The Radio Equipment Directive which is applicable for most wireless equipment also in the fire and security industry looks to be prepared for an update where cyber security requirements will become part of the directive and with that part of the CE-marking. While Euralarm supports the need for increased cyber security, the fire and security industry will preferably support a horizontal cyber security regulation.

Nevertheless, if embedded in the RED, Euralarm wants to ensure that the technical aspects addressing cyber security are relevant for wireless fire safety and security equipment and can work for manufacturers and service providers.

Horizontal Cyber regulation

With incidents around privacy reported after updates from wireless equipment with official and unofficial software, the commission is urgently looking to enforce increased cyber security to protect consumers and to ensure that radio equipment manufacturers meet a level of cyber security before they release a product to the market.

These developments will impact companies that manufacture or market wireless Fire and Security equipment

Because Horizontal Cyber regulation is still under construction and can take some time before being completed, it looks like the EC plans to do this through an update of the RED. These developments will impact companies that manufacture or market wireless Fire and Security equipment.

Industrial Internet of Things

Following the Internet of Things (IoT) the industrial version of it, Industrial Internet of Things (IIoT) now also enters a phase of wider adaption and deployment around numerous industries. It is predicted that the worldwide IoT spending will surpass $ 1 trillion in 2022 (source: IDC). More and more products and industrial assets with electronics, software, sensors, and network connectivity enable us to collect and exchange data.

By connecting numerous devices and pieces of equipment through the Internet, (I)IoT can help businesses operate more efficiently, make more informed decisions and unlock new revenue sources. However, the devices themselves also introduce serious risks for business and society with every device being a potential source for cyber criminals to unauthorised enter home, business or industrial networks.

Radio Equipment Directive

Radio Equipment Directive is being considered for inclusion of cyber security requirements

This threat is caused by the radio communication function ‘on board’ these devices which enables them to communicate via wireless networks and by the possibility to wireless update software / firmware on these devices. Now that products are getting more and more connected, the European Commission is looking how to create a legislative framework to make these products better resistant against cyber attacks.

This could be done by including cyber security requirements into directives and regulations of the New Legislative Framework (NLF). This framework sets mandatory product safety requirements that are necessary to put products on the EU market (CE marking). The Radio Equipment Directive (RED) is the first Directive that is being considered for inclusion of cyber security requirements.

Low voltage equipment

The idea is to include the cyber security requirements through a delegated act on Internet connected and wearable radio equipment. Such an act is a legally binding act that enables the Commission to supplement or amend non‑essential parts of EU legislative acts, for example, to define detailed measures. Euralarm supports an increased level of cyber security and a better protection for the consumers.

And they are not alone. With the Cybersecurity Act in place the European Union Agency for Cybersecurity ENISA is now working on new certification schemes to cover a wider range of products, processes and services on all aspects of cyber security. Putting aside the EU Cybersecurity Act and pursuing the “RED path” would bring a clear risk of overlaps and inconsistencies across European legislations, not only for radio equipment, but also for instance for low voltage equipment (LVD), machines (MD) and medical devices (MDR).

Wearable radio-equipment

Meanwhile the European Commission initiated a public consultation on two essential requirements

It could result in legal uncertainty and significant impact in case of concurrent mandatory requirements and certification schemes. This would threaten European companies’ ability to compete across the Digital Single Market as well as globally, forcing them to misallocate scarce resources. Fearing a future patchwork of different legislations, the industry suggested a horizontal legislation for products.

Meanwhile the European Commission initiated a public consultation on two essential requirements. It concerns the safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected as well as certain features ensuring protection from fraud. This consultation laid down several proposals for the application of those 2 requirements to internet-connected radio-equipment and wearable radio-equipment.

Impact assessment study

Based on the results of this consultation, the Commission mandated a consultancy firm to conduct an impact assessment study. In his report, the contractor highlights that delegated acts are already mentioned in the RED and that they therefore should be preferred above legislation on cyber security which might take more time to develop. It is therefore unlikely that a horizontal cyber security related legislation on products can still be developed in a short-term.

The report adds that such a horizontal legislation could be considered at mid-term. Euralarm is presently supporting a proposal in this direction. The consultants also recommended that the European Standardisation Organisations should be mandated to pertain to the delegated acts. Both CEN-CENELEC and ETSI are now preparing themselves to get ready for this.

Cyber security requirements

Installing new software or firmware could have an impact on the compliance of the equipment

Euralarm recommends companies involved in the production of security equipment to stay informed on the development to ensure that the relevant technical aspects for fire safety and security equipment are embedded into the cyber security requirements.

Another RED related development that is taking place concerns the Reconfigurable Radio Systems, i.e. radio equipment that can be reconfigured by software (including firmware). Under some conditions, installing new software or firmware could have an impact on the compliance of the equipment.

Reconfigurable Radio Systems

The European Commission is therefore currently investigating this to ensure that the RED adequately addresses this issue and that reconfigurable radio systems for Europe's single market stay compliant with the Radio Equipment Directive after new or modified software is installed. The investigation is focused on the essential requirements of the RED itself: health and safety, EMC, efficient use of radio spectrum and requirements empowered by adopted delegated acts.

Software implemented functions that have no influence on the compliance to these requirements are not technically impacted but the need for demonstration of no-impact will appear. That means for instance that manufacturers of Wi-Fi connected smoke alarm devices would have to demonstrate that software updates do not impact RED compliance.

Euralarm has therefore advised manufacturers of wireless equipment falling under the RED to follow these developments. Euralarm will make sure that additional legislation that could result from the current investigation will be feasible for manufacturers.

Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Download PDF version

In case you missed it

What is the impact of lighting on video performance?
What is the impact of lighting on video performance?

Dark video images contain little or no information about the subject being surveilled. Absence of light can make it difficult to see a face, or to distinguish the color of clothing or of an automobile. Adding light to a scene is one solution, but there are also new technologies that empower modern video cameras to see better in any light. We asked this week’s Expert Panel Roundtable: what impact does lighting have on the performance of video systems?

Alarm.com adapts during pandemic to enable partners to ‘succeed remotely’
Alarm.com adapts during pandemic to enable partners to ‘succeed remotely’

As a cloud-based platform for service providers in the security, smart home and smart business markets, Alarm.com has adapted quickly to changing conditions during the coronavirus pandemic. In the recent dynamic environment, Alarm.com has kept focus on supporting their service provider partners so they can keep local communities protected. “We moved quickly to establish work-from-home protocols to protect our employees and minimise impact on our partners,” says Anne Ferguson, VP of Marketing at Alarm.com. The Customer Operations and Reseller Education (CORE) team has operated without interruption to provide support to partners. Sales teams are utilising webinars and training resources to inform and educate partners about the latest products, tools, and solutions. Alarm.com’s partner tools are essential for remote installations and support of partner accounts. Helping customers remain connected Adapting to challenges of the coronavirus pandemic, Alarm.com is further investing in solutions that help customers remain connected and engaged. The company has created a resource hub called “Succeeding Remotely” that provides tools, tips and news links that partners can use to adapt their business operations. From adjusting sales and installation techniques to maintaining cellular upgrades, Alarm.com is helping partners stay connected to customers remotely, keep their teams trained, and address rapidly evolving customer concerns without rolling trucks.The company has created a resource hub called “Succeeding Remotely “Additionally, after seeing all that our partners are doing to support their local communities in need, we were compelled to highlight those efforts with ongoing videos called Good Connections, which we’re sharing with our partner community to spark more ideas and ways to help,” says Ferguson. “Though our partners have experienced varying degrees of disruption to their business, we’re inspired by their adaptability, ingenuity and resilience,” says Ferguson. “Along with establishing proper safeguards for operating in homes and businesses, our partners are leveraging our support resources more heavily, while our entire staff has worked tirelessly to deliver new, timely resources.” Do-It-Together solutions Alarm.com partners are successfully employing Do-It-Together (DIT) solutions, focusing on 3G-to-LTE upgrades, and pivoting to new verticals like commercial and wellness. Many are also streamlining their business operations and taking advantage of virtual training opportunities to enhance their technicians’ skills and knowledge, says Ferguson. Do-It-Together installs involve depending on customers to perform part or all of the installation process. Partners can send customers fully configured kits with mounting instructions, or technicians may guide customers on a remote video call. Alarm.com’s tools, training and products help partners modify remote installation options depending on each customer’s needs. End users can validate the Alarm.com Smart Gateway with their central station that sensors they have mounted were done correctly using the Alarm.com mobile app Alarm.com Smart Gateway For example, the Alarm.com Smart Gateway can be pre-configured with indoor and outdoor cameras for easy customer installation and to reduce the likelihood of future service calls. Also, end users can validate with their central station that sensors they have mounted were done correctly using the Alarm.com mobile app. “DIT is helping our partners continue onboarding customers and avoid backlogs,” says Ferguson. “We’ve been pleasantly surprised by the resiliency and level of future investment that our residential and commercial partners have shown in the face of adversity,” adds Ferguson. For example, a significant number of business customers have used the slow period to install systems that are typically too disruptive to put in during normal business hours. Similarly, service providers are adopting new technologies or business models, such as cloud-based access control. “They’re often saying to us, ‘I’m going to take this opportunity to make changes to improve our business,’ and have been working closely with us on training and business consulting to support their efforts,“ she says. Shift to the cloud Ferguson sees a growing preference for cloud-managed surveillance and access systems over ones that have historically been run on-premise. The technology itself is attractive, but especially driving change is the enhancement to the daily lives of service providers and customers, which have been strained during this time. “The foundational benefit of our cloud-based solution is the hassle-free, seamless customer experience it delivers,” says Ferguson. “We make this possible by taking ownership of the servers, software maintenance, firmware updates, health monitoring, and more. With cloud technology, these aspects become invisible to the customer and take a lot off their plate, which is more important than ever.” End users can take advantage of Smart Tip video tutorials to help with DIT installations, or they can use the Alarm.com Wellcam to connect with loved ones anywhere.End users can take advantage of Smart Tip video tutorials to help with DIT installations Partners can attend training workshops focused on remote installation tactics, while driving consumer interest in new offerings through Alarm.com’s Customer Connections platform. The goal is to make it simple for partners to stay connected to their customers to maximise lifetime account value. “We are well-positioned to endure the pandemic because of the strength of our partners in their markets along with our investments in technology, hardware and our team,” says Ferguson. “As restrictions slowly lift, there is cautious optimism that the residential, commercial, property management, plumbing/HVAC, builder and other verticals will recover quickly. We believe that as more partners adopt the DIT model and add commercial and wellness RMR, they will find increasing opportunities to deploy security, automation, video, video analytics, access and more throughout their customer base.”

COVID-19 worries boost prospects of touchless biometric systems
COVID-19 worries boost prospects of touchless biometric systems

Spread of the novel coronavirus has jolted awareness of hygiene as it relates to touching surfaces such as keypads. No longer in favour are contact-based modalities including use of personal identification numbers (PINs) and keypads, and the shift has been sudden and long-term. Both customers and manufacturers were taken by surprise by this aspect of the virus’s impact and are therefore scrambling for solutions. Immediate impact of the change includes suspension of time and attendance systems that are touch-based. Some two-factor authentication systems are being downgraded to RFID-only, abandoning the keypad and/or biometric components that contributed to higher security, but are now unacceptable because they involve touching. Touchless biometric systems in demand The trend has translated into a sharp decline in purchase of touch modality and a sharp increase in the demand for touchless systems, says Alex Zarrabi, President of Touchless Biometrics Systems (TBS). Biometrics solutions are being affected unequally, depending on whether they involve touch sensing, he says. Spread of the novel coronavirus has jolted awareness of hygiene as it relates to touching surfaces such as keypads “Users do not want to touch anything anymore,” says Zarrabi. “From our company’s experience, we see it as a huge catalyst for touchless suppliers. We have projects being accelerated for touchless demand and have closed a number of large contracts very fast. I’m sure it’s true for anyone who is supplying touchless solutions.” Biometric systems are also seeing the addition of thermal sensors to measure body temperature in addition to the other sensors driving the system. Fingerscans and hybrid face systems TBS offers 2D and 3D systems, including both fingerscans and hybrid face/iris systems to provide touchless identification at access control points. Contactless and hygienic, the 2D Eye system is a hybrid system that combines the convenience of facial technology with the higher security of iris recognition. The system recognises the face and then detects the iris from the face image and zeros in to scan the iris. The user experiences the system as any other face recognition system. The facial aspect quickens the process, and the iris scan heightens accuracy. TBS also offers the 2D Eye Thermo system that combines face, iris and temperature measurement using a thermal sensor module. TBS's 2D Eye Thermo system combines face, iris and temperature measurement using a thermal sensor module Another TBS system is a 3D Touchless Fingerscan system that provides accuracy and tolerance, anti-spoofing, and is resilient to water, oil, dust and dirt. The 2D+ Multispectral for fingerprints combines 2D sensing with “multispectral” subsurface identification, which is resilient to contaminants and can read fingerprints that are oily, wet, dry or damaged – or even through a latex glove. In addition, the 3D+ system by TBS provides frictionless, no-contact readings even for people going through the system in a queue. The system fills the market gap for consent-based true on-the-fly systems, says Zarrabi. The system captures properties of the hand and has applications in the COVID environment, he says. The higher accuracy and security ratings are suitable for critical infrastructure applications, and there is no contact; the system is fully hygienic. Integration with access control systems Integration of TBS biometrics with a variety of third-party access control systems is easy. A “middleware” subsystem is connected to the network. Readers are connected to the subsystem and also to the corporate access control system. An interface with the TBS subsystem coordinates with the access control system. For example, a thermal camera used as part of the biometric reader can override the green light of the access control system if a high temperature (suggesting COVID-19 infection, for example) is detected. The enrollment process is convenient and flexible and can occur at an enrollment station or at an administration desk. Remote enrollment can also be accomplished using images from a CCTV camera. All templates are encrypted. Remotely enrolled employees can have access to any location they need within minutes. The 3D+ system by TBS provides frictionless, no-contact readings even for people going through the system in a queue Although there are other touchless technologies available, they cannot effectively replace biometrics, says Zarrabi. For example, a centrally managed system that uses a Bluetooth signal from a smart phone could provide convenience, is “touchless,” and could suffice for some sites. However, the system only confirms the presence and “identity” of a smart phone – not the person who should be carrying it. “There has been a lot of curiosity about touchless, but this change is strong, and there is fear of a possible second wave of COVID-19 or a return in two or three years,” says Zarrabi. “We really are seeing customers seriously shifting to touchless.”