Client work

Success stories: what our advisory work changed for our customers.

Our clients range from five-person start-ups to multinational product groups, in consumer IoT, industrial systems, energy and safety-critical products. The engagements below are described with their permission. Names are withheld where confidentiality requires it.

Advisory
Sector

of 26 engagements

CRA readinessConsumer IoT

Unlocking security by design

Challenge
A leading consumer IoT manufacturer embedded security by design and by default in their existing product development processes, covering a wide portfolio across multiple sectors.
Approach
We integrated cyber security requirements and review gates into the existing development process, and trained 100 developers on secure design for their own products.

Security-by-designTraining

Product security strategyIndustrial IoT

Accelerating secure product release

Challenge
A multi-market industrial IoT manufacturer needed every product owner to define the right security requirements, without a security specialist available for each project.
Approach
We built a bespoke FAST tool that identifies the risks, derives the cyber security requirements and evaluates compliance automatically, and deployed it in the product teams.

Security-by-designProduct security governance

RED & EN 18031 complianceCritical infrastructure

Compliance in a short timeframe

Challenge
An energy management company was launching several connected products with RED cyber security applying, and no time to build the compliance capability first.
Approach
We delivered the cyber security risk assessments and the product documentation, and supported the engineers on the fixes, in step with the launch plan.

Cyber security risk assessmentTechnical documentation

Product security strategyCritical infrastructure

Supporting the product strategy

Challenge
A safety company saw cyber security requirements appear in tenders and in new markets, and had no way to show buyers how its products met them.
Approach
We defined the product security strategy and showed how cyber security supports the product functionalities while reducing risks to end users, in the language of the tenders.

Product security governance

CRA readinessConsumer IoT

Consolidated compliance budget

Challenge
A leading consumer IoT brand had a wide portfolio, a CRA deadline and no shared view of its exposure: engineering, compliance and the board each had their own picture, and no budget had been secured.
Approach
We assessed the portfolio and the processes against the Cyber Resilience Act, then turned the gaps into a plan the board could decide on: what to fund, in what order, and what happens if not.

Gap analysisCompliance roadmap

CRA readinessIndustrial IoT

Vulnerability management before the deadline

Challenge
A global industrial IoT manufacturer had SBOMs but no process behind them: vulnerability matches piled up, nobody owned the triage, and the CRA reporting deadlines were months away.
Approach
We set up the vulnerability handling process from intake and triage to remediation and reporting, with the SBOM as its input, and automated the correlation between components and known vulnerabilities inside that process.

Post-market requirementsSupport period definitionSecurity-by-design

CRA readinessIndustrial IoT

Secure factories, secure products

Challenge
A leading IoT manufacturer had to demonstrate that its products are produced securely, across complex manufacturing lines where provisioning and firmware flashing had never been assessed.
Approach
Over 16 weeks we executed an exhaustive threat model of the manufacturing lines, identified the risks in the provisioning and firmware flashing stages, and engineered the remediations with the plant teams.

Threat model for manufacturing

Product security strategyIndustrial IoT

Secure product development lifecycle

Challenge
An industrial IoT manufacturer found most of its vulnerabilities at the final assessment, when every fix delayed the release and security depended on a handful of individuals.
Approach
We put security milestones and responsibilities into the existing development process, so that flaws are caught at design and build time by the engineers themselves.

Product security governancePolicies and processesSupply chain managementResilient architecture

Product security strategyConsumer IoT

Unified vulnerability disclosure policy

Challenge
A consumer IoT group handled vulnerability reports differently in each brand and market, with no common public policy and no shared way to fix root causes.
Approach
We wrote one vulnerability disclosure policy for all the brands, published it, and aligned the product teams on how a report is handled from the day it arrives.

Product security governancePolicies and processes

Product security strategyConsumer IoT

Governance dashboard for product security

Challenge
A multi-brand consumer IoT group could not answer a simple question from its leadership: where does each brand stand on product security and compliance, across devices, applications and cloud services.
Approach
We defined who is responsible for what, the few indicators that matter for the development lifecycle and for the obligations after release, and built a dashboard that shows them for every brand, across devices, applications and cloud.

Product security governanceSupply chain management

Product security strategyIndustrial IoT

Maturity posture improvement

Challenge
An industrial IoT manufacturer knew its product security was uneven but could not show its executives where, or make a case for the budget to fix it.
Approach
We measured the existing practices against our maturity model, site by site, and turned the gaps into a business case written for the executive committee.

Maturity level evaluation

RED & EN 18031 complianceIndustrial IoT

Compliance as a market catalyst

Challenge
An industrial IoT manufacturer had a fragmented product line and EU operators of critical infrastructure asking for RED cyber security compliance before they would buy.
Approach
We ran a pre-compliance check of the portfolio against our RED framework, then migrated the product line onto a unified secure-by-design architecture with a compliance roadmap for each product.

Pre-compliance checkArchitecture engineeringCompliance roadmap

RED & EN 18031 complianceConsumer IoT

CE compliance within 3 weeks

Challenge
A wearable product had a launch date, a notified body review ahead, and no EN 18031 technical documentation.
Approach
We drafted the EN 18031-1 and EN 18031-2 documentation (E.Info and E.DT) from the available material, working with the product team on the justifications the notified body would examine.

Technical documentationLiaison with test lab

RED & EN 18031 complianceCritical infrastructure

Building internal compliance velocity

Challenge
A smart metering manufacturer needed its first EN 18031-1 technical documentation within a month, and wanted its engineers to be able to do the next ones alone.
Approach
We wrote the documentation with the engineering teams: our specialist drafted, their engineers reviewed and corrected, and learned the structure along the way.

Cyber security risk assessmentTechnical documentationLiaison with test lab

RED & EN 18031 complianceCritical infrastructure

Transforming test failures into CE compliance

Challenge
An EV charging manufacturer failed critical points of the final assessment at the test lab, weeks before the planned release.
Approach
We sat between the manufacturer and the lab: we wrote the technical justifications for the design choices the lab had questioned, and fixed the points where a justification was not enough.

Liaison with test labCyber security risk assessment

TrainingConsumer IoT

Increasing global capabilities

Challenge
A global multi-brand consumer IoT organisation had teams in several countries with very different levels of product security knowledge, and no way to align them without micro-management.
Approach
We designed structured training paths per role, from awareness to specialist courses, aligned with the corporate objectives, and delivered them across the brands.

Training pathsAwareness sessions

TrainingIndustrial IoT

Company-wide awareness packages

Challenge
An industrial group wanted every one of its 5,000 employees to recognise product security risks and follow the internal standards, without buying a licence per seat.
Approach
We built ready-made awareness packages covering the key challenges, the internal processes and the core requirements, and integrated them into the group’s existing training platform.

Awareness sessions

TrainingConsumer IoT

Technical expertise on IoT standards

Challenge
A consumer IoT manufacturer’s product teams spent weeks interpreting EN 303 645 for each product, and still depended on outside help to apply it.
Approach
We delivered specialised training on the standard, focused on the practical application of its provisions, translating its language into engineering tasks on the teams’ own products.

Deep-dive training

TrainingIndustrial IoT

Non-technical security governance

Challenge
In an industrial IoT manufacturer, marketing and product owners left every security decision to engineering, and each project stalled while the two sides worked out who decides what.
Approach
We delivered targeted deep-dive training for marketing and product owners on their own role in the security lifecycle, bridging business objectives and cyber security requirements.

Deep-dive training

Retained advisorIndustrial IoT

SBOM pilots for vulnerability management

Challenge
A manufacturer had SBOMs from several sources and no agreed way to use them: identifying whether a published vulnerability affected a product took five days on average.
Approach
Three pilot projects over six months, from the initial input to the deployment of the patch, in which we turned the inventory into a process: who receives the alert, who decides, who ships the fix, and how long each step may take.

Governance and implementationDecision support

Retained advisorConsumer IoT

Support period strategy across the portfolio

Challenge
A manufacturer with more than 50 products had to determine the CRA support period of each, and its legal, compliance and product teams disagreed on what the regulation expected.
Approach
We identified with legal and compliance the parameters that determine the support period, and applied them product by product across the portfolio, with the budget consequences of each decision.

Portfolio oversightProposals and business cases

Retained advisorConsumer IoT

PSIRT governance with the whole company

Challenge
A product security incident response team spent half its time coordinating customer support, quality, marketing and legal, none of whom knew their part when a vulnerability or an incident arrived.
Approach
We set up the incident management governance with the stakeholders outside security, defining each team’s role, its inputs and its deadlines, and briefed the leadership on the decisions that remain theirs.

Governance and implementationExecutive briefings

Retained advisorIndustrial IoT

Architecture review and supplier selection

Challenge
A manufacturer needed a new technical architecture delivered by outside suppliers, and had no security requirements to put in the request for proposals nor a way to compare the candidates on them.
Approach
We reviewed the architecture, identified the suppliers able to deliver it, wrote the request for proposals with the product team and carried the security requirements through every step of the selection.

Decision supportProposals and business cases

Product security strategyIndustrial IoT

FAST for IEC 62443 and EN 303 645

Challenge
A global IoT manufacturer had distributed product teams working across devices, applications and cloud services, each assessing risks its own way, and penetration tests catching the consequences late.
Approach
We developed a multi-asset, multi-standard FAST, covering IEC 62443 and EN 303 645, so that every team follows the same risk-based development process from the first design review.

FAST

Product security strategyConsumer IoT

Simplified risk assessment

Challenge
A leading consumer IoT manufacturer could not put a security specialist in every project, so risk assessments waited for one and slowed the roadmap.
Approach
We built a bespoke FAST: product teams answer a questionnaire, immediately identify the risks and the high-level requirements, and designate action owners and milestones in line with the governance.

FAST

Product security strategyConsumer IoT

FAST automation for compliance

Challenge
A wearable manufacturer validated product security and compliance by hand at the end of each release, too late and too slowly for its cadence.
Approach
We integrated the FAST results into the CI/CD system, so that automatic testing and reporting validate security and compliance at every build.

FAST

No published story for this selection yet. Most of our engagements are confidential: ask us about our work in this area.

Next step

Your products could be the next story

A first call takes thirty minutes and costs nothing: tell us about your product, your market and your timeline, and we will tell you honestly how we can help.