x) Summarize. 1. Jos Helmich
- GDPR - General Directive Data Protection
Demands that privacy is respected - NIS-2 - Network In formation and Systems # 2
Demands that organizations are cyber resilient - CRA - Cyber Resilience Act
Demands that digital products are cyber secure - AIA - Artificial Intelligence Act
Demands that maker of AI products take fundamental rights and product requirements into account
In US the Legislatives are "temporary" as they are made by current president that can be overturned by the next one.
E.O. 14017, Executive order on America's Supply Chains (24 Feb 2021)
E.O. 14028, Improving the Nation's cybersecurity (May 2021)
E.O. 14123, Whitehouse Council on Supply Chain Resiliance (14 June 2024)
OMB Memerandum M-22-18, "Enhancing the Security of the Software Supply Chain through Secure Software Development Practices" (14 Sep 2022)
OMB Memorandum M-23-16, "Update to Memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices," (23 Jun 2023)
Suppliers to the US government must fill a CISA attestation form
In effect since March 11, 2024
Based on Secure Software Development Framework (SSDF) by NIST
Based on Secure by design principles
https://www.cisa.gov/secure-software-attestation-form
NIS-2
Large impact on organisations
- Increased supervision by authority
- Emphasis on risk management
- Reporting requirements
Requirements are about the organisation's cybersecurity
ISO-27001 - Information security
- Supply chain security (ISO-27036)
- Vulnerability management (ISO-30111) Also
- Registration
- Reporting obligations
NIS-2 in Manufacturing
Industrial network is has extra protection and DMZ should be hard for the attacker to reach.
Ideally the industry zone has no connection to internet.
There are still things that need updating etc that keep things interesting and hard to solve.
Cloud connection... Where to put it 1, 2 or 3?
NIS-2 vs CRA
Both aim to enhance organizational and product-level cybersecurity but differ in their scope:
NIS-2: Targets organizational practices.
CRA: Focuses on digital product security.
NIS-2
Keep your house in order
Don't buy stuff in the garage sale
CRA
Don't mess up someone else's house
Don't sell bad stuff to the customer
NOTE! We need a certifiable standard to address the CRA!
62443
62443-4-1 Secure Software Development Lifecycle Requirements
62443-3-3 System Requirements
62443-4-2 Component Requirements
**Security levels in 62443 **
- Accident tourist
- Normal users
- Hackers
- Nation state
EU Legislation - New Legislative Framework
New legislative frameworks align with modular and standardized approaches
Standards for AI
ISO/IEC 42001:2023
ENISA - Multilayer Framework for Good Cybersecurity Practices for AI
ENISA - Generative AI cybersecurity assessment report (to be published)
ETSI - Secure Artificial Intelligence Technical Committee
NIST - Artificial Intelligence Risk Management Framework
There was a lot of information and I was not able to catch all of it, but luckily remembered to take screenshots.
Questions:
How do organizations manage compliance with overlapping regulations like NIS-2 and CRA?
Are there emerging technologies or frameworks that simplify compliance with these regulations?
What role does international collaboration play in harmonizing cybersecurity standards across regions?
- Reference: https://www.twitch.tv/helsec
x) Summarize. 2. Heikki Juva
State of Union
RED-CRA
https://github.com/Zokol/RED-CRA/blob/main/README.md
CRA - Cyber Resilience Act
2026 CRA Vulnerability notification starts
2027 CRA Vulnerability notification will be enforced
Timeline of how things will proceed:
There is a good resource for blackbox testing, check this out.
https://oulurepo.ouli.fi/handle/10024/52122
Device Classifications
Requirements
Case example
RED
RED - Radio Equipment Directive
Checklist to pass RED part 1
Standards and regulations governing the cybersecurity aspects of radio equipment.
- Software updates are enforced?
- Device storage is secure?
- No vulnerabilities?
- Password are unique or strong?
Checklist to pass RED part 2 Specific requirements for secure product development and operations in compliance with RED and CRA.
- All sensors that may affect user's privacy are documented?
- User is notified if protection or privacy of personal information is altered?
- 3rd party access to personal information is denied by default?
- User or authorized party can delete all personal information, passwords and other security information?
Implementations and Issues
A practical demonstration of device vulnerabilities, focusing on physical and software-based testing methodologies.
90% use TLS and cert pinning
80% implemented on baremetal (no OS)
66% us wifi for communication
90% are online only temporarely
Most common issues
Data not removed
Sharing privacy information with 3rd party
Complex manufacturing, seller does not know how device works
Notes and tools can be found at https://github.com/Zokol/RED-CRA
This panel as a blast and I was completely captivated by the presentation!
Questions:
How will the mandatory CRA vulnerability notification process impact product development timelines?
What industries are most affected by the upcoming CRA vulnerability notification requirements?
Idea
A tool for automated CRA vulnerability notifications to simplify the compliance process starting in 2026.
- Reference: https://www.twitch.tv/helsec
Homework reference
- Homework reports for security course taught by Tero Karvinen
- Reference: https://terokarvinen.com/trust-to-blockchain/
Related Documents
Design Document: BharatSeva AI
BharatSeva AI is a multi-agent orchestration system built on AWS using Amazon Bedrock Agents with Claude 3.5 Sonnet as the foundation model. The system deploys 10 AI agents (1 Master Orchestrator + 9 Specialist Agents) to assist India's informal sector workers in navigating government schemes across three domains: PM Vishwakarma (artisan credit), PMFBY (crop insurance), and BOCW (construction worker welfare).
OpenClaw Enterprise Transformation Plan
Transform OpenClaw from a single-user personal AI assistant into a **dual-mode platform** that is simultaneously:
Qwen Image and Edit: Open-sourcing and Local GGUF Generations with Lightning
Daniel Sandner, for article on https://sandner.art/
Qwen3-TTS — Model Reference
Models: `Qwen/Qwen3-TTS-12Hz-0.6B-CustomVoice` and `Qwen/Qwen3-TTS-12Hz-1.7B-CustomVoice`