Marko Kaasila Marko Kaasila

Software Bill Of Materials (SBOM)

What's actually running in your product? Most teams don't know. Learn how to generate an SBOM — from source code to binaries — and why the CRA requires it.

Read More
Marko Kaasila Marko Kaasila

No Known Exploitable Vulnerabilities

What “no known exploitable vulnerabilities” actually means under the CRA—and how SBOMs, risk assessment, and automation help you meet the new security and reporting duties.

Read More
Marko Kaasila Marko Kaasila

CRA risk assessment

Turn CRA’s abstract risk assessment requirement into a concrete, 3‑step process: define scope, identify assets, and prioritize risks by likelihood and impact to guide secure product design.

Read More
Compliance Marko Kaasila Compliance Marko Kaasila

The CRA and Your Backend: When the Cloud Platform Becomes Part of the Product

The EU Cyber Resilience Act doesn't just regulate IoT hardware—it includes your backend too. Learn when cloud platforms become part of your product and what compliance requirements you must meet.

Test of Things is end-to-end connected system cybersecurity compliance and testing platform covering devices, back-ends and for example mobile applications.
Stay compliant continuously and ship with confidence.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Scaling Security: How Automation Makes it Possible to Manage 10+ Device Variants and Updates Securely

The core challenge? Scaling security to match your product's complexity.

If your team is still relying on manual, point-in-time penetration testing, every new product variant, every minor firmware update, and every regional configuration change adds exponential overhead. This leads to a dangerous trade-off: compromising on the depth or frequency of testing to meet tight launch deadlines.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Beyond the Checklist: Why Automated Testing is a Game-Changer for IEC 62443-4-2 Compliance

For Product and Engineering Managers in IoT manufacturing, navigating the complex landscape of cybersecurity compliance is a constant challenge. Among the most asked standards, IEC 62443-4-2 stands out, defining technical security requirements for control system components.

Read this post how to transform compliance from a reactive, laborious process into a proactive, efficient, and deeply integrated part of your development lifecycle.

Read More