Regulatory Context
- James W.
- 3 days ago
- 1 min read

LinkedIn Post 13: Regulatory Context
The UK PSTI Act became enforceable in April 2024.
The Information Commissioner's Office (ICO) has published baseline security requirements for IoT devices:
Secure by default installation
User-changeable default passwords
Vulnerability disclosure mechanisms
Security update mechanisms
Enforcement has begun. The ICO is monitoring compliance and taking action against non-compliant distributors.
Your building IoT devices are in scope. Your FM company is the distributor. The liability is yours.
Don't wait for a regulatory letter to start thinking about compliance.
The companies that implement governance now will be the ones that avoid enforcement action later.

Comments