Unfit for purpose? Assessing the applicability of country-level IoT security advice

0Citations
Citations of this article
8Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Existing research offers insights into the properties of security advice and user abilities to implement such advice, but lacks insight into whether this advice is fit for purpose when applied to the diversity of consumer IoT devices. Our study bridges this gap by examining how country-level security advice from the UK, the USA, and the Netherlands relates to the user materials of 40 top-selling IoT devices across five categories, focusing on whether the advice can realistically be followed given the devices’ documented features. Drawing on manuals, videos, and organic search results, we offer a scalable approach for assessing the applicability of security advice across a wide range of IoT devices. Four overlapping pieces of advice regarding password management and firmware updates were identified in the three countries. Our assessment revealed a significant disconnect; no device supported the implementation of all four pieces of advice. At most, the analyzed materials for 36 devices provided sufficient information to apply one or two pieces of advice, primarily concerning updates. This shows that the advice does not merely fall short in isolated cases, but fails systematically to align with device capabilities. Users, typically non-experts, must determine whether expert advice applies to their devices, risking ineffective or harmful practices. This disconnect highlights a broader issue: advice itself lacks the grounding needed to support users in the first place. While framed as broadly applicable, general advice fails to account for the wide variability in device features and support materials. Even when seemingly connected to device features, advice risks leading to pseudo-security improvements rather than the proposed security improvements, placing a burden on users to assess the relevance, implementation, and security effectiveness of the advice. This situation jeopardizes IoT security at scale, and risks undermining user trust in protective measures. We propose that governments and researchers consider the practical constraints and informational contexts users face to ensure that provided security support aligns with the realities of device features and user capabilities.

Cite

CITATION STYLE

APA

Van Harten, V., Gañán, C. H., Van Eeten, M., & Parkin, S. (2025). Unfit for purpose? Assessing the applicability of country-level IoT security advice. Journal of Cybersecurity, 11(1). https://doi.org/10.1093/cybsec/tyaf024

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free