Our clients range from five-person start-ups to multinational product groups, in consumer IoT, industrial systems, energy and safety-critical products. The engagements below are described with their permission; names are withheld where confidentiality requires it.
CRA readinessConsumer IoT
Unlocking CRA compliance
- Challenge
- A leading consumer IoT manufacturer had to bring a wide portfolio into CRA compliance while penetration tests kept finding the same classes of defect late, when fixes are most expensive.
- Approach
- We integrated cyber security requirements and review gates into the existing development process, and trained 100 developers on secure design for their own products.
- Result
- 2 million products released on time, with security handled by the teams themselves.
Security-by-designTraining
“cetome supported us to achieve compliance by baking cyber security into our products.”
Product security strategyIndustrial IoT
Accelerating secure product release
- Challenge
- A multi-market industrial IoT manufacturer needed every product owner to define the right security requirements, without a security specialist available for each project.
- Approach
- We built a bespoke FAST tool that identifies the risks, derives the cyber security requirements and evaluates compliance automatically, and deployed it in the product teams.
- Result
- Product owners now integrate cyber security in their products with no prior knowledge, and the delivery of secure products is 30% faster.
Security-by-designProduct security governance
“With cetome, our teams are no longer afraid of cyber security. They now build it into every product from day one.”
RED & EN 18031 complianceEnergy management
Compliance in a short timeframe
- Challenge
- An energy management company was launching several connected products with RED cyber security applying, and no time to build the compliance capability first.
- Approach
- We delivered the cyber security risk assessments and the product documentation, and supported the engineers on the fixes, in step with the launch plan.
- Result
- RED compliance in two weeks per product, in time for the launches, with documentation the teams reuse for the next products.
Cyber security risk assessmentTechnical documentation
“cetome provided the tactical edge needed to synchronise our product roadmap with complex, evolving global regulations.”
Product security strategySafety-critical
Supporting the product strategy
- Challenge
- A safety company saw cyber security requirements appear in tenders and in new markets, and had no way to show buyers how its products met them.
- Approach
- We defined the product security strategy and showed how cyber security supports the product functionalities while reducing risks to end users, in the language of the tenders.
- Result
- Several tenders won and new markets entered: more than 20M€ of new business, with cyber resilience as a competitive advantage.
Product security governance
“cetome's expertise allowed us to turn cyber security into a market opener. With integrated cyber resilience, our products have a clear competitive advantage.”
CRA readinessConsumer IoT
Consolidated compliance budget
- Challenge
- A leading consumer IoT brand had a wide portfolio, a CRA deadline and no shared view of its exposure: engineering, compliance and the board each had their own picture, and no budget had been secured.
- Approach
- We assessed the portfolio and the processes against the Cyber Resilience Act, then turned the gaps into a plan the board could decide on: what to fund, in what order, and what happens if not.
- Result
- The board approved the new roles and a multi-year budget, and the products keep their access to the EU market for the next two years.
Gap analysisCompliance roadmap
CRA readinessIndustrial IoT
Vulnerability management before the deadline
- Challenge
- A global industrial IoT manufacturer had SBOMs but no process behind them: vulnerability matches piled up, nobody owned the triage, and the CRA reporting deadlines were months away.
- Approach
- We set up the vulnerability handling process from intake and triage to remediation and reporting, with the SBOM as its input, and automated the correlation between components and known vulnerabilities inside that process.
- Result
- Vulnerability triage over 2.5x faster, and a process the team runs itself, with owners and deadlines for each step.
Post-market requirementsSupport period definitionSecurity-by-design
CRA readinessIndustrial IoT
Secure factories, secure products
- Challenge
- A leading IoT manufacturer had to demonstrate that its products are produced securely, across complex manufacturing lines where provisioning and firmware flashing had never been assessed.
- Approach
- Over 16 weeks we executed an exhaustive threat model of the manufacturing lines, identified the risks in the provisioning and firmware flashing stages, and engineered the remediations with the plant teams.
- Result
- Production lines hardened against IP theft and unauthorised overproduction, with the evidence the CRA asks for on the production phase.
Threat model for manufacturing
Product security strategyIndustrial IoT
Secure product development lifecycle
- Challenge
- An industrial IoT manufacturer found most of its vulnerabilities at the final assessment, when every fix delayed the release and security depended on a handful of individuals.
- Approach
- We put security milestones and responsibilities into the existing development process, so that flaws are caught at design and build time by the engineers themselves.
- Result
- Ten times fewer vulnerabilities at the final assessment, and no more fixes delaying a release.
Product security governancePolicies and processesSupply chain managementResilient architecture
Product security strategyConsumer IoT
Unified vulnerability disclosure policy
- Challenge
- A consumer IoT group handled vulnerability reports differently in each brand and market, with no common public policy and no shared way to fix root causes.
- Approach
- We wrote one vulnerability disclosure policy for all the brands, published it, and aligned the product teams on how a report is handled from the day it arrives.
- Result
- One way of handling vulnerabilities across all brands and markets, and root causes fixed once instead of brand by brand.
Product security governancePolicies and processes
Product security strategyConsumer IoT
Governance dashboard for product security
- Challenge
- A multi-brand consumer IoT group could not answer a simple question from its leadership: where does each brand stand on product security and compliance, across devices, applications and cloud services.
- Approach
- We defined who is responsible for what, the few indicators that matter for the development lifecycle and for the obligations after release, and built a dashboard that shows them for every brand, across devices, applications and cloud.
- Result
- Leadership sees where each brand stands on product security and compliance, in one place, and the view survives changes in standards and technology.
Product security governanceSupply chain management
Product security strategyIndustrial IoT
Maturity posture improvement
- Challenge
- An industrial IoT manufacturer knew its product security was uneven but could not show its executives where, or make a case for the budget to fix it.
- Approach
- We measured the existing practices against our maturity model, site by site, and turned the gaps into a business case written for the executive committee.
- Result
- A roadmap backed by the numbers, executive approval, and a bigger budget to bring security to the whole portfolio.
Maturity level evaluation
RED & EN 18031 complianceIndustrial IoT
Compliance as a market catalyst
- Challenge
- An industrial IoT manufacturer had a fragmented product line and EU operators of critical infrastructure asking for RED cyber security compliance before they would buy.
- Approach
- We ran a pre-compliance check of the portfolio against our RED framework, then migrated the product line onto a unified secure-by-design architecture with a compliance roadmap for each product.
- Result
- Every product on one compliant architecture, and more than 10,000 units sold to EU critical infrastructure operators within 12 months.
Pre-compliance checkArchitecture engineeringCompliance roadmap
RED & EN 18031 complianceWearable IoT
CE compliance within 3 weeks
- Challenge
- A wearable product had a launch date, a notified body review ahead, and no EN 18031 technical documentation.
- Approach
- We drafted the EN 18031-1 and EN 18031-2 documentation (E.Info and E.DT) from the available material, working with the product team on the justifications the notified body would examine.
- Result
- RED compliance achieved and a CE certificate obtained from the notified body within three weeks.
Technical documentationLiaison with test lab
RED & EN 18031 complianceSmart metering
Building internal compliance velocity
- Challenge
- A smart metering manufacturer needed its first EN 18031-1 technical documentation within a month, and wanted its engineers to be able to do the next ones alone.
- Approach
- We wrote the documentation with the engineering teams: our specialist drafted, their engineers reviewed and corrected, and learned the structure along the way.
- Result
- Compliance within a month, and an engineering team able to self-assess the following products on its own.
Cyber security risk assessmentTechnical documentationLiaison with test lab
RED & EN 18031 complianceEV infrastructure
Transforming test failures into CE compliance
- Challenge
- An EV charging manufacturer failed critical points of the final assessment at the test lab, weeks before the planned release.
- Approach
- We sat between the manufacturer and the lab: we wrote the technical justifications for the design choices the lab had questioned, and fixed the points where a justification was not enough.
- Result
- A validated test report and CE certification on time, without moving the release date.
Liaison with test labCyber security risk assessment
TrainingConsumer IoT
Increasing global capabilities
- Challenge
- A global multi-brand consumer IoT organisation had teams in several countries with very different levels of product security knowledge, and no way to align them without micro-management.
- Approach
- We designed structured training paths per role, from awareness to specialist courses, aligned with the corporate objectives, and delivered them across the brands.
- Result
- Distributed teams with the same level of proficiency across brands, and a unified security posture maintained without micro-management.
Training pathsAwareness sessions
TrainingIndustrial IoT
Company-wide awareness packages
- Challenge
- An industrial group wanted every one of its 5,000 employees to recognise product security risks and follow the internal standards, without buying a licence per seat.
- Approach
- We built ready-made awareness packages covering the key challenges, the internal processes and the core requirements, and integrated them into the group’s existing training platform.
- Result
- Over 5,000 employees reached with zero licensing cost, and the internal standards followed as part of daily work.
Awareness sessions
TrainingConsumer IoT
Technical expertise on IoT standards
- Challenge
- A consumer IoT manufacturer’s product teams spent weeks interpreting EN 303 645 for each product, and still depended on outside help to apply it.
- Approach
- We delivered specialised training on the standard, focused on the practical application of its provisions, translating its language into engineering tasks on the teams’ own products.
- Result
- Product teams that implement the EN 303 645 provisions on their own, and far less time spent analysing the standard.
Deep-dive training
TrainingIndustrial IoT
Non-technical security governance
- Challenge
- In an industrial IoT manufacturer, marketing and product owners left every security decision to engineering, and each project stalled while the two sides worked out who decides what.
- Approach
- We delivered targeted deep-dive training for marketing and product owners on their own role in the security lifecycle, bridging business objectives and cyber security requirements.
- Result
- Clear role accountability across the product development process and faster development cycles.
Deep-dive training
Retained advisor
SBOM pilots for vulnerability management
- Challenge
- A manufacturer had SBOMs from several sources and no agreed way to use them: identifying whether a published vulnerability affected a product took five days on average.
- Approach
- Three pilot projects over six months, from the initial input to the deployment of the patch, in which we turned the inventory into a process: who receives the alert, who decides, who ships the fix, and how long each step may take.
- Result
- SBOMs in place across the pilots, and vulnerability identification shortened from five days to five hours on average.
Governance and implementationDecision support
Retained advisor
Support period strategy across the portfolio
- Challenge
- A manufacturer with more than 50 products had to determine the CRA support period of each, and its legal, compliance and product teams disagreed on what the regulation expected.
- Approach
- We identified with legal and compliance the parameters that determine the support period, and applied them product by product across the portfolio, with the budget consequences of each decision.
- Result
- A validated support period strategy and budget across more than 50 products, that the company can defend.
Portfolio oversightProposals and business cases
Retained advisor
PSIRT governance with the whole company
- Challenge
- A product security incident response team spent half its time coordinating customer support, quality, marketing and legal, none of whom knew their part when a vulnerability or an incident arrived.
- Approach
- We set up the incident management governance with the stakeholders outside security, defining each team’s role, its inputs and its deadlines, and briefed the leadership on the decisions that remain theirs.
- Result
- Every team knows its part, and the PSIRT workload is reduced by 50%, spent on security work rather than coordination.
Governance and implementationExecutive briefings
Retained advisor
Architecture review and supplier selection
- Challenge
- A manufacturer needed a new technical architecture delivered by outside suppliers, and had no security requirements to put in the request for proposals nor a way to compare the candidates on them.
- Approach
- We reviewed the architecture, identified the suppliers able to deliver it, wrote the request for proposals with the product team and carried the security requirements through every step of the selection.
- Result
- A supplier selected and signed within three months, meeting the security requirements before the contract.
Decision supportProposals and business cases
Product security strategyIndustrial IoT
FAST for IEC 62443 and EN 303 645
- Challenge
- A global IoT manufacturer had distributed product teams working across devices, applications and cloud services, each assessing risks its own way, and penetration tests catching the consequences late.
- Approach
- We developed a multi-asset, multi-standard FAST, covering IEC 62443 and EN 303 645, so that every team follows the same risk-based development process from the first design review.
- Result
- 150k€ saved in penetration tests over 18 months, with fewer findings reaching the final assessment.
FAST
Product security strategyConsumer IoT
Simplified risk assessment
- Challenge
- A leading consumer IoT manufacturer could not put a security specialist in every project, so risk assessments waited for one and slowed the roadmap.
- Approach
- We built a bespoke FAST: product teams answer a questionnaire, immediately identify the risks and the high-level requirements, and designate action owners and milestones in line with the governance.
- Result
- Product teams run their own risk assessments, with no security specialist in the room.
FAST
Product security strategyWearable IoT
FAST automation for compliance
- Challenge
- A wearable manufacturer validated product security and compliance by hand at the end of each release, too late and too slowly for its cadence.
- Approach
- We integrated the FAST results into the CI/CD system, so that automatic testing and reporting validate security and compliance at every build.
- Result
- Far fewer high-level risks reaching a release, and validation in minutes rather than days.
FAST
RED & EN 18031 complianceTest laboratory
FAST for RED compliance
- Challenge
- A test laboratory spent days per product working out the assets in scope, the applicable security mechanisms and the E.Info to collect before an EN 18031 assessment could start.
- Approach
- FAST identifies the assets in scope, the applicable security mechanisms and the relevant E.Info for RED cyber compliance, and highlights the tests and assessment units that apply.
- Result
- Product evaluation accelerated by several days per product.
FAST
No published story for this selection yet. Most of our engagements are confidential: ask us about our work in this area.
