Sarah Lyons of the National Cyber Security Centre said companies that make the products needed to take responsibility.
“Businesses have a critical role to play in protecting the public by ensuring the smart products they manufacture, import and distribute remain secured against cyberattacks, and this landmark legislation will help consumers make informed decisions about the safety of the products they buy,” she said.
Ken Munro, a security researcher at Pentest Partners, a company that specializes in ethical hacking of smart devices, called the new law “a step in the right direction.”
“It has teeth, and I like that about it,” he said.
He said that in the past it was too easy for manufacturers to drop support for older products when releasing new models, so it would be useful for consumers to compare how many years of support they were promised for the products they bought.
The long support period shows that manufacturers generally take cybersecurity seriously, he said.
“I suspect some device makers at the bottom of the market will just pay lip service and do the bare minimum to ensure their products are safe,” he said.
Rocio Concha, policy and advocacy director at consumer group Witch?, said the new law would give consumers “important protections.”
But the Product Safety and Standards Agency should be prepared to “take strong enforcement action when manufacturers flout the law,” he added.
