<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://bedrockcyber.co.uk/feed.xml" rel="self" type="application/atom+xml" /><link href="https://bedrockcyber.co.uk/" rel="alternate" type="text/html" /><updated>2026-09-08T08:04:17+01:00</updated><id>https://bedrockcyber.co.uk/feed.xml</id><title type="html">Bedrock Cyber</title><subtitle>Answer whatever a customer or a regulator asks, from what your engineers already do. Product security, threat modelling and evidence for teams building critical product solutions.</subtitle><author><name>Tom Eggington</name></author><entry><title type="html">EU Cyber Resilience Act Preparation</title><link href="https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-playbook/" rel="alternate" type="text/html" title="EU Cyber Resilience Act Preparation" /><published>2026-08-27T00:00:00+01:00</published><updated>2026-08-27T00:00:00+01:00</updated><id>https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-playbook</id><content type="html" xml:base="https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-playbook/"><![CDATA[<h2 id="what-eu-cra-means-for-businesses">What EU CRA means for businesses</h2>

<p>In an environment of narrow and voluntary product security frameworks and regulations, the EU Cyber Resilience Act presents a step change for businesses deploying connected products into the European Union.</p>

<p>Compliance becomes a gatekeeper for access to the market, and the only exclusions are for product categories that are already heavily regulated.</p>

<p>This presents unique challenges for many businesses which, until now, have faced no mandatory minimum product security standards. The shift in obligations means businesses will be grappling with complex security topics in areas where they lack prior experience and in-house expertise.</p>

<p>While large organisations make up the substantial majority of revenue for impacted products, this doesn’t tell the full story. Because of the wide net EU CRA casts, and the minimal carve outs, it is estimated that 99% of all impacted businesses are small and medium sized.</p>

<p>The organisations that succeed will be those that adopt a structured approach to  the regulation through genuine improvement of their product security and resilience. Technical excellence alone will not be enough. Operational preparedness is a central pillar of the requirements, and client procurement pressures will necessitate meaningful evidence gathering activity.</p>

<p>How businesses approach alignment to the Cyber Resilience Act will determine not only initial success in adhering to it, but how effectively they can meet its demands into the future.</p>

<hr />

<h2 id="principal-actions-for-successful-compliance">Principal actions for successful compliance</h2>

<h3 id="understand-how-much-of-your-product-catalogue-is-affected">Understand how much of your product catalogue is affected</h3>

<p>The regulations capture a broad horizontal segment of products, but this doesn’t necessarily mean that an entire business’s product catalogue will fall under the regulations.</p>

<p>Product inventory already placed on the market before 11 December 2027 and some special categories of products (e.g., aviation, medical) are exempt.</p>

<p>It’s also important to understand that the scope of EU CRA may in some cases be broader and capture more than an organisation anticipates. For example, if an organisation imports or distributes someone else’s white-labelled products under its own name, then it inherits the full set of obligations for those products.</p>

<p>The pre-11 December 2027 carve out only applies to individual units, not a product type. And any substantial modification to those units after the date brings them into scope.</p>

<h3 id="seek-leadership-buy-in">Seek leadership buy-in</h3>

<p>An EU Cyber Resilience Act compliance project requires clear planning and resourcing. The regulations require review of, and potential changes to, many areas of a business, from product design to software development, legal counsel, and customer service.</p>

<p>Gaining leadership buy-in from decision makers is vital for effective execution of organisation readiness. Without this support, coordinating a compliance programme becomes inefficient and fragmented. Necessary resource goes unallocated, timescales are stretched and compliance is put at risk.</p>

<h3 id="identify-internal-stakeholders">Identify internal stakeholders</h3>

<p>Understanding and assigning internal responsibilities for teams and individuals when planning a compliance programme is key to operational success. It must be clear who within a business owns the strategic implementation, and who is accountable for each tranche of compliance.</p>

<p>Consider how centralised compliance execution should be. The 24-hour notification window for vulnerability exploitation and severe incidents mandated by EU CRA necessitates rapid internal communication and coordination. Even with sufficient planning, the reporting timescales require clarity from everyone on the role that they play. A RACI matrix can be a useful framework for achieving such clarity.</p>

<h3 id="understand-where-compliance-is-already-met">Understand where compliance is already met</h3>

<p>Much of the regulation formalises best practices in secure product design, development, and operations. As a result, businesses that have well established development and security programmes will already be implementing many of the requirements.</p>

<p>An organisation must understand its current compliance position before embarking on any roll out of new practices or documentation. By assessing each area of the requirements against existing business practice, more efficient and coordinated implementation plans can be presented to leadership sponsors.</p>

<h3 id="triage-and-plan-remediation">Triage and plan remediation</h3>

<p>If European Standards organisations haven’t published formal implementation guidance when a business comes to plan EU CRA compliance, advice from the European Commission is clear: do not wait.</p>

<p>There is no single correct path to compliance, and essential requirements are listed clearly in the regulation’s annexes. Businesses that have completed an assessment of their current product security posture should begin planning their remediation programme, and look to analogous established security frameworks to guide their implementations.</p>

<hr />

<h2 id="turn-eu-cra-into-a-business-asset">Turn EU CRA into a business asset</h2>

<p>The regulation should not be framed merely as a box ticking exercise. The requirements are rigorous, but also lean enough to allow compliance activities to become transformative for a business’s product security.</p>

<p>Organisations will come out of the process with capabilities that genuinely strengthen operational confidence in incident response, while solidifying product competitiveness during the sales process, and improving client relationships in the face of ever more thorough cyber scrutiny.</p>

<hr />

<h2 id="gauge-your-readiness">Gauge your readiness</h2>

<p>Ask the right questions from the start to set up for success.</p>

<ul>
  <li>Do you have a complete catalogue of the products going into the EU market, and do you have enough information to hand to classify them?</li>
  <li>Could you produce a machine-readable software bill of materials for your products on the market without starting a project for it?</li>
  <li>If you became aware of an actively exploited vulnerability in your product Friday afternoon, who would be filing the notification before the end of Saturday?</li>
  <li>Do you have a named owner for delivering EU CRA, with a defined budget?</li>
  <li>Do your products have a published end of support date and has providing security updates until then been costed?</li>
  <li>If asked tomorrow, could you assemble the required technical product documentation from what your engineering team already produces?</li>
</ul>

<hr />

<h2 id="where-to-start">Where to start</h2>

<p>Build your compliance programme so that evidence of your product security comes from what the business already does.</p>

<p>Bedrock Cyber supports organisations in planning for and delivering EU CRA compliance with processes that generate proof without additional burden.</p>

<p class="u-space-m u-enter" style="--delay:.58s">
    <a class="btn btn--ink" href="/contact">
    <span class="dot" aria-hidden="true"></span>Start a conversation
    <span class="btn__arrow" aria-hidden="true">&rarr;</span>
    </a>
</p>

<hr />

<p><strong>Looking to go deeper?</strong> Find examples of compliance readiness activities and a pathway outline in <a href="/writing/eu-cyber-resilience-act-are-you-ready/">Bedrock Cyber’s EU CRA Factsheet</a>.</p>]]></content><author><name>Tom Eggington</name></author><summary type="html"><![CDATA[What EU CRA means for businesses]]></summary></entry><entry><title type="html">EU Cyber Resilience Act: Are You Ready?</title><link href="https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-are-you-ready/" rel="alternate" type="text/html" title="EU Cyber Resilience Act: Are You Ready?" /><published>2026-07-25T00:00:00+01:00</published><updated>2026-07-25T00:00:00+01:00</updated><id>https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-are-you-ready</id><content type="html" xml:base="https://bedrockcyber.co.uk/writing/eu-cyber-resilience-act-are-you-ready/"><![CDATA[<p>The reporting requirements of the EU Cyber Resilience Act come into force in September 2026.</p>

<p>If you place products with digital elements onto the EU market, including mobile apps, you are likely to be affected and might need to take action to be compliant.</p>

<p><strong>Download Bedrock Cyber’s EU CRA Factsheet</strong> to quickly learn what you should know today.</p>

<div>
  <a class="download" href="/assets/downloads/bedrock-cyber-eu-cra-factsheet.pdf" download="">
    <span class="download__icon" aria-hidden="true">
      <svg viewBox="0 0 24 24"><path d="M12 3.5 V15" /><path d="M7.5 10.5 L12 15 L16.5 10.5" /><path d="M4.5 19.5 H19.5" /></svg>
    </span>
    <span class="download__text">
      <span class="download__title">EU CRA Factsheet</span>
      <span class="download__meta">PDF &middot; 4 pages &middot; 288&nbsp;KB</span>
    </span>
    <span class="download__arrow" aria-hidden="true">&darr;</span>
  </a>
</div>

<h2 id="what-the-factsheet-covers">What the factsheet covers</h2>

<ul>
  <li><strong>Scope</strong> what counts as a product “with digital elements”, how remote data processing is treated, where importers and distributors pick up obligations, and what is excluded.</li>
  <li><strong>The two dates</strong> 11 September 2026 for reporting, 11 December 2027 for full application.</li>
  <li><strong>Reporting obligations</strong> the 24-hour, 72-hour and 14-day clocks, the ENISA Single Reporting Platform, and who else has to be told.</li>
  <li><strong>Core obligations</strong> secure by design and default, no known exploits at release, support periods, vulnerability handling, and the documentation you have to keep.</li>
  <li><strong>Who does the work</strong> an example of how compliance activity lands across engineering, supply chain, legal, support and leadership.</li>
  <li><strong>A pathway</strong> six practical steps to take before the harmonised standards arrive.</li>
</ul>

<p>Complying with the act is not a one-size-fits-all exercise. The standard doesn’t change with company size, but the practical implementation does.</p>

<p>It is common for teams to already be doing more security work than they realise or can currently point to evidence for.</p>]]></content><author><name>Tom Eggington</name></author><summary type="html"><![CDATA[A free factsheet on the EU Cyber Resilience Act: scope, the September 2026 and December 2027 dates, reporting obligations, and a pathway to compliance.]]></summary></entry><entry><title type="html">Nobody Wants To Steal Your Sensor Data</title><link href="https://bedrockcyber.co.uk/writing/nobody-wants-to-steal-sensor-data/" rel="alternate" type="text/html" title="Nobody Wants To Steal Your Sensor Data" /><published>2026-07-17T00:00:00+01:00</published><updated>2026-07-17T00:00:00+01:00</updated><id>https://bedrockcyber.co.uk/writing/nobody-wants-to-steal-sensor-data</id><content type="html" xml:base="https://bedrockcyber.co.uk/writing/nobody-wants-to-steal-sensor-data/"><![CDATA[<h2 id="treat-physical-world-interactions-differently">Treat physical world interactions differently</h2>

<p>Suppliers into the critical infrastructure space have a host of requirements to deal with that simply don’t exist in other sectors. This burden becomes even more acute once you’re delivering solutions that are involved in real world interventions. AI and ML features and behaviour can then act as a multiplier on top.</p>

<p>It’s one thing to have to defend the security of your product when it’s handling personal data or storing sensitive geospatial infrastructure data. But much of the CNI supplier landscape interacts with the physical world in ways that other sector businesses simply don’t have to contemplate.</p>

<p>You don’t see Salesforce worrying about whether a bad update is going to mean a burst pipe on the high street goes unreported. If Jira metrics are reporting the wrong numbers for a couple of hours, it doesn’t result in a burst water main. And the latest hotshot e-commerce start-up doesn’t need to worry about being in hot water with the Environment Agency: if their AI modelling goes wrong, it’s not going to result in erroneous EDM reporting.</p>

<h2 id="theres-more-to-security-than-confidentiality">There’s more to security than confidentiality</h2>

<p>ISO 27001 is the de facto standard for managing risk in information systems and for demonstrating that security is an audited priority amongst your people and technology. But it’s not a silver bullet and can be misinterpreted and misapplied, resulting in a certification that satisfies clients on a surface level, but which begins to break down for those that dig a little deeper.</p>

<p>Even worse, it can result in a false sense of security while your solution is left exposed to the realities of contemporary threats.</p>

<p>The problem with trying to fit conventional information security practices onto products in this space is that the security industry and its practitioners are often heavily weighted towards confidentiality. Protecting the secrecy of data in transit, in storage, ensuring access to it is recorded. In an information age, this makes sense. Data is treated like the crown jewels because it usually is.</p>

<p>But when delivering solutions that interact with the world around us, availability of data, and integrity and trust in that data, is often just as if not more important than confidentiality.</p>

<h2 id="protect-hard-won-trust">Protect hard-won trust</h2>

<p>A sensor’s readings are unlikely to be sensitive on their own, but if they can be intercepted and suppressed, then you’ve got an overflow event on your hands that your product was supposed to proactively detect.</p>

<p>You might prevent all but your most senior engineers from accessing anomaly data, but if they can accidentally overwrite it, then you’ve got a failed regulatory obligation.</p>

<p>No data has been stolen, no one is making a report to the ICO, your systems haven’t been ransomwared, but when your business model is built around proactive detection and event containment, trust in the product is essential, and it’s just been eroded.</p>

<h2 id="iso-27001-is-effective-but-only-if-applied-well">ISO 27001 is effective, but only if applied well</h2>

<p>The security industry needs to do better by clients and not just apply frameworks like ISO 27001 by blindly following the same playbook every time. Different organisations have different security needs, and security must be evaluated in the context of the product and systems being protected. ISO 27001 is an adaptable and highly effective risk management framework when applied correctly.</p>

<p>Organisations shouldn’t be getting to ISO 27001 certification by systematically applying the 93 controls from Annex A of the standard. This does a disservice to the business underneath. The 93 controls were never intended to be a prescriptive list of requirements. They’re guidelines and recommendations of how to manage security risk and should be treated as such, and there are mechanisms build into the standard for justifying why a control isn’t relevant.</p>

<h2 id="machine-learning-and-ai-systems-need-attention">Machine learning and AI systems need attention</h2>

<p>The National Cyber Security Centre (NCSC) themselves say in their <a href="https://www.ncsc.gov.uk/sites/default/files/documents/NCSC-Machine-learning-principles.pdf">Machine Learning Principles publication</a> that there’s no one size fits all, and that ML systems require additional consideration above and beyond established cyber security best practice. Just from that, we can infer that if a service incorporates ML elements, then the standard 93 controls from ISO 27001 are likely to provide insufficient protection.</p>

<p>The NCSC publication talks about poisoning attacks where manipulated data finds its way into training, and reshapes the definition of normal. A model that’s subversively trained on tampered readings could end up reporting a healthy network where the reality is anything but.</p>

<h2 id="true-security-starts-with-the-funamdentals">True security starts with the funamdentals</h2>

<p>The benefit of the framework is that it is designed to be flexible and adaptable to any shaped organisation. By asking some fundamental questions of teams, it doesn’t have to be difficult to evaluate how effectively it’s working:</p>

<ul>
  <li>Could you tell the difference between a faulty sensor and maliciously modified measurements?</li>
  <li>Do you have a mechanism to prevent your ML models from training on manipulated data?</li>
  <li>Would you know if your ML model’s alerting behaviour had drifted since the version the client validated?</li>
</ul>

<p>The good news is that because ISO 27001 is non-prescriptive by design, it can support and help frame processes that fit the real security needs and risks inside an organisation.</p>

<p>And the even better news is that a correctly scoped certification means only needing to do the things that are actually relevant to your risk. You end up with something that’s both more tailored and therefore more secure, and also involves less overhead to maintain.</p>

<hr />

<p>Doing product security right doesn’t need to be burdensome, but it does require the coming together of specialist expertise from within an organisation and the specialist security expert who can bring the correct controls for that organisation.</p>

<p>Once we get away from the generalist one size fits all thinking, real change and real defence of our vital infrastructure is achievable.</p>]]></content><author><name>Tom Eggington</name></author><summary type="html"><![CDATA[Treat physical world interactions differently]]></summary></entry><entry><title type="html">Regulatory Pressure on Utility Third Party Risk Means Suppliers are Falling Behind</title><link href="https://bedrockcyber.co.uk/writing/regulatory-pressure-means-suppliers-falling-behind/" rel="alternate" type="text/html" title="Regulatory Pressure on Utility Third Party Risk Means Suppliers are Falling Behind" /><published>2026-05-22T00:00:00+01:00</published><updated>2026-05-22T00:00:00+01:00</updated><id>https://bedrockcyber.co.uk/writing/regulatory-pressure-means-suppliers-falling-behind</id><content type="html" xml:base="https://bedrockcyber.co.uk/writing/regulatory-pressure-means-suppliers-falling-behind/"><![CDATA[<h2 id="regulation-is-changing-the-security-landscape">Regulation is changing the security landscape</h2>

<p>Technology suppliers are used to being the innovative partner in the operator-supplier relationship. The image conjured is of utility operators in their dusty offices, celebrating the “newbie’s” 20-year work anniversary, akin to a Flash the sloth scene from Zootopia.</p>

<p>Meanwhile, the trailblazing Silicon Valley adjacent technology supplier occupies a swanky London office with something called a “breakout room”, lamenting their clients’ languid progress toward moving into the 21st century.</p>

<p>But UK regulatory pressures are changing the utility operator landscape, and suppliers who rest on their laurels are at risk of falling behind in areas that matter most to their clients.</p>

<h2 id="eu-cra-and-uk-nis-changes-mean-suppliers-need-to-prepare">EU CRA and UK NIS changes mean suppliers need to prepare</h2>

<p>The EU Cyber Resilience Act is a significant step change for suppliers. Security practices that for years had been considered option best practice, nice to haves that the team would get to “one day”, are now barriers to entering the EU market.</p>

<p>The implementation of the Cyber Security and Resilience Bill will push operators even further than existing NIS regulations and they’ll adapt accordingly. Suppliers need to be ready to meet the inevitable increased maturity of operators’ security questionnaires.</p>

<p>Operators are adopting modern platforms to help manage the changing regulatory landscape when it comes to third party risk management. While their newly implemented risk management platform might be the thin end of the wedge today, it becomes a problem for suppliers who aren’t prepared when the operator need only flip a switch to start demanding answers to more thorough criteria aligned to the Cyber Security and Resilience Bill.</p>

<p>The truth is, it’s not just the operators that feel the sharp end of new cyber regulation, because much of that pressure ends up pushed down the supply chain, and all else being equal, it will be the suppliers ready to meet that challenge with minimal disruption to their day to day operations who will flourish and succeed.</p>

<h2 id="more-rigorous-evidence-will-be-needed-more-frequently">More rigorous evidence will be needed more frequently</h2>

<p>As a supplier to critical infrastructure, it doesn’t matter how innovative and revolutionary a solution might be; if their cyber risk profile doesn’t meet the operator’s requirements and they can’t get into the client’s supply chain, then they have a problem.</p>

<p>But there’s a more insidious danger waiting for the chosen ones who do make it through, and that is in the regular reviews of third-party risk that operators now conduct. Procurement is no longer the only moment when suppliers are expected to answer cyber security questions and so that heavy lift to get the deal over the line becomes a regular burden that commonly spans across multiple teams.</p>

<p>By operating in the classic model of point in time evidence gathering, suppliers put themselves at risk of the dual threat of operators requiring answers not only to more thorough security questions, but also of those same operators asking more often.</p>

<p>If suppliers don’t adapt, they will end up with more of their people spending more time on cyber reviews: time which could otherwise be spent on operational delivery.</p>

<hr />

<h2 id="smarter-product-security-is-the-solution">Smarter product security is the solution</h2>

<p>Utility operators are responding as a result of top-down regulatory pressure. But their technology suppliers are uniquely positioned to innovate.</p>

<p>If suppliers update working practices and the way they approach security so that evidence is generated naturally as part of their daily operations, then there is real opportunity to get ahead and not just respond to customer demand but do what they have always done: trailblaze.</p>]]></content><author><name>Tom Eggington</name></author><summary type="html"><![CDATA[Regulation is changing the security landscape]]></summary></entry></feed>