How often does a new vulnerability compromise millions of connected products, affecting our privacy and our safety? Too often. Why are IoT products still used in cyber attacks after all these years? In most cases, product teams do not manage product cyber security after market release. The Cyber Resilience Act now requires it, and the reporting obligations already apply.
In this one-hour awareness session, you discover how to protect products after their release on the market: the concepts and the tools that identify new cyber security issues and fix them in compliance with the regulations. We explain how the software bill of materials (SBOM), vulnerability disclosure, vulnerability management and security updates work together to keep a product secure throughout its support period.
Audience: product security teams, product owners, customer support teams, developers and senior management. The content remains accessible to non-security experts: there is no coding and no hacking involved. Customer support teams learn to recognise a vulnerability report when one arrives, and their part in the reporting obligations.
The session is available live, or as a package to deploy on your internal training platform.
Objectives
-
Understand the challenges of securing products after market release.
-
Know the possibilities to secure products after release, and how these concepts and tools work together.
-
Plan these requirements in the product development phase, before the product ships.
Programme
-
Introduction to product cyber security after market release, and what the CRA expects during the support period.
-
The concepts and tools to secure products in the market: SBOM, vulnerability disclosure and management, security updates, reporting.
-
How to combine them to improve security throughout the product lifecycle.
-
Prerequisites to integrate these requirements in the product development phase.
