber security related such as the Data Protection Act 2018 (GDPR) for systems that handle personal data or PCI DSS for systems that process payments. Others such as the Environment Act 2021 are not cyber security-related, but a cyber-attack could indirectly cause non-compliance.
| Applicable to: | All use cases |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills |
Security risk is ultimately owned by the chief executive of the authority, as the person with overall accountability to the local council. Individual business functions or projects may have direct risk owners with accountability for a specific scope. A security risk governance structure helps to inform risk owners and allow them to make confident decisions.
Within the security risk governance structure, it is essential that clear roles and responsibilities are defined for cyber security in the organisation. Leadership should, as a minimum, appoint a senior leader to have overall responsibility for cyber security (e.g. a Chief Information Security Officer, CISO) Beyond that, an organisational structure or network of people can be defined where security responsibilities for specific projects or disciplines can be delegated.

Example of how security roles and responsibilities could be defined at a high level.
The security officer for the organisation should enact cyber security policies and procedures to ensure security is considered from day one by new smart streets projects, and that existing projects and operations work to identify their security risks to inform the security officer. Some of the most critical security policies and procedures we recommend the authority’s security officer enact are a:
| Applicable to: | All use cases |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills #4 Understanding your suppliers’ role within your connected place |
System assurance supports a risk owner in accepting that the risks of the system have been appropriately identified and managed, and that the residual risk meets the risk owner’s appetite.
The risk owner should be aware of cyber security risks and how they have been managed. However, the risk owner is generally not a cyber security expert, so a security assurance framework helps provide the risk owner assurance that good practice has been followed. Furthermore, a security assurance framework ensures that the supplier’s expectations are set regarding level to which they need to consider security and what deliverables they need to generate in order to gain the approval of the authority.
The security assurance framework should be flexible and provide different levels of assurance based on the criticality of the project so as to not create unnecessary costs. Typically, a short and simple security classification questionnaire should be completed at the start of a smart streets project to determine the potential for security risk. This is a consideration of the impact alone, with no consideration to likelihood, which may require a more in-depth assessment. Based on the potential for security risk, the project can be assigned a criticality.
The following table provides an example security classification questionnaire:
|
|
High (Full |
Medium (Light |
Low (Simple |
|
What |
Likely |
May have |
No |
|
Would |
Major violation of data protection regulations |
Minor violation of data protection regulations |
No sensitive data could be exposed leading to a |
|
How |
Failure |
Failure |
Failure would |
|
What |
Failure would have a widespread impact on other |
Another system or service may be impacted by |
No other system would be impacted by a failure. |
|
Does the system directly interface with a critical system? |
Yes. A compromise of the system could potentially allow an attacker to launch a further attack on the critical system. |
Only indirect interfaces to critical systems. |
No interfaces to critical systems. . |
|
What |
Complex |
A system |
An |
|
How |
A new type of system never before deployed. |
A new type of system deployed by only a few authorities. |
A mature type of system with a long established |
|
What |
Authority |
Authority |
Public |
|
|
|
||
|
Example |
New traffic |
CCTV |
Vandalism |
Example OT security classification questionnaire.
Given that no project will perfectly fit one of the above criticalities, the authority can set rules regarding how a project is given a security classification. For example, points can be assigned to each answer with a threshold given for each level of criticality.
For each level of assurance, the framework should explain what an acceptable cyber security assurance case would include. It should set out your high-level expectations for the types of security activities that will be carried out and types of security deliverables that will be produced.
Given their size, local authorities must be particularly careful not each adopt widely varying requirements within their security assurance framework. Ideally, there would be a specific standard for smart streets or smart cities, but this is not currently the case. We recommend authorities keep their security assurance framework as generic and in line with NIST 800-160 and IEC 62443 as possible. National transport authorities such as Network Rail and National Highways typically already have a security assurance framework and specify that system suppliers must follow the framework. It may be advisable to work towards alignment with other national and local authorities through forums such as the Local Council Roads Innovation Group (LCRIG) and the Transport Technology Forum (TTF).
Below is an example of such a framework.
|
Phase |
Min. Activities for |
Min. Activities for Light Assurance |
Min. |
|
|
Security |
Allocate security role |
|||
|
Determine |
||||
|
Security Definition |
Conduct high-level threat and risk assessment |
Identify standard security considerations |
||
|
Specify security |
||||
|
Secure |
Responsible engineer oversees purchasing |
– |
||
|
Secure Delivery |
Conduct |
– |
||
|
Review detailed security design |
– |
|||
|
Conduct |
– |
|||
|
Manage remediation |
– |
|||
|
Plan for |
– |
|||
|
Secure |
Regular audit and review of the assurance case |
– |
||
|
Secure |
Manage |
– |
||
Example OT security assurance framework, minimum required activities.
|
Phase |
Req. Deliverables for |
Req. Deliverables for Light Assurance |
Req. |
||
|
Security |
Security Assurance Plan |
– |
|||
|
Security Definition |
High |
– |
|||
|
Security Requirements Specification |
|||||
|
Secure |
– |
||||
|
Secure Delivery |
Security Implementation Plan |
– |
|||
|
Detailed |
– |
||||
|
Detailed Security Design |
– |
||||
|
Security |
– |
||||
|
Security test results and remediation evidence |
– |
||||
|
Secure |
Security |
– |
|||
|
Secure |
Decommissioning Certificate |
– |
|||
Example OT security assurance framework, required deliverables.
| Applicable to: | Owned and managed services |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills |
An important part of establishing cyber security governance within your organisation is ensuring that projects take cyber security seriously and do not progress without identifying and managing security risks. Adding generic cyber security milestones to your organisation’s project management process and requiring them to be achieved to pass certain stage gates is a common method to achieve this.
The ideal approach is to align the project management process with the security assurance framework. However, it is a prerequisite that the authority have governance relating to project controls.
It is important that all smart streets projects, no matter the size, consider cyber security. The level to which cyber security is considered should be proportionate to the associated risks, but no project should be completely exempt based on size alone. As a minimum an upfront assessment should be performed and recorded to establish that no significant cybersecurity risks exist.
Observations in Part 1 demonstrate that small trial smart streets projects can evolve into larger, more permanent operations. If cyber security is not considered from the start, cyber security risks can be found later at a time when they become difficult and expensive to mitigate.
This does not mean that small projects can nor need to allocate significant funding to cyber security. Simple awareness of potential security risks can allow a trial system to be architected such that it is more feasible to address cyber security later.
Industry LessonsA drone research company recently had limited funding to develop a demonstrator of a new unmanned aerial vehicle control system. Securing the demonstrator was not necessary for the trial, and it was undesirable to invest in the security of a project that may not be progressed. Under the guidance of their security officer, they followed the framework of an appropriate cyber security standard, but did not implement security measures. Because they followed the framework from project start and maintained an awareness of security, it was later a much simpler exercise to secure the system once the prototype was proven. |
When there is a change in project scope, the security classification questionnaire should be revisited to avoid unmanaged scope creep.
| Applicable to: | All use cases |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills |
An important part of building security maturity at your authority is ensuring that all staff have an awareness of cyber security and an understanding appropriate for their role. You should have a security training programme with different levels of training aimed at different groups of staff. Most authorities already have a general security awareness e-learning session targeted across all staff. This typically includes considerations such as avoiding phishing emails.
However, for project managers and engineers, more targeted training is needed. This is because these roles must now take on engineering security responsibilities, despite most having no background in cyber security. There are an increasing number of training courses available either based on IEC 62443 or tailored to smart cities cyber security. Suitable training courses would:
It may also be advisable to target procurement staff with some security fundamentals training, so that when they need to support security-aware projects, they have an understanding of the vocabulary and concepts involved. However, we still expect that the project manager or engineer will need to take responsibility for ensuring purchasers consider security.
Off-the-shelf training courses targeted at connected places are currently rare. Thus, a common approach is to work with a cyber security consultant or training specialist to tailor existing generic and industrial cyber security syllabuses to the standards and applications applicable to the authority. Training is another area where authorities could benefit from a joint approach. If local authorities were to jointly procure smart cities or smart streets security training, or the training were arranged centrally, a better targeted course could be procured at a lower cost.
| Applicable to: | Owned and managed services |
|---|
| NCSC Connected Places CS Principles: |
| #3 Understanding cyber security governance and skills #4 Understanding your suppliers’ role within your connected place #12 Managing your connected place’s supply chain #13 Managing your connected place throughout its life cycle |
Smart street solutions are often reliant on many supply chain partners, such as product vendors, system integrators and service providers. These partners are essential to operating smart street services, however, reliance on the supply chain can also introduce cyber risk if not managed properly. It is important that authorities understand who their suppliers are, what subcontractors they rely on, what critical data and functions they handle, what security measures suppliers are contractually obliged to take, and what playbook is in place with suppliers in the event of a safety incident.
The NCSC recently released Supply Chain Mapping (SCM) guidance. Authorities should consider implementing this guidance within their supply chain management framework to prepare for the challenge of procuring from and relying on supply chain partners throughout the life cycle.
Most products today come from a global supply chain, and the regulatory frameworks within which suppliers operate can introduce security risks. Regulations in some jurisdictions may force suppliers to secretly comply with government requests to plant deliberate security vulnerabilities, such as backdoors, in products. When managing supply chain security risks, authorities should be aware of this possibility.
Given that attempts to mitigate these risks can easily become intertwined with geopolitics, local authorities should take care when developing policies to blanket ban suppliers based on nationality. However, the risks should be considered:
The first two risks can be mitigated by preferring suppliers from countries that are considered to have compatibile values. However, this is a sensitive and specialist matter outside the scope of this guidance. The third risk can be mitigated by procuring products that have been subject to extensive independent testing. However, for many small products, this is not economically viable.
Authorities whose supply chain includes cloud services should consider in which jusrisdictions data is processed and stored. Data is subject to the regulations of the jurisdiction where it is handled and kept. Processing data outside the UK may be incompatible with the Data Protection Act 2018 unless the other jurisdiction is approved by the UK government. Your procurement policy for cloud services should consider this.