IoT systems are complex and challenging to secure, and a vulnerability in a connected product can present a risk to safety and privacy, not only to data.
Participants discover the differences between IoT and IT security, see how cyber attacks compromise IoT systems, and learn the principles that protect a product at every stage of its lifecycle: devices, networks, mobile applications and cloud systems.
Two formats. The one-hour awareness session covers the challenges, the threats and the principles, and can be deployed as a package on your internal training platform. The one-day course adds the analysis of real-life attacks, the good practices that prevent them, security and privacy by design, and what standards and regulation now require.
Audience: this course is ideal for non-technical participants such as project and product managers, executives, new IoT manufacturers and start-ups who want to learn the basics of IoT security. It is also built for developers and security experts who want to update their knowledge on IoT. No prior knowledge of cyber security is required.
The course integrates elements of the ENISA IoT guidelines, the OWASP IoT Top 10, and the requirements that EN 303 645 and the Cyber Resilience Act place on products.
Objectives
-
Understand the security challenges of IoT systems and how they differ from IT.
-
Get up to date with the latest threats and vulnerabilities affecting connected products.
-
Learn the good security practices and how they prevent cyber attacks.
In the one-day course, also:
-
Assess threats and risks for devices, networks, mobile applications and cloud systems.
-
Analyse real-life cyber attacks on IoT systems and understand their root causes.
-
Apply security and privacy by design, and understand what standards, certification and regulation now require.
Programme
-
Introduction to IoT systems and their differences with IT systems.
-
The security challenges of IoT: the threats to IoT systems and the risks to users, systems and society.
-
The principles that secure IoT systems, at every level: governance, organisation, operations and technology.
In the one-day course, also:
-
Deconstructing high-profile cyber attacks against IoT, and the root causes behind them.
-
Applying good practices to prevent the attacks analysed, and the bad practices to avoid.
-
Security by design: how to secure project management and product development. Privacy and GDPR for IoT products.
-
Beyond good practices: standardisation, certification and labels, and what the Cyber Resilience Act and EN 303 645 require.
