Skip to main content

Cybersecurity in smart cities

At the Allianz Smart City meetup in Dortmund, current projects were presented: a climate sensor network, smart waste management, digital pillars. Each of these systems collects data to run the city better, from air quality to bin collection. Ali Recai Yekta spoke about the cybersecurity of smart cities and how their digital resilience can be raised. Every sensor is a device on a network, and can be attacked.

Cybersecurity in smart cities, Ali Yekta, Yekta IT

A recent case shows what that means. In July 2026 it became known that a Russian military intelligence group, Fancy Bear, had been tapping private surveillance and doorbell cameras along NATO supply routes for years, to watch arms deliveries to Ukraine. Dutch intelligence services traced it. Access came through default passwords and outdated firmware. The owners noticed nothing, because the cameras kept working normally. That is what makes these attacks hard to find: the effects are not immediately visible.

The devices of a smart city are networked small computers, usually called IoT devices. Many ship with default passwords, rarely receive security updates and are reachable directly from the internet. Unprotected devices get taken over in large numbers and wired together into remotely controlled networks, botnets.

Then there is how long they stay in service. In the Netherlands, traffic lights could be switched remotely over a radio system. That system, KAR (Korteafstandsradio), has let emergency vehicles and buses turn junctions green since 2005. It was built before these threats existed and cannot be secured, which is why tens of thousands of installations have to be replaced by about 2030. Technology in public space stands for ten to fifteen years. Whether a device will get updates over that period therefore belongs in the procurement decision. From December 2027 the EU Cyber Resilience Act requires security updates over a defined support period of at least five years. For long-lived municipal technology that is a legal minimum which does not cover the actual service life.

Die Allianz Smart City Dortmund - YekCity

Some attacks are felt at once. At the end of December 2025 a coordinated attack hit more than 30 Polish wind and solar farms and a heating plant with around 500,000 heat customers. More common is the quiet damage. A city’s sensors yield movement profiles, through cameras, number plates and the radio signals of mobile phones. That data comes together on a central platform, where it is tempting for the operator too, for instance through a later extension of purpose. Data protection law sets limits here. Whoever collects little from the start loses little when something happens. Another possibility is false information. In Dallas in 2017, attackers set off all 156 emergency sirens at night. Display boards and digital pillars can be misused the same way if they are not properly protected.

For planning, that gives concrete priorities. Collect and connect only what has a purpose, change default passwords, and clarify before purchase whether a device will get updates over its service life. Just as important is the assumption that an attacker gets in without destroying anything. Quiet access of that kind is only found by someone who knows their infrastructure and watches it. That takes asset management, recording which devices exist and where they send data, and security monitoring that reports anomalies, for instance a camera that suddenly sends data to an unfamiliar address.

Ali Recai Yekta, Marco Gren and Mucahid Yekta demonstrated the effect on our YekCity platform. On a city model they ran attacks on the power supply through to a blackout, modelled on real incidents in Poland and Ukraine.

Questions about this?

Talk to our consultants.