The UK bans default guessable usernames and passwords for some IoT devices, to help avoid a situation like the 2016 Mirai botnet, the first country to do so
Seven years ago, a cyberattack left many of the most popular websites based in the United States inaccessible.
Context & Ripple Effects
The measure turns the UK’s earlier proposal for unique device passwords and disclosed update periods into a concrete baseline for part of the connected-device market. It addresses a long-running weakness illustrated by hardcoded default credentials in IoT equipment.
The policy is tied to the Mirai era, when compromised routers were used to disrupt internet access for more than a million customers in attacks affecting UK providers.
First-order effects
- Manufacturers of covered IoT devices can no longer rely on default credentials that are easily guessed, requiring changes to device setup and account provisioning.
- UK buyers of covered devices gain a basic protection against one of the simplest routes for mass device takeover.
Second-order effects
- Vendors selling across markets may standardize stronger credential practices rather than maintain a UK-specific configuration, increasing pressure on lagging IoT brands.
- Retailers, enterprise deployers, and support teams will need to account for more deliberate initial device setup instead of assuming shared defaults.
Third-order effects
- If other jurisdictions follow, baseline security requirements could become a market-access condition for IoT hardware, shifting accountability toward manufacturers rather than end users.
- The move reflects a broader transition from responding to botnet incidents after deployment to regulating insecure-by-default device design before sale; its reach will depend on which devices are covered and how compliance is enforced.
The trend: Governments are moving IoT cybersecurity from voluntary guidance toward product-level security rules that target repeatable, ecosystem-scale attack paths.