• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » Avoiding Regulation of Device Security? It Doesn’t Have to Be a Struggle

Think Tank
Think Tank RSS FeedRSS

Avoiding Regulation of Device Security? It Doesn’t Have to Be a Struggle

March 25, 2022
Jeanette Sherman, SCB Contributor

Today’s device manufacturers not only face vulnerabilities and costly security breaches, but the growing potential for government regulation as well.

Hackers are finding new ways to gain access to internet of things (IoT) products and weaponize them for attacks, even as manufacturers create new products at a scale that makes manual security processes impractical. The vulnerability in Log4j’s code is just the latest to dominate cybersecurity headlines and affect hundreds of millions of devices. As Cybersecurity and Infrastructure Security Agency (CISA) director Jen Easterly said, “It is one of the most serious I’ve seen in my entire career, if not the most serious.”

All the more serious because, for various reasons, manufacturers often don’t know what vulnerabilities their devices might have. According to a survey we recently conducted with the Ponemon Institute, only half of manufacturers test products before deploying them. Sixty-two percent of respondents say they lack resources to properly secure their products, and 60% say they lack in-house expertise.

Despite the challenges, something has to change. Fifty-nine percent of respondents say security concerns have cost them sales. And while only 12% say the government should be responsible for ensuring the security of IoT devices, inaction could force regulators to step in, especially if cyber-physical attacks grow in severity and scale.

Most manufacturers would prefer to avoid government regulation, but at least for those in the private sector, there could be another option.

The government began establishing regulatory frameworks with an executive order in May, 2021. Among the mandates is a requirement that federal agencies adopt zero-trust architecture, but there isn’t much assistance to get them there. Unless something changes, the current path of IoT breaches leads toward more government regulation for device manufacturers.

For some, this is unavoidable. In our study with the Ponemon Institute, 36% of respondents say government regulators already require their organizations to provide details about the components of devices or attest to their security.

But government regulations aren’t as responsive as they could be. Regulations could be imposed by people who lack deep knowledge of the issues that the regulated sector is facing. Mandates made reactively, in response to attacks, tend to be implemented quickly.

You can have a much more responsive and flexible framework for security requirements when they come from a private, non-government regulatory body. There’s a national council of Information Sharing and Analysis Centers (ISACs), each of which creates security standards within its sector. The idea is to make sure that the industry has enough self-set regulations that government regulations aren’t necessary.

For example, the IT-ISAC is a non-profit, limited liability corporation formed in 2000 by members of the information technology sector. IT-ISAC touts that “members have access to tens of thousands of threat indicators each week,” and “can help a company manage risks through trusted analysis, collaboration and coordination and drive informed decision making by policy makers on cybersecurity, incident response and information-sharing issues.”

Other ISACS that are active in the IoT world include the Automotive ISAC, Communications ISAC, Healthcare Ready, Health ISAC, and Water ISAC.

Through private regulation, organizations have better visibility into how and why the rules are created, and are likely to have more of a say in what they are. Public regulation doesn’t typically have that transparency or insight from anyone outside the governing body.

Device manufacturers are responsive to their customers’ needs, which is one reason that product security is becoming more important. According to the survey, 73% of respondents noted that customers’ device security concerns had a high impact on the length of the sales cycle. Additionally, 55% of respondents’ sales teams put pressure on those responsible for product security to attest to their security.

A clear set of regulations would make the target easier for those product security teams. While end users might not understand the details of what’s in a device, it’s far more reassuring to know that security standards are created by experts in the field rather than politicians.

If a manufacturer abides by private regulations, it can instill customer confidence that there’s a well-thought-out prescription for security, and that the device was deployed with quality in mind.

Jeanette Sherman is senior director of product at Finite State.

General SCM Technology Technology Regulation & Compliance Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • A TRUCK WITH ITS CONTAINER DOOR OPEN SITS UNDER A SIGN THAT READS INTERNATIONAL BORDER COMMERCIAL TRUCKS

    Importers Into Mexico Can No Longer Delay Complying With New Customs Declaration Law

    Data Management (Big Data/IoT/Blockchain)
  • 018_how_3pls_can_get_started_with_ai_v1-(540p).png

    Watch: How 3PLs Can Get Started With Automation

    Logistics Outsourcing
  • An employee in a warm suit crouches down to get boxes of food ready for shipping at a warehouse

    Packaging Optimization Is Boosting Cold Chain Growth

    Air Cargo
  • A FIGURE IN CAMOUFLAGE LOOKS THROUGH A SCOPING DEVICE AT A SHIP IN THE DISTANCE, BELCHING SMOKE

    Strait of Hormuz Ship Transits Are Rising Thanks to U.S. Help

    Global Gateways
  • Heat Haze Distorts Video of Semi-Trucks Driving Down an Interstate Surrounded by Mountains on a Sunny Day

    The Biggest Challenges Facing Logistics Operators This Summer

    Logistics

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing