On July 27, 2026, the European Commission published its most substantial guidance yet on applying the EU Cyber Resilience Act (CRA). The guidance helps manufacturers, developers, and businesses of all sizes by working through questions that have caused the most...
On July 29, 2026, CISA and a coalition of international cybersecurity agencies published the 2026 Minimum Elements for a Software Bill of Materials (SBOM)—the first full update to the baseline the National Telecommunications and Information Administration (NTIA)...
The first major Cyber Resilience Act (CRA) deadline is nearly here. Beginning September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements. The broader CRA requirements become...
Key takeaways Compliance is only a starting point. At scale, training and audits can’t outpace the threat. Know what you have first. Inventory the enterprise, then secure the top missions. Manage as an enterprise. One consolidated Cisco contract saved ~$300M and...
Key takeaways Automotive compliance is usually captured as a snapshot at release or audit time, but resilience is a culture sustained across the full lifecycle and into incident response. Traceability tends to break first because it feels like paperwork, and the cost...
Modern vehicles are built on layers of software that few teams fully control and even fewer can fully see. Between supplier-delivered components, open source dependencies, and long product lifecycles, gaining a clear, reliable view of what’s actually in a vehicle—and...