Our clients range from five-person start-ups to multinational product groups, in consumer IoT, industrial systems, energy and safety-critical products. The engagements below are described with their permission. Names are withheld where confidentiality requires it.
of 26 engagements
CRA readinessConsumer IoT
Unlocking security by design
- Challenge
- A leading consumer IoT manufacturer embedded security by design and by default in their existing product development processes, covering a wide portfolio across multiple sectors.
- Approach
- We integrated cyber security requirements and review gates into the existing development process, and trained 100 developers on secure design for their own products.
Product security strategyIndustrial IoT
Accelerating secure product release
- Challenge
- A multi-market industrial IoT manufacturer needed every product owner to define the right security requirements, without a security specialist available for each project.
- Approach
- We built a bespoke FAST tool that identifies the risks, derives the cyber security requirements and evaluates compliance automatically, and deployed it in the product teams.
RED & EN 18031 complianceCritical infrastructure
Compliance in a short timeframe
- Challenge
- An energy management company was launching several connected products with RED cyber security applying, and no time to build the compliance capability first.
- Approach
- We delivered the cyber security risk assessments and the product documentation, and supported the engineers on the fixes, in step with the launch plan.
Product security strategyCritical infrastructure
Supporting the product strategy
- Challenge
- A safety company saw cyber security requirements appear in tenders and in new markets, and had no way to show buyers how its products met them.
- Approach
- We defined the product security strategy and showed how cyber security supports the product functionalities while reducing risks to end users, in the language of the tenders.
CRA readinessConsumer IoT
Consolidated compliance budget
- Challenge
- A leading consumer IoT brand had a wide portfolio, a CRA deadline and no shared view of its exposure: engineering, compliance and the board each had their own picture, and no budget had been secured.
- Approach
- We assessed the portfolio and the processes against the Cyber Resilience Act, then turned the gaps into a plan the board could decide on: what to fund, in what order, and what happens if not.
CRA readinessIndustrial IoT
Vulnerability management before the deadline
- Challenge
- A global industrial IoT manufacturer had SBOMs but no process behind them: vulnerability matches piled up, nobody owned the triage, and the CRA reporting deadlines were months away.
- Approach
- We set up the vulnerability handling process from intake and triage to remediation and reporting, with the SBOM as its input, and automated the correlation between components and known vulnerabilities inside that process.
Post-market requirementsSupport period definitionSecurity-by-design
CRA readinessIndustrial IoT
Secure factories, secure products
- Challenge
- A leading IoT manufacturer had to demonstrate that its products are produced securely, across complex manufacturing lines where provisioning and firmware flashing had never been assessed.
- Approach
- Over 16 weeks we executed an exhaustive threat model of the manufacturing lines, identified the risks in the provisioning and firmware flashing stages, and engineered the remediations with the plant teams.
Product security strategyIndustrial IoT
Secure product development lifecycle
- Challenge
- An industrial IoT manufacturer found most of its vulnerabilities at the final assessment, when every fix delayed the release and security depended on a handful of individuals.
- Approach
- We put security milestones and responsibilities into the existing development process, so that flaws are caught at design and build time by the engineers themselves.
Product security governancePolicies and processesSupply chain managementResilient architecture
Product security strategyConsumer IoT
Unified vulnerability disclosure policy
- Challenge
- A consumer IoT group handled vulnerability reports differently in each brand and market, with no common public policy and no shared way to fix root causes.
- Approach
- We wrote one vulnerability disclosure policy for all the brands, published it, and aligned the product teams on how a report is handled from the day it arrives.
Product security strategyConsumer IoT
Governance dashboard for product security
- Challenge
- A multi-brand consumer IoT group could not answer a simple question from its leadership: where does each brand stand on product security and compliance, across devices, applications and cloud services.
- Approach
- We defined who is responsible for what, the few indicators that matter for the development lifecycle and for the obligations after release, and built a dashboard that shows them for every brand, across devices, applications and cloud.
Product security strategyIndustrial IoT
Maturity posture improvement
- Challenge
- An industrial IoT manufacturer knew its product security was uneven but could not show its executives where, or make a case for the budget to fix it.
- Approach
- We measured the existing practices against our maturity model, site by site, and turned the gaps into a business case written for the executive committee.
RED & EN 18031 complianceIndustrial IoT
Compliance as a market catalyst
- Challenge
- An industrial IoT manufacturer had a fragmented product line and EU operators of critical infrastructure asking for RED cyber security compliance before they would buy.
- Approach
- We ran a pre-compliance check of the portfolio against our RED framework, then migrated the product line onto a unified secure-by-design architecture with a compliance roadmap for each product.
Pre-compliance checkArchitecture engineeringCompliance roadmap
RED & EN 18031 complianceConsumer IoT
CE compliance within 3 weeks
- Challenge
- A wearable product had a launch date, a notified body review ahead, and no EN 18031 technical documentation.
- Approach
- We drafted the EN 18031-1 and EN 18031-2 documentation (E.Info and E.DT) from the available material, working with the product team on the justifications the notified body would examine.
RED & EN 18031 complianceCritical infrastructure
Building internal compliance velocity
- Challenge
- A smart metering manufacturer needed its first EN 18031-1 technical documentation within a month, and wanted its engineers to be able to do the next ones alone.
- Approach
- We wrote the documentation with the engineering teams: our specialist drafted, their engineers reviewed and corrected, and learned the structure along the way.
Cyber security risk assessmentTechnical documentationLiaison with test lab
RED & EN 18031 complianceCritical infrastructure
Transforming test failures into CE compliance
- Challenge
- An EV charging manufacturer failed critical points of the final assessment at the test lab, weeks before the planned release.
- Approach
- We sat between the manufacturer and the lab: we wrote the technical justifications for the design choices the lab had questioned, and fixed the points where a justification was not enough.
TrainingConsumer IoT
Increasing global capabilities
- Challenge
- A global multi-brand consumer IoT organisation had teams in several countries with very different levels of product security knowledge, and no way to align them without micro-management.
- Approach
- We designed structured training paths per role, from awareness to specialist courses, aligned with the corporate objectives, and delivered them across the brands.
TrainingIndustrial IoT
Company-wide awareness packages
- Challenge
- An industrial group wanted every one of its 5,000 employees to recognise product security risks and follow the internal standards, without buying a licence per seat.
- Approach
- We built ready-made awareness packages covering the key challenges, the internal processes and the core requirements, and integrated them into the group’s existing training platform.
TrainingConsumer IoT
Technical expertise on IoT standards
- Challenge
- A consumer IoT manufacturer’s product teams spent weeks interpreting EN 303 645 for each product, and still depended on outside help to apply it.
- Approach
- We delivered specialised training on the standard, focused on the practical application of its provisions, translating its language into engineering tasks on the teams’ own products.
TrainingIndustrial IoT
Non-technical security governance
- Challenge
- In an industrial IoT manufacturer, marketing and product owners left every security decision to engineering, and each project stalled while the two sides worked out who decides what.
- Approach
- We delivered targeted deep-dive training for marketing and product owners on their own role in the security lifecycle, bridging business objectives and cyber security requirements.
Retained advisorIndustrial IoT
SBOM pilots for vulnerability management
- Challenge
- A manufacturer had SBOMs from several sources and no agreed way to use them: identifying whether a published vulnerability affected a product took five days on average.
- Approach
- Three pilot projects over six months, from the initial input to the deployment of the patch, in which we turned the inventory into a process: who receives the alert, who decides, who ships the fix, and how long each step may take.
Retained advisorConsumer IoT
Support period strategy across the portfolio
- Challenge
- A manufacturer with more than 50 products had to determine the CRA support period of each, and its legal, compliance and product teams disagreed on what the regulation expected.
- Approach
- We identified with legal and compliance the parameters that determine the support period, and applied them product by product across the portfolio, with the budget consequences of each decision.
Retained advisorConsumer IoT
PSIRT governance with the whole company
- Challenge
- A product security incident response team spent half its time coordinating customer support, quality, marketing and legal, none of whom knew their part when a vulnerability or an incident arrived.
- Approach
- We set up the incident management governance with the stakeholders outside security, defining each team’s role, its inputs and its deadlines, and briefed the leadership on the decisions that remain theirs.
Retained advisorIndustrial IoT
Architecture review and supplier selection
- Challenge
- A manufacturer needed a new technical architecture delivered by outside suppliers, and had no security requirements to put in the request for proposals nor a way to compare the candidates on them.
- Approach
- We reviewed the architecture, identified the suppliers able to deliver it, wrote the request for proposals with the product team and carried the security requirements through every step of the selection.
Product security strategyIndustrial IoT
FAST for IEC 62443 and EN 303 645
- Challenge
- A global IoT manufacturer had distributed product teams working across devices, applications and cloud services, each assessing risks its own way, and penetration tests catching the consequences late.
- Approach
- We developed a multi-asset, multi-standard FAST, covering IEC 62443 and EN 303 645, so that every team follows the same risk-based development process from the first design review.
Product security strategyConsumer IoT
Simplified risk assessment
- Challenge
- A leading consumer IoT manufacturer could not put a security specialist in every project, so risk assessments waited for one and slowed the roadmap.
- Approach
- We built a bespoke FAST: product teams answer a questionnaire, immediately identify the risks and the high-level requirements, and designate action owners and milestones in line with the governance.
Product security strategyConsumer IoT
FAST automation for compliance
- Challenge
- A wearable manufacturer validated product security and compliance by hand at the end of each release, too late and too slowly for its cadence.
- Approach
- We integrated the FAST results into the CI/CD system, so that automatic testing and reporting validate security and compliance at every build.
No published story for this selection yet. Most of our engagements are confidential: ask us about our work in this area.
