<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Red Alert Labs, Author at IoTAC</title>
	<atom:link href="https://iotac.eu/author/annamarton26gmail-com/feed/" rel="self" type="application/rss+xml" />
	<link>https://iotac.eu/author/annamarton26gmail-com/</link>
	<description>Internet of Things Access Control</description>
	<lastBuildDate>Thu, 09 Mar 2023 16:55:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.2.9</generator>

<image>
	<url>https://iotac.eu/wp-content/uploads/2020/11/cropped-favicon-32x32.jpg</url>
	<title>Red Alert Labs, Author at IoTAC</title>
	<link>https://iotac.eu/author/annamarton26gmail-com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Top 8 Things You Should Know About the EU Cyber Resilience Act (CRA)</title>
		<link>https://iotac.eu/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra/</link>
					<comments>https://iotac.eu/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra/#respond</comments>
		
		<dc:creator><![CDATA[Red Alert Labs]]></dc:creator>
		<pubDate>Thu, 09 Mar 2023 08:47:38 +0000</pubDate>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[IoT architecture]]></category>
		<category><![CDATA[IoT security]]></category>
		<category><![CDATA[security by design]]></category>
		<guid isPermaLink="false">https://iotac.eu/?p=11769</guid>

					<description><![CDATA[<p>The post <a href="https://iotac.eu/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra/">Top 8 Things You Should Know About the EU Cyber Resilience Act (CRA)</a> appeared first on <a href="https://iotac.eu">IoTAC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69f3b8d708367"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row top-level standard_section "  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-overlay="false"><div class="inner-wrap"><div class="row-bg"  style=""></div></div><div class="row-bg-overlay" ></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone "  data-t-w-inherits="default" data-bg-cover="" data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-hover-bg="" data-hover-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" ><div class="column-bg-overlay-wrap" data-bg-animation="none"><div class="column-bg-overlay"></div></div>
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<div class="wpb_wrapper">
		<p>More and more successful cyberattacks are targeting hardware and software products, leading to an estimated global annual cost of cybercrime of EUR 5.5 trillion by 2021 according to the EU commission. This is due mainly, on one side, to the lack of appropriate security in such products who often go to market including inherent vulnerabilities and on the other side, to the lack of awareness of the consumers or enterprises adopting those products due to an insufficient transparency of the manufacturers when it comes expressing their level of security.</p>
<p>This is why, on September 15, 2022, the <a style="font-weight: inherit;" href="https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act" data-type="web">European Commission</a> published the EU Cyber Resilience Act (CRA) regulation proposal necessary to increase the level of trust among users and the attractiveness of EU products with digital elements while providing legal certainty.</p>
<p>The regulation is very exhaustive, and we would recommend you to go through it in details. In the meantime, here are the top 8 things you should know about the EU Cyber Resilience Act that we just picked for you&#8230;</p>
<p>&nbsp;</p>
<p><strong>1- Am I concerned?</strong></p>
<p>Yes, if you are a manufacturer, importer or distributor of connected products (Hardware/Software) with digital elements (e.g. smart sensors, smart cameras, mobile devices, network devices, etc.). All market sectors are concerned in a horizontal way except sectors where some other EU regulations already applies such as in the medical, civil aviation, motor vehicles domains. Note that this can consist also of non-embedded software (software that can be made available without hardware). For instance services such as SaaS applications are not<br />
within the scope of this regulation unless these are used to remote processing the product at a distance which is under the responsibility of the product manufacturer and the absence of which would prevent such product from performing one of its functions. Finally, Free and<br />
open-source software supplied outside of a commercial activity should not be covered by this regulation.</p>
<p>&nbsp;</p>
<p><strong>2- What are my obligations?</strong></p>
<p>One of the main goals of the CRA is to cover the entire lifecycle of digital products. So your first obligation would be to insure that a list of essential cybersecurity requirements and harmonized rules have been considered at all stages including the design phase, delivery,<br />
actual product use, maintenance decommission, and disposal. Security by design, security by default, the security of the supply chain and vulnerability handling will be the main domains to be addressed. Secondly you need to conduct and document a security risk assessment and<br />
provide user guidance. You must report actively exploited vulnerabilities and provide security updates for at least five years. If you know or have reason to believe that the product or the processes put in place by the manufacturer are not in conformity with the CRA essential requirements, you shall immediately take the corrective measures necessary, to withdraw or to recall the product as appropriate and notify ENISA within 24 hours.</p>
<p>&nbsp;</p>
<p><strong>3- How should I demonstrate conformity?</strong></p>
<p>Most common families of digital products belong to non-critical risk category requiring a conformity self-assessment that should be carried out under your responsibility. Some other products considered belonging to higher risk categories will be qualified critical (Class I) and might require additional assurance requirements to be satisfied by applying harmonised standards or the EU cybersecurity certification schemes such as the EUCC or the EUCS and that could be under your responsibility or through a third-party CAB. Some other highly critical (Class II) products should always involve a third-party CAB. Finally, certified products according to the EU cybersecurity certification schemes such as the EUCC developed under the CSA are supposed to satisfy by default the EU Cyber Resilience Act requirements and can provide a presumption of conformity.</p>
<p>&nbsp;</p>
<p><strong>4- How does it relate to other EU policies?</strong></p>
<p>The CRA complements the existing Directive on the security of Network and Information Systems (NIS2) and the existing EU Cybersecurity Act (EU CSA). It is also based on the New Legislative Framework (NLF) for industrial products, which aims to improve market surveillance and the quality of conformity assessments. It is expected to satisfy the Radio Equipment Directive (RED) cybersecurity-related requirements. This means that RED-related harmonised cybersecurity standards (under development) will most probably serve as basis for the EU CRA essential requirements.</p>
<p>&nbsp;</p>
<p><strong>5- What are the potential Costs vs Benefits?</strong></p>
<p>It is estimated that any compliance costs for businesses would be outweighed by the benefits brought by a higher level of security of products, by preventing divergent security requirements and an increase of trust of users and market adoption. It also increases positive competitiveness and quality standards by levelling the playing field. It would reduce the number of incidents, incident handling costs and reputational damage. For the EU this means roughly 180 to 290 billion Euros of consequence costs could be avoided. Finally, non-compliance with the CRA essential cybersecurity requirements and all relevant obligations shall be subject to fines of up to 15 000 000 EUR or, if the offender is an undertaking, up to 2.5 % of its total annual turnover for the preceding financial year, whichever is higher.</p>
<p>&nbsp;</p>
<p><strong>6- By when it will be applicable?</strong></p>
<p>The proposal will now pass to the European Parliament and Council that will form their own positions before coming together for the trialogue negotiations in Q3/Q4 2023. So in order for all stakeholders (manufacturers, distributors, importers, CABs, Member States, ENISA, etc.) to adapt to the new requirements, the proposed CRA regulation will become applicable 24 months (at the latest by Q1 2026) after its entry into force, except for the reporting obligation on the manufacturer, which would apply from 12 months (most probably by Q1 2025) after the date of entry into force.</p>
<p>&nbsp;</p>
<p><strong>7- How could I recognize a conformant product?</strong></p>
<p>I&#8217;m sure you&#8217;re all familiar with CE marking which you could find on all products circulating in the EU. This same mark will indicate the conformity of all products with digital elements with this regulation. Only beta releases for testing purposes could be issued without that mark as long as these are time limited to testing purposes. Most importantly, importers of products with digital elements must ensure in addition to checking on the CE marking that the appropriate assessment procedures have been carried out by the manufacturer depending on the risk assessment and that the manufacturer has created all required technical documentation.</p>
<p>&nbsp;</p>
<p><strong>8- Yes, you could appoint an authorized representative</strong></p>
<p>Indeed, as a manufacturer you could mandate an external authorised representative who could discharge you from the EU declaration of conformity management and for market surveillance purposes.</p>
<p>Finally, it&#8217;s not too early to start planning accordingly, adapt your digital product strategy and chose the right specialized partners to avoid missing the EU single market access opportunity.</p>
<p>&nbsp;</p>
<p>This guest blog is published with the kind permission of <a href="https://www.redalertlabs.com/">Red Alerts Lab</a> and originally appeared <a href="https://www.redalertlabs.com/blog/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra">here</a>.</p>
<p>If you want to learn more about the CRA and its impact, join our Roundtable  on 17. April, where you can listen to the position of the European Commission, the US NIST, standardization organizations, and industry. For agenda and registration, please go to <a href="https://iotac.eu/iot-day-roundtable-2023/">https://iotac.eu/iot-day-roundtable-2023/</a>!</p>
	</div>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://iotac.eu/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra/">Top 8 Things You Should Know About the EU Cyber Resilience Act (CRA)</a> appeared first on <a href="https://iotac.eu">IoTAC</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://iotac.eu/top-8-things-you-should-know-about-the-eu-cyber-resilience-act-cra/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Top 5 Cybersecurity Challenges Facing IoT Device Manufacturers</title>
		<link>https://iotac.eu/top-5-cybersecurity-challenges-facing-iot-device-manufacturers/</link>
					<comments>https://iotac.eu/top-5-cybersecurity-challenges-facing-iot-device-manufacturers/#respond</comments>
		
		<dc:creator><![CDATA[Red Alert Labs]]></dc:creator>
		<pubDate>Fri, 21 Oct 2022 13:47:51 +0000</pubDate>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[IoT architecture]]></category>
		<category><![CDATA[IoT security]]></category>
		<category><![CDATA[security by design]]></category>
		<guid isPermaLink="false">https://iotac.eu/?p=10555</guid>

					<description><![CDATA[<p>The post <a href="https://iotac.eu/top-5-cybersecurity-challenges-facing-iot-device-manufacturers/">Top 5 Cybersecurity Challenges Facing IoT Device Manufacturers</a> appeared first on <a href="https://iotac.eu">IoTAC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69f3b8d709b41"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row standard_section "  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-overlay="false"><div class="inner-wrap"><div class="row-bg"  style=""></div></div><div class="row-bg-overlay" ></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone "  data-t-w-inherits="default" data-bg-cover="" data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-hover-bg="" data-hover-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" ><div class="column-bg-overlay-wrap" data-bg-animation="none"><div class="column-bg-overlay"></div></div>
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<div class="wpb_wrapper">
		<p>Consumers have been concerned about the security of IoT devices for some time, placing much pressure on manufacturers to demonstrate that their products are secure and trustworthy. As a device manufacturer, it’s important to recognize the challenges you’ll face as you aim to gain consumer confidence in your product. Here are the top 5 cybersecurity challenges facing IoT device managers:<span style="font-size: 16px;">                                     </span></p>
<p><strong>1. Misconfiguration issues</strong></p>
<p>According to a <a style="font-weight: inherit;" href="https://www2.deloitte.com/content/dam/Deloitte/in/Documents/technology-media-telecommunications/in-tmt-IoT_Theriseoftheconnectedworld-28aug-noexp.pdf" data-type="">whitepaper by Deloitte</a>, 70% of IoT devices are configured to use factory-set usernames and passwords. Many users never change the default credentials, which cybercriminals are quick to take advantage of. When manufacturing your product, it becomes your responsibility to prevent weak authentication and provide secure default configuration settings for the operating system. Look into <a style="font-weight: inherit;" href="https://www.redalertlabs.com/blog/top-10-things-you-should-know-about-fido-device-onboarding-fdo" data-type="">FIDO Device Onboard (FDO)</a> technology, which is a device onboarding protocol developed by the <a style="font-weight: inherit;" href="https://fidoalliance.org/" data-type="">FIDO Alliance</a>. It is an automatic onboarding mechanism for IoT devices, meaning it is invoked autonomously and performs only limited, specific interactions with its environment to complete.</p>
<p><strong>2. Lack of control once it’s in the hands of the end-user</strong></p>
<p>It doesn’t matter how secure you’ve developed your product to be if the end-user ends up configuring it incorrectly, making it vulnerable to attacks. It may feel that this is no fault of yours that consumers ignore your directions and warnings about the consequences of improperly configuring your devices. However, any attacks involving your devices consequently damage your reputation. You may be able to address these issues by investing in services that ensure end-users properly configure their devices on-site.</p>
<p><strong>3. Toolsets to verify product security</strong></p>
<p>While there are many emerging IoT technologies being introduced into the market, toolsets for secure embedded development are rare, and the ones that do exist are limited. Manufacturers find themselves burdened by the responsibility to develop their own tools for validating the security of their products. And this may require hiring an in-house development team or partnering with a third-party vendor, which may involve stretching out your budget more than expected. Take a look at innovative and trending product cybersecurity assessment tools such as <a style="font-weight: inherit;" href="https://www.cyber-pass.eu/" data-type="">CyberPass</a>.</p>
<p><strong>4. Complexities of having multiple suppliers for hardware and software</strong></p>
<p>The more third parties that are introduced into your process, the higher the risks for threats and vulnerabilities. After all, a software supplier may have different processes compared to your hardware vendor. Because you don’t have control over the security processes of these channels, it becomes your responsibility to assess and minimize any potential risks and security issues they may introduce into your development process. You can lessen the risk of passing security threats to your customers by identifying vulnerabilities across the various channels of your supply chain.</p>
<p><strong>5. Late-development vulnerabilities and threats</strong></p>
<p>Sophisticated threats can enter in the final stages of the development process, making vulnerability management crucial. A good vulnerability management system proactively mitigates the potential for vulnerabilities rather than managing attacks after they’ve happened. To ensure all device components are secure, you should keep an eye for potential vulnerabilities, write and release constant updates and patches, and prepare for more advanced attacks.</p>
<p>Finally, to be cyber resilient, IoT manufacturers need to spend more time on security measures in the product development stage supported by domain specialists when necessary. Connected products that come with reliable protection and detailed monitoring infrastructure are well-placed to meet these security challenges and provide trust to the market.</p>
<p>This guest blog is published with the kind permission of Red Alerts Lab and originally appeared <a href="https://www.redalertlabs.com/blog/top-5-cybersecurity-challenges-facing-iot-device-manufacturers">here</a>.</p>
	</div>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://iotac.eu/top-5-cybersecurity-challenges-facing-iot-device-manufacturers/">Top 5 Cybersecurity Challenges Facing IoT Device Manufacturers</a> appeared first on <a href="https://iotac.eu">IoTAC</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://iotac.eu/top-5-cybersecurity-challenges-facing-iot-device-manufacturers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
