Skip to main content
Cyber Resilience Act

Cyber Resilience Act

Search complete. 55 mentions across 37 episodes found for "Cyber Resilience Act".

Sep 11, 2026

Dave BittnerHOST
7:53
The company argues AI is lowering the expertise and labor required for sophisticated cyber operations while noting that familiar techniques, including phishing, stolen credentials, and software vulnerabilities remain central to successful attacks.
Dave BittnerHOST
8:11
Manufacturers selling products with digital elements in the European Union are now subject to mandatory vulnerability and incident reporting under the Cyber Resilience Act.
Dave BittnerHOST
8:22
Companies must notify authorities within twenty-four hours of learning about an actively exploited vulnerability or severe security incident, followed by a detailed report within seventy-two hours.
Dave BittnerHOST
8:34
Reports must be submitted through ENISA's single reporting platform, and manufacturers may also need to quickly inform affected users about vulnerabilities, incidents, and available mitigations.
Christopher BaileyHOST
22:08
SBOMs, as they're abbreviated, are used as inputs for SCA tools such as scanners for vulnerabilities and licenses, and have been gaining traction in global software regulations and frameworks.
Christopher BaileyHOST
22:21
SBOMs are required by recent software security regulations like the Secure Software Development Framework and the Cyber Resilience Act.
Christopher BaileyHOST
22:30
770 was accepted in April last year.
Christopher BaileyHOST
22:32
I won't dive too much further into all the specifics of it, of the PEP, but it's w- well written and definitely something you might wanna look into.
speaker_0VOICE_ACTOR
0:48
Top story number two.
speaker_0VOICE_ACTOR
0:50
The EU Cyber Resilience Act is tightening reporting requirements for manufacturers of connected products, requiring them to disclose actively exploited vulnerabilities and severe incidents within strict timeframes.
speaker_0VOICE_ACTOR
1:03
The rules are designed to improve transparency and speed up response across the software supply chain, but they also raise compliance pressure for vendors selling into the European market.
speaker_0VOICE_ACTOR
1:14
For executives, the measure signals a shift from voluntary disclosure to mandatory cyber incident reporting with significant operational and legal consequences.
Raj RajendraGUEST
3:37
But knowing that cybersecurity is going to be a law, if not in the US, in Europe, they have legislation coming out that we had to comply by 2027.
Raj RajendraGUEST
3:49
It's called Cyber Resilience Act.
Raj RajendraGUEST
3:54
And we had to be ready with all of our systems.
Raj RajendraGUEST
3:56
So customers get capabilities beyond previously associated with larger PLC system while retaining the simplicity and cost-effectiveness expected in small applications.

6 MINS LATER

Raj RajendraGUEST
10:22
These features help protect against unauthorized access, support compliance requirements, and improve long-term operational reliability.
Chris McNamaraHOST
10:32
Okay, we're talking compliance.
Chris McNamaraHOST
10:34
The Cyber Resilience Act that we touched on a minute ago is on the tip of everyone's tongue in this space.
Chris McNamaraHOST
10:39
And that deadline for compliance is going to be here before we know it.
speaker_0HOST
3:03
The thread connecting these first three stories is trust being used as a weapon, and European regulators have clearly had enough of that.
speaker_0HOST
3:11
Starting this week, the European Union's Cyber Resilience Act requires companies selling connected products in Europe to report serious security incidents to regulators within 24 hours of discovery.
speaker_0HOST
3:25
That's not 72 hours, not a week, 24 hours.
speaker_0HOST
3:29
The law covers manufacturers, developers, and distributors of virtually anything with software or network connectivity, from consumer electronics to industrial equipment.
Joachim MahlstedtGUEST
3:46
Uh, so everybody knows NIS2 is, is there to stay.
Joachim MahlstedtGUEST
3:50
The Cyber Resilience Act is [laughs] has us all, uh, caught up in, in, in many activities, but, uh, also GDPR and, and there has been a great rise in, in compliancy requirements which we all have to face.
Joachim MahlstedtGUEST
4:02
And if you compare this now with the problems which we are having in getting personnel, you know, personnel who are actually able to operate these systems which we are required to have, also paired maybe with a lot of, uh, complexity within these silos of systems.
Joachim MahlstedtGUEST
4:18
Suddenly you notice there's a high risk of failure-
Marc LaliberteHOST
10:40
Up until now, the market continues to decide that security is less important than something that's cheap and that technically works.
Marc LaliberteHOST
10:47
That's why we're seeing things like the Cyber Resilience Act come in to force a lot of these security practices across vendors like WatchGuard.
Marc LaliberteHOST
10:55
But With something like ID verification, since that as a topic is becoming so important across the world, we definitely need some sort of like, okay, if you're gonna require it, maybe have some requirements on how they actually secure that type of data too.
Corey NachreinerHOST
11:10
Yeah, I want you to make sure there's nothing else we should finish in the story before we discuss takeaways.
Ildikó VáncsaHOST
0:03
Let's venture over to the corporate land a little bit in Europe, or well, more specifically, in the European Union market, which means that we're also talking to folks in other countries who are not in the European Union, but they might have a product on that market.
Ildikó VáncsaHOST
0:26
Because I don't know if you heard but there is this thing called Cyber Resilience Act which is not about open source but it does affect open source as well it is about all the digital products that are hitting the European market.
Ildikó VáncsaHOST
0:43
And if they happen to have some kind of vulnerability in them, that is a problem.
Ildikó VáncsaHOST
0:49
And if that vulnerability, to my knowledge, if it is in an open source project, like the vulnerability itself is in the upstream project, then the companies also have some responsibilities to report that vulnerability, um, probably multiple places, but one of those is the open source community itself.
Ildikó VáncsaHOST
1:13
And I also remember reading it somewhere that if the company has a fix to the vulnerability, they are also obligated to share that.
Ildikó VáncsaHOST
1:23
Now, the Cyber Resilience Act has been a long process of forming and then having all the standards and processes set up around it and some deadlines are coming up.
Ildikó VáncsaHOST
1:37
So can you give a little bit of an overview of where we are and what crazy things I said that may or may not be reality?
Christopher CRob RobinsonGUEST
1:49
So the European Union Cyber Resilience Act is one of the most impactful pieces of legislation that I've seen in my career.
Piet De VaereHOST
0:18
Hello, Pete.
Piet De VaereHOST
0:20
Welcome to our fifth episode of O2 Resilience, the premier podcast about the EU Cyber Resilience Act and so much more.
August BourniqueHOST
0:29
Are we still the only podcast about the CRA? I guess we should not
August BourniqueHOST
0:32
be the people informing others of that.
Steve AtkinsHOST
2:35
Now we begin the new season in the heart of European industry.
Steve AtkinsHOST
2:39
The Cyber Resilience Act and NIS2 are changing the responsibilities of manufacturers, product developers and senior management.
Steve AtkinsHOST
2:48
The CRA focuses on the security of products with digital elements throughout their lifecycle While NIS2 addresses organizational resilience, cyber risk management, and more importantly, management accountability.
Steve AtkinsHOST
3:04
For industrial companies, these responsibilities increasingly meet inside the same product, system, and business process.

27 more episodes mention Cyber Resilience Act.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.