Insights
Notes on building compliant, secure products
Practical writing on the Cyber Resilience Act, IEC 62443-4-1, and the engineering practices that turn a compliance obligation into a defensible product. New articles are added over time.
- AI & the secure SDLC
Let AI write your IEC 62443-4-1 SDLC documentation — and keep it true to the code
Turn IEC 62443-4-1 into a machine-readable policy, keep it in Git next to the code, and let AI generate SDLC documentation that tracks every change. Done with human review and CI, it makes CRA-grade evidence a byproduct of development.
Read the article7 min read - Vulnerability management
Why vulnerability management is the engine of a secure-by-design product
Secure by design and secure by default are not one-time design decisions — they are claims you have to keep true for years. Vulnerability management is the process that keeps them true, and it is where IEC 62443-4-1 and the CRA both point.
Read the article6 min read
Get in touch
Want help putting any of this into practice?
These notes are the short version. If a topic here maps onto a problem you are actually facing, tell us what you build and where you are in the process — we will come back with where we would start.
We reply within two working days.
Full contact detailsWorth including in a first message
- What the product is, and whether it contains software or connects to a network.
- Which markets you sell into, and your role — manufacturer, importer, or distributor.
- Any date you are working towards — a launch, an audit, or a customer deadline.
Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.