Marko Kaasila Marko Kaasila

Secure by default: CRA's baseline security expectations

Blog #5 in our Human Written CRA expert series: The EU Cyber Resilience Act flips security responsibility onto manufacturers. Learn what “secure by default” really demands for configurations, updates, features, and data collection.

Read More
Marko Kaasila Marko Kaasila

Software Bill Of Materials (SBOM)

Blog #4 in our Human Written CRA expert series: What's actually running in your product? Most teams don't know. Learn how to generate an SBOM — from source code to binaries — and why the CRA requires it.

Read More
Marko Kaasila Marko Kaasila

No Known Exploitable Vulnerabilities

Blog #3 in our Human Written CRA expert series: What “no known exploitable vulnerabilities” actually means under the CRA—and how SBOMs, risk assessment, and automation help you meet the new security and reporting duties.

Read More
Marko Kaasila Marko Kaasila

CRA risk assessment

Blog #2 in our Human Written CRA expert series: Turn CRA’s abstract risk assessment requirement into a concrete, 3‑step process: define scope, identify assets, and prioritize risks by likelihood and impact to guide secure product design.

Read More
Compliance Marko Kaasila Compliance Marko Kaasila

The CRA and Your Backend: When the Cloud Platform Becomes Part of the Product

The EU Cyber Resilience Act doesn't just regulate IoT hardware—it includes your backend too. Learn when cloud platforms become part of your product and what compliance requirements you must meet.

Test of Things is end-to-end connected system cybersecurity compliance and testing platform covering devices, back-ends and for example mobile applications.
Stay compliant continuously and ship with confidence.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Scaling Security: How Automation Makes it Possible to Manage 10+ Device Variants and Updates Securely

The core challenge? Scaling security to match your product's complexity.

If your team is still relying on manual, point-in-time penetration testing, every new product variant, every minor firmware update, and every regional configuration change adds exponential overhead. This leads to a dangerous trade-off: compromising on the depth or frequency of testing to meet tight launch deadlines.

Read More