Client work

Success stories: what our advisory work changed for our customers.

Our clients range from five-person start-ups to multinational product groups, in consumer IoT, industrial systems, energy and safety-critical products. The engagements below are described with their permission; names are withheld where confidentiality requires it.

Advisory
Sector

CRA readinessConsumer IoT

Unlocking CRA compliance

Challenge
A leading consumer IoT manufacturer had to bring a wide portfolio into CRA compliance while penetration tests kept finding the same classes of defect late, when fixes are most expensive.
Approach
We integrated cyber security requirements and review gates into the existing development process, and trained 100 developers on secure design for their own products.
Result
2 million products released on time, with security handled by the teams themselves.

Security-by-designTraining

“cetome supported us to achieve compliance by baking cyber security into our products.”

CISO, leading smart home manufacturer

Product security strategyIndustrial IoT

Accelerating secure product release

Challenge
A multi-market industrial IoT manufacturer needed every product owner to define the right security requirements, without a security specialist available for each project.
Approach
We built a bespoke FAST tool that identifies the risks, derives the cyber security requirements and evaluates compliance automatically, and deployed it in the product teams.
Result
Product owners now integrate cyber security in their products with no prior knowledge, and the delivery of secure products is 30% faster.

Security-by-designProduct security governance

“With cetome, our teams are no longer afraid of cyber security. They now build it into every product from day one.”

SVP of engineering, Industrial IoT manufacturer

RED & EN 18031 complianceEnergy management

Compliance in a short timeframe

Challenge
An energy management company was launching several connected products with RED cyber security applying, and no time to build the compliance capability first.
Approach
We delivered the cyber security risk assessments and the product documentation, and supported the engineers on the fixes, in step with the launch plan.
Result
RED compliance in two weeks per product, in time for the launches, with documentation the teams reuse for the next products.

Cyber security risk assessmentTechnical documentation

“cetome provided the tactical edge needed to synchronise our product roadmap with complex, evolving global regulations.”

VP of Products, energy management company

Product security strategySafety-critical

Supporting the product strategy

Challenge
A safety company saw cyber security requirements appear in tenders and in new markets, and had no way to show buyers how its products met them.
Approach
We defined the product security strategy and showed how cyber security supports the product functionalities while reducing risks to end users, in the language of the tenders.
Result
Several tenders won and new markets entered: more than 20M€ of new business, with cyber resilience as a competitive advantage.

Product security governance

“cetome's expertise allowed us to turn cyber security into a market opener. With integrated cyber resilience, our products have a clear competitive advantage.”

CEO, safety company

CRA readinessConsumer IoT

Consolidated compliance budget

Challenge
A leading consumer IoT brand had a wide portfolio, a CRA deadline and no shared view of its exposure: engineering, compliance and the board each had their own picture, and no budget had been secured.
Approach
We assessed the portfolio and the processes against the Cyber Resilience Act, then turned the gaps into a plan the board could decide on: what to fund, in what order, and what happens if not.
Result
The board approved the new roles and a multi-year budget, and the products keep their access to the EU market for the next two years.

Gap analysisCompliance roadmap

CRA readinessIndustrial IoT

Vulnerability management before the deadline

Challenge
A global industrial IoT manufacturer had SBOMs but no process behind them: vulnerability matches piled up, nobody owned the triage, and the CRA reporting deadlines were months away.
Approach
We set up the vulnerability handling process from intake and triage to remediation and reporting, with the SBOM as its input, and automated the correlation between components and known vulnerabilities inside that process.
Result
Vulnerability triage over 2.5x faster, and a process the team runs itself, with owners and deadlines for each step.

Post-market requirementsSupport period definitionSecurity-by-design

CRA readinessIndustrial IoT

Secure factories, secure products

Challenge
A leading IoT manufacturer had to demonstrate that its products are produced securely, across complex manufacturing lines where provisioning and firmware flashing had never been assessed.
Approach
Over 16 weeks we executed an exhaustive threat model of the manufacturing lines, identified the risks in the provisioning and firmware flashing stages, and engineered the remediations with the plant teams.
Result
Production lines hardened against IP theft and unauthorised overproduction, with the evidence the CRA asks for on the production phase.

Threat model for manufacturing

Product security strategyIndustrial IoT

Secure product development lifecycle

Challenge
An industrial IoT manufacturer found most of its vulnerabilities at the final assessment, when every fix delayed the release and security depended on a handful of individuals.
Approach
We put security milestones and responsibilities into the existing development process, so that flaws are caught at design and build time by the engineers themselves.
Result
Ten times fewer vulnerabilities at the final assessment, and no more fixes delaying a release.

Product security governancePolicies and processesSupply chain managementResilient architecture

Product security strategyConsumer IoT

Unified vulnerability disclosure policy

Challenge
A consumer IoT group handled vulnerability reports differently in each brand and market, with no common public policy and no shared way to fix root causes.
Approach
We wrote one vulnerability disclosure policy for all the brands, published it, and aligned the product teams on how a report is handled from the day it arrives.
Result
One way of handling vulnerabilities across all brands and markets, and root causes fixed once instead of brand by brand.

Product security governancePolicies and processes

Product security strategyConsumer IoT

Governance dashboard for product security

Challenge
A multi-brand consumer IoT group could not answer a simple question from its leadership: where does each brand stand on product security and compliance, across devices, applications and cloud services.
Approach
We defined who is responsible for what, the few indicators that matter for the development lifecycle and for the obligations after release, and built a dashboard that shows them for every brand, across devices, applications and cloud.
Result
Leadership sees where each brand stands on product security and compliance, in one place, and the view survives changes in standards and technology.

Product security governanceSupply chain management

Product security strategyIndustrial IoT

Maturity posture improvement

Challenge
An industrial IoT manufacturer knew its product security was uneven but could not show its executives where, or make a case for the budget to fix it.
Approach
We measured the existing practices against our maturity model, site by site, and turned the gaps into a business case written for the executive committee.
Result
A roadmap backed by the numbers, executive approval, and a bigger budget to bring security to the whole portfolio.

Maturity level evaluation

RED & EN 18031 complianceIndustrial IoT

Compliance as a market catalyst

Challenge
An industrial IoT manufacturer had a fragmented product line and EU operators of critical infrastructure asking for RED cyber security compliance before they would buy.
Approach
We ran a pre-compliance check of the portfolio against our RED framework, then migrated the product line onto a unified secure-by-design architecture with a compliance roadmap for each product.
Result
Every product on one compliant architecture, and more than 10,000 units sold to EU critical infrastructure operators within 12 months.

Pre-compliance checkArchitecture engineeringCompliance roadmap

RED & EN 18031 complianceWearable IoT

CE compliance within 3 weeks

Challenge
A wearable product had a launch date, a notified body review ahead, and no EN 18031 technical documentation.
Approach
We drafted the EN 18031-1 and EN 18031-2 documentation (E.Info and E.DT) from the available material, working with the product team on the justifications the notified body would examine.
Result
RED compliance achieved and a CE certificate obtained from the notified body within three weeks.

Technical documentationLiaison with test lab

RED & EN 18031 complianceSmart metering

Building internal compliance velocity

Challenge
A smart metering manufacturer needed its first EN 18031-1 technical documentation within a month, and wanted its engineers to be able to do the next ones alone.
Approach
We wrote the documentation with the engineering teams: our specialist drafted, their engineers reviewed and corrected, and learned the structure along the way.
Result
Compliance within a month, and an engineering team able to self-assess the following products on its own.

Cyber security risk assessmentTechnical documentationLiaison with test lab

RED & EN 18031 complianceEV infrastructure

Transforming test failures into CE compliance

Challenge
An EV charging manufacturer failed critical points of the final assessment at the test lab, weeks before the planned release.
Approach
We sat between the manufacturer and the lab: we wrote the technical justifications for the design choices the lab had questioned, and fixed the points where a justification was not enough.
Result
A validated test report and CE certification on time, without moving the release date.

Liaison with test labCyber security risk assessment

TrainingConsumer IoT

Increasing global capabilities

Challenge
A global multi-brand consumer IoT organisation had teams in several countries with very different levels of product security knowledge, and no way to align them without micro-management.
Approach
We designed structured training paths per role, from awareness to specialist courses, aligned with the corporate objectives, and delivered them across the brands.
Result
Distributed teams with the same level of proficiency across brands, and a unified security posture maintained without micro-management.

Training pathsAwareness sessions

TrainingIndustrial IoT

Company-wide awareness packages

Challenge
An industrial group wanted every one of its 5,000 employees to recognise product security risks and follow the internal standards, without buying a licence per seat.
Approach
We built ready-made awareness packages covering the key challenges, the internal processes and the core requirements, and integrated them into the group’s existing training platform.
Result
Over 5,000 employees reached with zero licensing cost, and the internal standards followed as part of daily work.

Awareness sessions

TrainingConsumer IoT

Technical expertise on IoT standards

Challenge
A consumer IoT manufacturer’s product teams spent weeks interpreting EN 303 645 for each product, and still depended on outside help to apply it.
Approach
We delivered specialised training on the standard, focused on the practical application of its provisions, translating its language into engineering tasks on the teams’ own products.
Result
Product teams that implement the EN 303 645 provisions on their own, and far less time spent analysing the standard.

Deep-dive training

TrainingIndustrial IoT

Non-technical security governance

Challenge
In an industrial IoT manufacturer, marketing and product owners left every security decision to engineering, and each project stalled while the two sides worked out who decides what.
Approach
We delivered targeted deep-dive training for marketing and product owners on their own role in the security lifecycle, bridging business objectives and cyber security requirements.
Result
Clear role accountability across the product development process and faster development cycles.

Deep-dive training

Retained advisor

SBOM pilots for vulnerability management

Challenge
A manufacturer had SBOMs from several sources and no agreed way to use them: identifying whether a published vulnerability affected a product took five days on average.
Approach
Three pilot projects over six months, from the initial input to the deployment of the patch, in which we turned the inventory into a process: who receives the alert, who decides, who ships the fix, and how long each step may take.
Result
SBOMs in place across the pilots, and vulnerability identification shortened from five days to five hours on average.

Governance and implementationDecision support

Retained advisor

Support period strategy across the portfolio

Challenge
A manufacturer with more than 50 products had to determine the CRA support period of each, and its legal, compliance and product teams disagreed on what the regulation expected.
Approach
We identified with legal and compliance the parameters that determine the support period, and applied them product by product across the portfolio, with the budget consequences of each decision.
Result
A validated support period strategy and budget across more than 50 products, that the company can defend.

Portfolio oversightProposals and business cases

Retained advisor

PSIRT governance with the whole company

Challenge
A product security incident response team spent half its time coordinating customer support, quality, marketing and legal, none of whom knew their part when a vulnerability or an incident arrived.
Approach
We set up the incident management governance with the stakeholders outside security, defining each team’s role, its inputs and its deadlines, and briefed the leadership on the decisions that remain theirs.
Result
Every team knows its part, and the PSIRT workload is reduced by 50%, spent on security work rather than coordination.

Governance and implementationExecutive briefings

Retained advisor

Architecture review and supplier selection

Challenge
A manufacturer needed a new technical architecture delivered by outside suppliers, and had no security requirements to put in the request for proposals nor a way to compare the candidates on them.
Approach
We reviewed the architecture, identified the suppliers able to deliver it, wrote the request for proposals with the product team and carried the security requirements through every step of the selection.
Result
A supplier selected and signed within three months, meeting the security requirements before the contract.

Decision supportProposals and business cases

Product security strategyIndustrial IoT

FAST for IEC 62443 and EN 303 645

Challenge
A global IoT manufacturer had distributed product teams working across devices, applications and cloud services, each assessing risks its own way, and penetration tests catching the consequences late.
Approach
We developed a multi-asset, multi-standard FAST, covering IEC 62443 and EN 303 645, so that every team follows the same risk-based development process from the first design review.
Result
150k€ saved in penetration tests over 18 months, with fewer findings reaching the final assessment.

FAST

Product security strategyConsumer IoT

Simplified risk assessment

Challenge
A leading consumer IoT manufacturer could not put a security specialist in every project, so risk assessments waited for one and slowed the roadmap.
Approach
We built a bespoke FAST: product teams answer a questionnaire, immediately identify the risks and the high-level requirements, and designate action owners and milestones in line with the governance.
Result
Product teams run their own risk assessments, with no security specialist in the room.

FAST

Product security strategyWearable IoT

FAST automation for compliance

Challenge
A wearable manufacturer validated product security and compliance by hand at the end of each release, too late and too slowly for its cadence.
Approach
We integrated the FAST results into the CI/CD system, so that automatic testing and reporting validate security and compliance at every build.
Result
Far fewer high-level risks reaching a release, and validation in minutes rather than days.

FAST

RED & EN 18031 complianceTest laboratory

FAST for RED compliance

Challenge
A test laboratory spent days per product working out the assets in scope, the applicable security mechanisms and the E.Info to collect before an EN 18031 assessment could start.
Approach
FAST identifies the assets in scope, the applicable security mechanisms and the relevant E.Info for RED cyber compliance, and highlights the tests and assessment units that apply.
Result
Product evaluation accelerated by several days per product.

FAST

No published story for this selection yet. Most of our engagements are confidential: ask us about our work in this area.

Next step

Your products could be the next story

A first call takes thirty minutes and costs nothing: tell us about your product, your market and your timeline, and we will tell you honestly how we can help.