Impulse Offer

IoT

With an exponential growth in the number of interconnected devices expected to reach around 75 billion by 2025, online security is becoming an increasingly pressing concern for players operating in the IoT area. To deal with this phenomenon, on 15 September 2022, the European Commission introduced ground-breaking legislation in Europe, called the “Cyber Resilience Act” (CRA). This regulatory proposal aims to consolidate digital security for items containing digital elements, thus marking a significant step in the ever-changing landscape of cybersecurity.

Zoom-in on the Cyber Resilience Act and what it will change in IoT projects.

What is the Cyber Resilience Act (CRA)?

Speaker_YannickGaudin

“The Cyber Resilience Act (CRA) provides a common regulatory framework for Member States to fight the increasing number of cyberattacks to which connected devices are victim, so as to make business players responsible for the cybersecurity of the products they offer on the European market.”

Yannick Gaudin
Security Architect, LACROIX

Complying with the key points

  1. IoT data security requirements

In the interconnected world of IoT, the collection and processing of personal and sensitive data has become commonplace. However, the Cyber Resilience Act highlights the need to protect this data from unauthorized access.

The consequences of a data breach can be devastating, leading not only to financial damage, but also to a loss of customer trust. To meet these requirements, it is essential to implement robust security measures and ensure appropriate data management.

 

  1. Cybersecurity standards for IoT devices

The CRA emphasizes the importance of designing secure IoT devices right from their very creation (referred to as “secure-by-design”). The recommended cybersecurity standards are intended to ensure that devices are protected against potential vulnerabilities and flaws.

Integrating security at an early stage in the development process is fundamental to avoiding costly security gaps and ensuring compliance with the requirements of the Cyber Resilience Act. This proactive approach reduces the risks and lays a strong foundation for IoT projects.

 

  1. Vulnerability and incident management

Continuous vulnerability monitoring and responding rapidly to security incidents are central elements of this regulation. Businesses must be able to quickly identify and correct security flaws to minimize potential damage.

Effective incident response requires well-defined processes and collaboration between technical teams and stakeholders.

Anticipating the implementation of the Cyber Resilience Act

An expert in electronics design and specialised in IoT solutions, LACROIX supports its customers every step of the way to develop their IoT projects.

In order to be compliant with the Cyber Resilience Act, IoT players are required to meet several criteria. And LACROIX is the perfect partner to ensure that all 5 of these key points are fulfilled:

Secure by design

  • Technical framework: architecture, cryptography, secure enclave, etc.
  • Processes: product lifecycle, crisis management, R&D best practices, etc.

Risk & threat analysis model, with cyclical examination

Vulnerability Disclosure Policy (VDP)

  • CVE tracker in place, with teams organized around it
  • Communication channel to inform your customers
  • Mitigation/resolution actions triggered promptly

Large-scale updates at any time

  • Your product’s firmware
  • Secrets-rotation ready

Free security patches

  • All throughout the product’s life cycle (minimum of 5 years)

A close-up of the PizzaIoT conference on the Cyber Resilience Act

To find out more about the CRA and its impacts on IoT projects, LACROIX held a PizzaIoT conference in the heart of Paris on Tuesday 23 May 2023.

What is the concept behind PizzaIoT? An afterwork event, where we talk about IoT, while tucking into some pizza!

  • What is at stake with this regulation and how does it impact IoT products?
  • What should companies do to get ready?
  • What are the recommendations for players such as LACROIX, Provenrun and Kereval to support the deployment of this standard, from design through to maintenance and including validation?
  • Standards evolution, electronic design, technological building blocks, design validation, security vulnerability and certificate management, firmware updates, IoT platforms and beyond: where do we stand today in terms of these aspects?

These were the main topics addressed at the conference hosted by three key speakers from the world of IoT: LACROIX, ProvenRun (software publisher for Internet of Things security) and Kereval (software test engineering laboratory).

Some thirty participants gathered to take part in the conference, which continued with a networking session dedicated to IoT, all over a pizza in the splendid setting of Bpifrance.

➡️ WATCH THE VIDEO OF THE CONFERENCE

If you are interested in the subject of IoT development, you can also find out what happened at the previous PizzaIoT conference: Zephyr OS in all its states.

More stories

3 tips for reshoring through automation

LACROIX Electronics

Behind the myth of the Cyber Resilience Act (or CRA for cybersecurity insiders)

Impulse Offer

Infographic: The obligations of the Cyber Resilience Act for manufacturers

Impulse Offer

Explained

Scalable Industrial Automation: Flexibility and Efficiency for the Factory of the Future

LACROIX Electronics

Explained

Lean Management 4.0 has come to LACROIX!

LACROIX Electronics

Explained

The Digitalization of Technical Documentation: Tested and Approved by LACROIX!

LACROIX Electronics

Expert's take

Digitizing data to boost industrial performance with Power BI!

LACROIX Electronics

How to get ready for the arrival of the Cyber Resilience Act?

Impulse Offer

How LACROIX is using IoT to make road traffic safer and more fluid?

Impulse Offer 5 min

How does LACROIX use IoT to optimize the energy efficiency of buildings?

Impulse Offer 3 min

Case study

How Nevers Agglomeration Increased Efficiency on its Water Network by 20%

LACROIX Environment

Explained

Supporting and securing the transition to soft mobility: what solutions?

LACROIX City

Explained

Reducing non-revenue water

LACROIX Environment

Case study

Traffic peaks on the Ile de Ré: Intelligent, dynamic and automated regulation

LACROIX City

Expert's take

Water pressure regulation to save water and energy

LACROIX Environment

Case study

Reykjavik : Outdoor lighting and the northern lights, cohabitation made possible...

LACROIX City

Detecting wildlife crossings to ensure safety of motorists in Ain aera (France)

LACROIX City

Case study

Commune of Troistorrents rolls out intelligent and progressive street lighting solution

LACROIX City

Innovation

SOFREL S4W a new RTU for hydraulic structures management

LACROIX Environment

Conversation

From LACROIX Sofrel to LACROIX Environment: a look back at 5 years of major change

LACROIX Environment