Impulse Offer

IoT

With an exponential growth in the number of interconnected devices expected to reach around 75 billion units by 2025, online security is becoming an increasingly pressing concern for players operating in the IoT area. To deal with this phenomenon, on September 15th 2022, the European Commission introduced ground-breaking legislation in Europe, called the “Cyber Resilience Act” (CRA). This regulatory proposal aims to consolidate digital security for items containing digital elements, thus marking a significant step in the ever-changing landscape of cybersecurity.

Zoom-in on the Cyber Resilience Act and what it will change in IoT projects.

 

What is the Cyber Resilience Act (CRA)?

 

Speaker_YannickGaudin

“The Cyber Resilience Act (CRA) provides a common regulatory framework for Member States to fight the increasing number of cyberattacks to which connected devices are victim, so as to make business players responsible for the cybersecurity of the products they offer on the European market.”

Yannick Gaudin
Security Architect, LACROIX

Complying with the key points

  1. IoT data security requirements

In the interconnected world of IoT, the collection and processing of personal and sensitive data has become commonplace. However, the Cyber Resilience Act highlights the need to protect this data from unauthorized access.

The consequences of a data breach can be devastating, leading not only to financial damage, but also to a loss of customer trust. To meet these requirements, it is essential to apply robust security measures and ensure appropriate data management.

 

  1. Cybersecurity standards for IoT devices

The CRA emphasizes the importance of designing secure IoT devices right from their very creation (referred to as “secure-by-design”). The recommended cybersecurity standards are intended to ensure that devices are protected against potential vulnerabilities and flaws.

Integrating security at an early stage in the development process is fundamental to avoiding costly security gaps and ensuring compliance with the requirements of the Cyber Resilience Act. This proactive approach reduces the risks and lays a strong foundation for IoT projects.

 

  1. Vulnerability and incident management

Continuous vulnerability monitoring and responding rapidly to security incidents are central elements of this regulation. Businesses must be able to quickly identify and correct security flaws to minimize potential damage.

Effective incident response requires well-defined processes and collaboration between technical teams and stakeholders.

Anticipating the implementation of the Cyber Resilience Act

Expert in electronics design and specialised in IoT solutions, LACROIX supports its customers each step on the way to develop their IoT projects.

In order to be compliant with the Cyber Resilience Act, IoT players are required to meet several criteria. And LACROIX is the perfect partner to ensure that all 5 of these key points are fulfilled:

Secure by design

  • Technical framework: architecture, cryptography, secure enclave, etc.
  • Processes: product lifecycle, crisis management, R&D best practices, etc.

Risk & threat analysis model, with cyclical examination

Vulnerability Disclosure Policy (VDP)

  • CVE tracker in place, with teams organized around it
  • Communication channel to inform your customers
  • Mitigation/resolution actions triggered promptly

Large-scale updates at any time

  • Your product’s firmware
  • Secrets-rotation ready

Free security patches

  • All throughout the product’s life cycle (minimum of 5 years)

A close-up of the PizzaIoT conference on the Cyber Resilience Act

To find out more about the CRA and its impacts on IoT projects, LACROIX held a PizzaIoT conference in the heart of Paris on Tuesday 23rd 2023.

What is the concept behind PizzaIoT? An afterwork event, where we talk about IoT, while tucking into some pizza!

  • What is at stake with this regulation and how does it impact IoT products?
  • What should companies do to get ready?
  • What are the recommendations for players such as LACROIX, Provenrun and Kereval to support the deployment of this standard, from design through to maintenance and including validation?
  • Standards evolution, electronic design, technological building blocks, design validation, security vulnerability and certificate management, firmware updates, IoT platforms and beyond: where do we stand today in terms of these aspects?

These were the main topics addressed at the conference hosted by three key speakers from the world of IoT: LACROIX, ProvenRun (software publisher for Internet of Things security) and Kereval (software test engineering laboratory).

Some thirty participants gathered to take part in the conference, which continued with a networking session dedicated to IoT, all over a pizza in the splendid setting of Bpifrance.

➡️ WATCH THE VIDEO OF THE CONFERENCE

If you are interested in the subject of IoT development, you can also find out what happened at the previous PizzaIoT conference: Zephyr OS in all its states.

More stories

Case study

Supporting and securing the transition to soft mobility: what solutions?

LACROIX Environment

Case study

Increase users' well-being of the co-ownerships association Les Contamines-Montjoie

LACROIX Environment

Case study

LACROIX City and Villefranche-sur-Saône Get ready for tomorrow's lighting challenge

LACROIX Environment

Case study

Lighting Management for the Stadiums by LACROIX City

LACROIX Environment

Case study

Commune of Troistorrents rolls out intelligent and progressive street lighting solution

LACROIX Environment

Explained

Relocating your electronics production to Tunisia: the advantages you need to know

LACROIX Electronics 5 min

Matter: everything you need to know about this protocol that could change the connected home industry

Impulse Offer

Electronic design: why an integrated design center can help you better develop your product

Impulse Offer

Case study

Pau, FRANCE : uncompromising lighting management : savings and quality of service

LACROIX City

Electronic Design: A Winning Strategy to Accelerate Your Project Development

Impulse Offer

Case study

Grau-du-Roi tourist site: intelligent access management

LACROIX City

Explained

Revolutionizing Smart Cities with AIoT: LACROIX and STMicroelectronics Unveil Innovative EdgeAI Technology powered by AWS re:Invent 2023

LACROIX Electronics

Explained

3 good reasons to relocate your electronic production close to your customers

LACROIX Electronics 5 min

A successful IoT project: from CSR strategy to product development

Impulse Offer

Smart water management: optimization and efficiency for sustainable urban supply

Impulse Offer

Explained

Connected devices: are they of any help in dealing with societal issues?

LACROIX 3 minutes

Cobots: Man’s new ally ?

LACROIX Electronics

3 tips for reshoring through automation

LACROIX Electronics

Explained

Supporting and securing the transition to soft mobility: what solutions?

LACROIX City

Case study

Traffic peaks on the Ile de Ré: Intelligent, dynamic and automated regulation

LACROIX City

Case study

Reykjavik : Outdoor lighting and the northern lights, cohabitation made possible...

LACROIX City