272
Copyright © 2019, IGI Global. Copying or distributing in print or electronic forms without written permission of IGI Global is prohibited.
Chapter 12
DOI: 10.4018/978-1-5225-7332-6.ch012
ABSTRACT
Our societal infrastructure is transforming into a connected cyber-physical system of systems, providing
numerous opportunities and new capabilities, yet also posing new and reinforced risks that require ex-
plicit consideration. This chapter addresses risks specifically related to cyber-security. One contributing
factor, often neglected, is the level of security education of the users. Another factor, often overlooked,
concerns security-awareness of the engineers developing cyber-physical systems. Authors present results
of interviews with developers and surveys showing that increase in security-awareness and understand-
ing of security risks, evaluated as low, are the first steps to mitigate the risks. Authors also conducted
practical evaluation investigating system connectivity and vulnerabilities in complex multi-step attack
scenarios. This chapter advocates that security awareness of users and developers is the foundation
to deployment of interconnected system of systems, and provides recommendations for steps forward
highlighting the roles of people, organizations and authorities.
INTRODUCTION
Joe
1
was driving a long-hauler on his way to Michigan. Suddenly, the truck electronics started acting
crazy showing speeds above 90 mph, lots of failures on the display, beeping all over. He pulls off the
truck onto the sideway. That day most of the trucks stopped all over the country, not possible to fix or
repair on a short notice... This led to goods not being delivered, with empty supermarkets, empty gas
stations, stopped production plants, and other economically negative consequences. What was the reason
for these events? A good friend recommended installing a great app for fuel consumption monitoring.
Security Awareness in the
Internet of Everything
Viacheslav Izosimov
Semcon Sweden AB, Sweden
Martin Törngren
https://orcid.org/0000-0002-4300-885X
KTH Royal Institute of Technology, Sweden