Secure products after market release

Most product teams do not manage product cyber security after market release, and the Cyber Resilience Act now requires it. In one hour, discover how SBOMs, vulnerability disclosure and vulnerability management work together to keep products secure after release.

Express your interest!

How often does a new vulnerability compromise millions of connected products, affecting our privacy and our safety? Too often. Why are IoT products still used in cyber attacks after all these years? In most cases, product teams do not manage product cyber security after market release. The Cyber Resilience Act now requires it, and the reporting obligations already apply.

In this one-hour awareness session, you discover how to protect products after their release on the market: the concepts and the tools that identify new cyber security issues and fix them in compliance with the regulations. We explain how the software bill of materials (SBOM), vulnerability disclosure, vulnerability management and security updates work together to keep a product secure throughout its support period.

Audience: product security teams, product owners, customer support teams, developers and senior management. The content remains accessible to non-security experts: there is no coding and no hacking involved. Customer support teams learn to recognise a vulnerability report when one arrives, and their part in the reporting obligations.

The session is available live, or as a package to deploy on your internal training platform.

Objectives

  • Understand the challenges of securing products after market release.

  • Know the possibilities to secure products after release, and how these concepts and tools work together.

  • Plan these requirements in the product development phase, before the product ships.

Programme

  • Introduction to product cyber security after market release, and what the CRA expects during the support period.

  • The concepts and tools to secure products in the market: SBOM, vulnerability disclosure and management, security updates, reporting.

  • How to combine them to improve security throughout the product lifecycle.

  • Prerequisites to integrate these requirements in the product development phase.

Practical information

How our training runs

All our courses are open to anyone with an interest in cyber security. Every course starts with the generic context, so that everyone begins on the same footing, and combines theory, practice and real-life scenarios.

  1. Delivery formats

    Awareness sessions are delivered remotely.

    Training courses are delivered remotely, on-site in your premises, or in a hybrid mode.

    Hands-on courses are delivered on-site in your premises only.

  2. Quality assurance

    Throughout the delivery our trainers remain accessible, and we are always happy to share our own experience in the field. Our objective is that every attendee gains something they can use in their daily activities.

    We commit to the highest possible standard before, during and after the training. Each course ends with a live debrief with the participants, followed by an anonymous survey to collect their feedback afterwards.

  3. Certificate of training

    For our training courses, every participant receives a certificate of training and a letter of completion, certifying that they followed the course and acquired knowledge they can use in their daily activities.
  4. Trainees and participants

    Our training and awareness courses are designed to develop new knowledge and skills in cyber security and cyber resilience. We develop our material for a specific audience, based on their level of knowledge and experience.

Next step

Beyond the training

The course gives your teams the skills. If you also need the work done, our services cover the assessment, the documentation and the support for your products.