...
Skip to content

Smart cities face web of cyber challenges

More cities are becoming “smart,” adopting technology to improve their citizens’ quality of life, but rapid advances come with some heightened risks that can stretch resources. 

Cities and communities making expansive use of new technology face challenges addressing cyber risks because of their traditional budgetary constraints and problems competing with the better-paying private sector for top personnel, experts say.

Smart city initiatives can include utilities, energy and transportation, but also projects as small as monitoring available parking for electric vehicles. The projects usually rely heavily on “internet of things” technology, including sensors and other monitoring devices that collect large amounts of data. The data is then used to manage resources and services.

“At its core, the smart city’s probably best described as an ‘internet of things’ exercise, because it’s integrating information and communication technology with a lot of physical devices,” said Robert Parisi, New York-based managing director and cyber product leader for Marsh LLC.

“The initiatives are being implemented at difference paces nationally,” said Lisa Marsalis, San Antonio, Texas-based senior underwriting manager with OneBeacon Insurance Group’s government risk group.

“Usually, it’s a long process just to determine funding and the citizens’ appetite, and they usually start off with one or two initiatives” and become smart cities over time, she said.

Whatever the degree to which public entities become involved, smart cities are becoming increasingly popular, experts say. “Virtually every city that is interested in some kind of quality-of-life improvement for residents is looking into smart cities,” although “it doesn’t mean that all their efforts are in the right direction or are scalable and sustainable,” said Sokwoo Rhee, associate director for cyber physical system innovation at the Gaithersburg, Maryland-based National Institute of Standards and Technology.

One major factor facing smart cities is tight budgets, and the related challenge of attracting qualified personnel to aid them with their cyber security issues.

“It comes back to the fact that cities have budget constraints,” said Ronni Rausch, senior vice president with Arthur J. Gallagher & Co. in Boston. “Municipalities struggle to attract top IT talent because they’re competing with the private sector.”

Raimundo Rodulfo, director of information technology/chief information officer for Coral Gables, Florida, which has introduced smart city technology, said the city has recruited specialists to aid the transition. 

The city employs licensed engineers in multiple areas. “It wasn’t like that from the beginning,” he said. “We had to invest in our team.” 

“Capital planning for the IT structure is fairly new” among public entities, and, compared with other sectors such as financial institutions, has been a lower priority until recently, said Jeff Norton, Chicago-based senior vice president of technology and cyber for Brit Global Specialty USA, a unit of Brit Ltd.

Last year’s ransomware-related breaches in Baltimore and other cities “are raising a lot of attention to these needs, but it doesn’t just happen overnight. It takes time to plan for capital infrastructure and implement it,” Mr. Norton said. 

“Smart cities depend on the convergence of cyber and physical infrastructure,” which involves joining new systems to old, said Thom Rickert, Dallas-based vice president and head of marketing at Trident Public Risk Solutions, which is part of the Argo Group. “It naturally can create a gap in security and operational ability.” 

“Unless security is built into what they’re doing, this is going to be an issue with even bigger repercussions,” said Anthony Dagostino, New York-based global cyber and technology practice leader for Lockton Cos. LLC.

“These systems are public facing,” said Eric Friedberg, New York-based co-president of Aon PLC’s Cyber Solutions Group. “There’s tens of thousands, if not millions, of cyber front doors where attackers can sort of jiggle the knob and see if the door is open.”

Attackers, for instance, could take over all of a city’s parking meters, or manipulate smart meters to indicate there was no gas usage, Mr. Friedberg said.

Vendors are an issue as well. “Once you end up with hundreds, if not thousands, of dif  ferent vendors who are producing multiple products, it creates an enormous challenge from a process and personnel point of view to keep pace to make sure everything is patched and tested so it’s not vulnerable,” he said. 

Mr. Friedberg said mandatory low-bid procurements also pose an “enormous danger.” “You risk that the vendor is going to cut corners on its own internal security testing and its own internal insurance procurement,” he said.

Smart cities face variations of what they have always faced, but it is “just a little bit different,” Ms. Marsalis said. “They must continue to analyze exposures, and identify and implement risk management controls,” she said. 

Those who already have risk management practices in place are “not facing ground-shaking transformations,” although they are required to adopt new technology, retrain staff and add positions, she said.

“When they’re thinking about adding new technology to their environment, they all need to be asking themselves, ‘What could go wrong?’” and have “the right people in the room to answer that question,” said Aaron Aanenson, director, cyber security, with consulting firm S-RM Intelligence and Risk Consulting 2019 in New York.

 “Don’t implement these solutions faster than you can secure them,” Mr. Friedberg said, adding smart cities must ensure the devices they are using are periodically tested and capable of receiving security updates.

Smart cities need to develop contingency plans, making sure there are appropriate policies and procedures in place in the event of a breach, said Diane Barr, St. Paul, Minnesota-based global practice leader for public sector services at Travelers Cos. Inc.

They should also make sure employees are trained to conduct a proper risk assessment and understand the risk so they can put an appropriate solution in place, she said.

Megan Zanesky, director of risk management for the Town of Greenwich, Connecticut, which has introduced several computerized systems, said employee error, including the risk of clicking on the wrong email, is a “major concern.”

“The way we’re addressing that is by increasing awareness,” training workers on the importance of cyber security and how to use the systems properly, she said.

One approach is to have the public sector join with private companies and academia in working groups, Mr. Dagostino said. He added that he is optimistic about these initiatives’ success because “the cities today are more willing to listen to outsider reviews” than they were 12 to 24 months ago.

Vendor management is critical as well. Cities must have fundamentally sound contracts with their vendors and conduct appropriate due diligence concerning their products and the protections they have against perils, said Damian Caracciolo, Columbia, Maryland-based vice president with CBIZ Insurance Services Inc.

They must also make sure their vendors “have adequate cyber policies with appropriate limits,” Mr. Caracciolo said.