Marko Kaasila Marko Kaasila

Software Bill Of Materials (SBOM)

What's actually running in your product? Most teams don't know. Learn how to generate an SBOM — from source code to binaries — and why the CRA requires it.

Read More
Marko Kaasila Marko Kaasila

No Known Exploitable Vulnerabilities

What “no known exploitable vulnerabilities” actually means under the CRA—and how SBOMs, risk assessment, and automation help you meet the new security and reporting duties.

Read More
Marko Kaasila Marko Kaasila

CRA risk assessment

Turn CRA’s abstract risk assessment requirement into a concrete, 3‑step process: define scope, identify assets, and prioritize risks by likelihood and impact to guide secure product design.

Read More
Compliance Marko Kaasila Compliance Marko Kaasila

The CRA and Your Backend: When the Cloud Platform Becomes Part of the Product

The EU Cyber Resilience Act doesn't just regulate IoT hardware—it includes your backend too. Learn when cloud platforms become part of your product and what compliance requirements you must meet.

Test of Things is end-to-end connected system cybersecurity compliance and testing platform covering devices, back-ends and for example mobile applications.
Stay compliant continuously and ship with confidence.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Scaling Security: How Automation Makes it Possible to Manage 10+ Device Variants and Updates Securely

The core challenge? Scaling security to match your product's complexity.

If your team is still relying on manual, point-in-time penetration testing, every new product variant, every minor firmware update, and every regional configuration change adds exponential overhead. This leads to a dangerous trade-off: compromising on the depth or frequency of testing to meet tight launch deadlines.

Read More
Compliance Automation Marko Kaasila Compliance Automation Marko Kaasila

Beyond the Checklist: Why Automated Testing is a Game-Changer for IEC 62443-4-2 Compliance

For Product and Engineering Managers in IoT manufacturing, navigating the complex landscape of cybersecurity compliance is a constant challenge. Among the most asked standards, IEC 62443-4-2 stands out, defining technical security requirements for control system components.

Read this post how to transform compliance from a reactive, laborious process into a proactive, efficient, and deeply integrated part of your development lifecycle.

Read More
Compliance Marko Kaasila Compliance Marko Kaasila

The EU RED Countdown: 4 Things You Must Do Now to be Prepared

Compliance officers at IoT device manufacturing organizations must act immediately to prepare for the EU Radio Equipment Directive (RED) and its new cybersecurity requirements, which became mandatory on August 1, 2025. The new EN 18031 series of standards provides the framework for demonstrating compliance. A successful strategy focuses on proactive integration of these requirements into the product lifecycle.

Read More