
What cyber risk is in your product? Assess it right, avoid costly mistakes
The CRA wants you to assess your product's cyber risk. How to do it well, and how to avoid spending on security in the wrong places.
Topic
When & Where
Details
Format:
Technology lecture
Language:
German
Session description
The EU Cyber Resilience Act asks a single question, but it is the right one: What cyber risk is in your product? Can you explain which risk arises from which product property, which measure reduces it, and which residual risk remains?
The CRA already provides the 13 essential cybersecurity requirements (see Annex I). What it does not provide is the answer to which of them apply to your product, and how deeply.
Only a properly conducted cyber risk assessment gives that answer.
It makes the difference between real product security and expensive security in the wrong place. Anyone who wants to "meet" everything across the board pays twice: once for measures nobody needs, and a second time when someone asks for justifications and they are missing.
In 15 minutes, this ...

