CyOne Security AG
Zürich
Smart City comes to a halt: It is time to invest in IoT Security
- 07 August 2026
- 100%
- Permanent position
- Zürich
About the job
Cities are becoming smarter and more connected. This is fundamentally to be welcomed. The problem: The Smart City is taking shape so quickly that those responsible in administration and suppliers from industry are often focused on the corresponding functionalities. The necessary IoT security, however, is hardly addressed. As a result, the Smart City can quickly become a fiasco. Learn in the blog post why it is important to make a city not only smart but also secure.
The vision of the Smart City sounds enticing. Intelligent technologies are supposed to make our cities more livable. The clever networking of areas such as environment, energy and transport enables a more efficient use of urban infrastructure – so goes the promise of the Smart City. The population is to benefit on various levels: less congestion, no more searching for parking spaces, more efficient connections in public transport, better air quality, higher energy efficiency and more convenient services in administration.
Cities around the globe are enthusiastically embracing the implementation of this vision. Exemplary examples are Darmstadt, Barcelona or Amsterdam: The cities are already highly networked with sensors and intelligent data analysis increases the efficiency of urban infrastructure – from parking management to waste collection to the irrigation of green spaces. Also in Switzerland, the connected city is gradually taking shape: cities with developed Smart City strategies include Zurich, Basel and Winterthur. The latter even saw itself as a so-called "Living Lab" within the framework of the "Win.Lab" project, i.e. a real laboratory or test city in which social and technological innovations were tested and, ideally, scaled in the sense of sustainable urban development.
Cyber-attack on the Smart City
Cyber-attacks on Smart Cities have already clearly demonstrated the damage potential of connected technologies in the past: In 2017, hackers triggered a false alarm on over 150 sirens in Dallas, causing fear and panic among the population. In 2018, the city IT system of Atlanta was infected with malware, leading to outages in city administration. In 2021, hackers manipulated the drinking water supply of a city in Florida.
In many cases, smart traffic lights and street lamps are installed without considering the possible damage potential of the technology and the effects of possible manipulation by cyber criminals. Carelessly, urban water sprinkler systems in gardens, soil moisture meters, temperature sensors are networked with urban water storage plants, which are supposed to ensure optimal irrigation based on weather forecasts. A possible impact on the drinking water supply of the population through a takeover of the storage plant by cyber criminals is often not a topic.
Do not neglect IoT Security
In the euphoria about the enormous potential of networking, in most cities only the topic of "protection of personal data" is given some importance. The actual risks of this networking of people, organisations and infrastructure are forgotten in the vast majority of cases. Our IoT security experts agree: IoT security is grossly neglected by most Smart Cities. Although the cities test the systems for their functionality, other factors such as performance or weather resistance are then the focus. The potential vulnerability due to possible cyber-attacks as a result of networking various infrastructures is still far too little in the foreground today. Most city administrations as well as providers of smart solutions lack the expertise in dealing with IoT security.
Learn more about our specific IoT Security Services here→
"Security by Design" for a secure Smart City
Manufacturers of intelligent products and systems for the Smart City should therefore give the highest priority to data and device security – and from the very beginning. When security is considered from the product idea to the decommissioning of IoT devices according to the principle of "Security by Design", system security increases without massively increasing the cost of individual components. For example, a secure update mechanism serves to ensure the integrity, i.e. the immutability of the loaded software.
Manufacturers have the choice whether they want to build up the specific security expertise themselves or obtain the know-how from a specialised partner. Those who only deal with security issues on the sidelines will have to invest a lot to develop these skills in-house. This also costs valuable time, which can delay market readiness and product launch.
IoT Security – Make or Buy? Is it worth building explicit IoT and Product Cyber Security expertise in-house or is it advisable to purchase it project-specifically? Our decision checklists help you with the decision-making.