The Smart City Security Imperative: Lessons from New York's IoT Cyber Defense Program
Key Highlights
- Urban centers are vital to national prosperity but face increasing threats from physical and cyber attacks targeting infrastructure and IoT devices.
- NYC Cyber Command developed a ground-up cybersecurity program to inventory, monitor, and secure IoT and smart building systems across the city, overcoming legal and cultural barriers.
- Municipalities must adopt comprehensive strategies that include risk assessments, standardized procurement, and automated device inventories to safeguard against cyber-physical threats.
- Advanced mobile endpoints like autonomous maritime vessels introduce new security challenges, requiring specialized protections such as data encryption and tamper-resistant sensors.
- Despite existing federal and state guidelines, many cities lack coordinated efforts and sufficient budgets to implement effective IoT cybersecurity measures, leaving critical infrastructure vulnerable.
The top 30 cities in America are home to approximately 60 million people. American cities are the backbone of our nation’s prosperity, economic stability, cultural diversity and public safety. However, our cities remain highly vulnerable to multiple threats, including, but not limited to, physical attacks on key municipal infrastructure; geomagnetic storms (GMDs); electromagnetic pulses (EMPs) from high-altitude nuclear detonations; suitcase nukes; locally generated pulses from high-powered microwave weapons; and cyberattacks, both domestic and foreign. This article focuses on the strategy and program implemented by the City of New York Cyber Command to secure the world’s largest footprint of endpoint technology (Internet of Things – IoT) and smart building automation systems.
The City of New York faced a massive problem: City Agencies were deploying unvetted IoT Endpoint Technology and connecting it to New York City networks and critical infrastructure, exponentially increasing the threat landscape. Coupled with the unknown fact that NYC had no idea how many IoT devices had been deployed across the five Boroughs. The problem seemed to be endless and enormous. These internet-connected devices and systems significantly increased the City’s exposure to cybersecurity risks. NYC needed to effectively address these risks and their potential catastrophic cascading effects, which could leave NYC without government services, transportation, communications, power, and much more, placing our largest city and its residents in grave danger with potential existential consequences.
Big Apple Challenges
It is New York City; is there much more to say? Large-scale programs for securing IoT and Smart Building Automation Systems did not exist, especially at the municipal level. The challenges were not only at the technology level but also at the City Agency cultural level. The program would be new to the City; an entire cyber infrastructure would need to be built around securing Endpoint Technology, with many city agencies believing that a program to secure IoT would be a roadblock to their rapid deployment of technology.
Other big challenges were:
- Inconsistent legal agreements for the purchasing of technologies – almost every City agency had its own legal technology purchasing agreements/contracts/licensing.
- Having a ‘catch mechanism’ in the procurement of new and existing IoT
- technology.
- Educating agencies on what exactly is IoT; many did not know.
- The Great Unknown – the existing IoT footprint:
- What exactly is out there now, how many and is it being supported contractually (legally)?
- How to inventory existing IoT footprint.
- How to capture existing technologies and bring them into the process.
- How to automate the monitoring and upgrades of IoT networks, especially as autonomous mobile infrastructure joins the municipal grid.
- While the U.S. Federal Trade Commission and NIST have issued certain guidelines and policies for IoT cybersecurity best practices, there are no universal standards regarding the cybersecurity of IoT devices. A budget of only $150,000.00!
Municipalities must fully understand both the operational gains and the severe cyber-physical risks associated with this tier of advanced mobile Endpoint Technology before deployment.
Landscape
Our cities depend on endpoint technology, from a police officer’s mobile communications device to critical sensors placed throughout cities to detect dangerous gases, radiation, temperature, and water levels. This increase includes highly advanced, mobile cyber-physical endpoints, such as the autonomous maritime vessels and hydrographic survey platforms developed by Mythos AI.
Integrating Mythos AI platforms into municipal port, harbor, and waterway infrastructure introduces major efficiency and safety benefits. Their autonomous maritime navigation systems enable continuous, real-time hydrographic mapping, automated shallow-water surveys, and self-docking logistics. This drastically reduces human error, optimizes transit routing, minimizes fuel consumption, and improves overall port safety.
However, because these vessels operate as mobile, internet-connected endpoints, they pose complex, unique security concerns that go far beyond those of standard stationary IoT devices. From a technical security perspective, autonomous vessels rely on a complex ecosystem of sensor fusion (combining LiDAR, Radar, and cameras), GPS/GNSS telemetry, Automatic Identification System (AIS) data, and internal Controller Area Network (CAN) buses. If an adversary successfully executes an AIS spoofing attack, corrupts sensor data feeds, intercepts the satellite telemetry, or exploits wireless over-the-air (OTA) software updates, the vessel's autonomous navigation logic could be compromised. An attacker could blind the vessel, feed it ghost obstacles, reroute it off-course, or worse, hijack its propulsion systems to turn the vessel into a kinetic weapon capable of physically ramming critical infrastructure, blocking major shipping lanes, or causing catastrophic environmental spills in busy waterways.
Municipalities must fully understand both the operational gains and the severe cyber-physical risks associated with this tier of advanced mobile Endpoint Technology before deployment. Without properly securing IoT device systems, infiltration through one device can have rapid, catastrophic consequences, bringing a large city to its knees (Baltimore, Atlanta).
The weaknesses of IoT devices and their management systems are well documented and have been recognized for years, with various organizations taking different approaches by publishing basic security requirements to protect municipal infrastructure, networks, and systems from threats. On the federal level, the bipartisan Internet of Things Cybersecurity Improvement Act of 2020 was signed into law and at the state level, the California Civil Code on Security of Connected Devices was passed into law in 2018 which requires manufacturers of IoT devices sold or offered for sale in the state, to; “equip the device with a reasonable security feature or features...designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure...”
Unfortunately, these efforts, requirements and directives have not had the desired effects. Actions, when taken, were unsynchronized, uncoordinated, stove-piped, and, for the most part, ignored by municipalities because of budgetary constraints and the difficulty of finding the talent needed to implement these programs. Many of our adversaries are very aware of the weaknesses of IoT solutions and have demonstrated the capability and willingness to attack our city governments, grid, water systems, communication systems, etc. As documented by previous successful municipal cyber and ransomware exploits, these breaches have cost cities across America hundreds of billions of dollars, and their long-term effects are having catastrophic consequences for city services.
Recommendation
City governments around America are investing billions of dollars in innovative new technologies to improve government services. When implementing IoT devices and advanced autonomous systems, such as Mythos AI, as part of this digital transformation, municipalities must understand the security risks and vulnerabilities inherent in these technologies.
American cities should include plans in their budgets to implement programs to secure their IoT, maritime endpoints, and building automation systems before deployment. At a minimum, each city should have a citywide strategy outlining how it can adopt IoT technologies equitably and safely. The guide must provide:
- An assessment of the city’s current IoT environment and how it will examine cybersecurity vulnerabilities of its deployment of IoT, explicitly accounting for autonomous vehicular, drone, and maritime systems.
- Policies, standards, and the created processes to review and test devices and networks that city agencies procure, ensuring that appropriate cybersecurity protocols are in place. For autonomous systems, this must include vetting of zero-trust communication architectures, data encryption for telemetry, and tamper-resistant sensor validation systems.
- The guide should include recommendations for conducting an inventory of all the city’s IoT devices periodically. Ideally, this should be automated to track stationary and mobile maritime endpoints in real time.
- Establish a standard review process that all city agencies and offices must follow to consistently (contractually) purchase technology within the city and ensure IoT devices are safe and secure before deployment on city networks.
A program to proactively secure IoT will protect our cities against catastrophic cyber-attacks by not only catching “low-hanging fruit (vulnerabilities)” but programs like the one implemented in NYC can also have a cascading positive effect on existing network architectures by including a review of the existing network typology and further securing it downstream before connection to the IoT solutions.
If it can be implemented in NYC, it can be implemented in any American city. When I arrived at NYC Cyber Command, none of these programs existed. Each was developed from the ground up and brought to maturity. It is my mission now to share this expertise with other municipalities.
About the Author
Maria R. Sumnicht Maria R. Sumnicht
National Cybersecurity Director for Critical Infrastructure at the Task Force on National and Homeland Security
Maria R. Sumnicht is National Cybersecurity Director for Critical Infrastructure at the Task Force on National and Homeland Security, where she focuses on protecting America’s critical infrastructure from cyber, physical and emerging technology threats. She advises government agencies, infrastructure operators and industry leaders on cybersecurity, operational technology (OT), industrial control systems (ICS), IoT and converged cyber-physical environments. Sumnicht brings more than three decades of experience spanning cybersecurity, networking, physical security and critical infrastructure engineering. Her career includes leadership roles with New York City Cyber Command, Cisco Systems, SurveillanceGrid, Lockheed Martin and NASA Ames Research Center, where she participated in incident response during the 1988 Morris Worm attack.
