# What Can We Learn From the United Kingdom’s New Security Laws?

By Zach Werblo · Published 2019-08-14 · Updated 2026-07-23 · Industrial IoT on MarketScale
Canonical: https://www.marketscale.com/industries/industrial-iot/what-can-we-learn-from-the-united-kingdoms-new-security-laws

> The United Kingdom has announced plans to introduce new IoT laws aimed at boosting the security of connected devices. The law has three basic principles: Devices must have unique passwords that cannot be reset to a universal factory setting Manufacturers must provide a public point of contact as part of a ‘vulnerability disclosure policy’…

## Key points

- Devices must have unique passwords and cannot revert to a factory default.
- Manufacturers must provide a public contact for vulnerability disclosures.
- Devices should clearly state the duration for receiving security updates.

The United Kingdom has announced plans to introduce new IoT laws aimed at boosting the security of connected devices.

The law has three basic principles:

1. Devices must have unique passwords that cannot be reset to a universal factory setting
2. Manufacturers must provide a public point of contact as part of a ‘vulnerability disclosure policy’
3. Manufacturers must explicitly state the minimum length of time that a device will continue to receive security updates as part of an ‘end of life policy.’

This kind of regulation shows that governments are increasingly worried about the lack of firewalls or antivirus software in IoT devices.

This could be a first step towards establishing secure and standardized framework for further IoT development.

Tags: [object Object], [object Object], [object Object], [object Object], [object Object], [object Object]

---
Source: MarketScale, https://www.marketscale.com/industries/industrial-iot/what-can-we-learn-from-the-united-kingdoms-new-security-laws. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
