Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Scaling Security: How Automation Makes it Possible to Manage 10+ Device Variants and Updates Securely

The core challenge? Scaling security to match your product's complexity.

If your team is still relying on manual, point-in-time penetration testing, every new product variant, every minor firmware update, and every regional configuration change adds exponential overhead. This leads to a dangerous trade-off: compromising on the depth or frequency of testing to meet tight launch deadlines.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Beyond the Checklist: Why Automated Testing is a Game-Changer for IEC 62443-4-2 Compliance

For Product and Engineering Managers in IoT manufacturing, navigating the complex landscape of cybersecurity compliance is a constant challenge. Among the most asked standards, IEC 62443-4-2 stands out, defining technical security requirements for control system components.

Read this post how to transform compliance from a reactive, laborious process into a proactive, efficient, and deeply integrated part of your development lifecycle.

Read More
Compliance Marko Kaasila Compliance Marko Kaasila

The EU RED Countdown: 4 Things You Must Do Now to be Prepared

Compliance officers at IoT device manufacturing organizations must act immediately to prepare for the EU Radio Equipment Directive (RED) and its new cybersecurity requirements, which became mandatory on August 1, 2025. The new EN 18031 series of standards provides the framework for demonstrating compliance. A successful strategy focuses on proactive integration of these requirements into the product lifecycle.

Read More
Regulation Marko Kaasila Regulation Marko Kaasila

The Clock Just Ran Out: IoT Compliance Is Now Law in Europe

The alarm clock rang on August 1st, 2025, and everything changed. Europe's IoT compliance shifted from voluntary to mandatory overnight. With RED requirements now enforced and CRA coming in 2027, IoT manufacturers face a new reality: get compliant or lose market access. Discover why smart companies are turning compliance challenges into competitive advantages.

Read More
Business Marko Kaasila Business Marko Kaasila

Test of Things development is co-funded by EU

The European Union has taken decisive action to address cybersecurity issues by introducing new regulations like the Radio Equipment Directive (RED) and the Cyber Resilience Act (CRA). We are proud to be supported by the European Union in developing our innovative technology further.

The goal is to develop a product prototype that is easy to use and allows users to self-assess their product’s compliance with the security standards and regulations. The grant empowers us to further our mission of protecting customers and society from cyber incidents by making IoT cybersecurity testing easy and automated. 

Read More
SBOM Rauli Kaksonen SBOM Rauli Kaksonen

The ‘S’ in SBOM Isn’t for Security

Software Bill Of Materials (SBOM) is hailed as the solution to managing cybersecurity. It brings transparency to the used software components and allows you to check if published vulnerabilities may be present in your system. This is great, but SBOM leaves many aspects of product security unaddressed.

Read More
Hiring Rauli Kaksonen Hiring Rauli Kaksonen

Summer of Things - Test of Things summer Internships 2025

Summer of Things

At Test of Things, we are building the future platform for securing the Internet of Things. We are looking for two interns for the summer 2025. Trainers would work in the R&D team on tasks like security assessment of IoT devices, development of security testing tools, participation in evaluation projects, and working with our open-source platform Toolsaf (https://github.com/testofthings/toolsaf).

Read More
Regulation Marko Kaasila Regulation Marko Kaasila

Decoding Cybersecurity: EN 18031 vs. the EU Cyber Resilience Act

The world of connected devices is booming, and the critical need for robust cybersecurity comes with it.  Two key players in this arena are EN 18031 (Radio Equipment Directive (RED)) and the EU Cyber Resilience Act (CRA).  While both aim to improve the security of our digital lives, they approach the challenge from different angles.  Let's break down the key differences and explore how they relate.

Read More
Rauli Kaksonen Rauli Kaksonen

Security statements for machine-readable cybersecurity posture

Security statement is a machine readable description of system’s security characteristics, like network nodes (devices, gateways, applications and servers), network interfaces (ports and services), connections between the network nodes and services, web interfaces, authentication methods, SBOMs data encryption at rest (and in transit) and so on.

Once those have been defined, one can test and verify it.

Read More
Marko Kaasila Marko Kaasila

EU Cyber Resilience Act (CRA): Vulnerability handling requirements

Tackling vulnerabilities is at the top of the CRA’s priority list. Device manufacturers and developers will need to offer customers support for the expected product lifetime or five years, whichever is shorter. During that period manufacturers are obliged to address and correct security flaws promptly.

Read More