Product Security

We support our client with code/design reviews, implmentation of security requirements, and security testing.

Why Product Security Matters?

Securing Products from Design to End-of-Life

Product security focuses on ensuring the safety of a product from its initial design and development phases through to its end-of-life (EOL). With the increasing reliance on connected devices such as vehicles, smartphones, IoT, and critical infrastructure systems, security becomes crucial. These devices often operate in non-trusted environments and, if compromised, can be used to launch attacks or facilitate coordinated cyber threats like DDoS attacks. To mitigate these risks, security must be integrated into every stage of product development and implementation, as well as continous monitoring and regular testing during the operational phase.


Automotive

Cybersecurity has been a hot topic over the past few years as hackers continue to find ways to exploit vulnerabilities within vehicles. As automakers begin to implement vehicle-to-everything (V2X) communication systems, they also face challenges with cybersecurity. The V2X technology allows cars to communicate with each other, as well as with surrounding environment and exchange information, without human intervention. This type of system could potentially save lives when used properly; however, there are risks involved.

EV Charging

As electric vehicle (EV) adoption accelerates, the cybersecurity of EV charging infrastructure becomes increasingly critical, particularly given the integration of communication protocols like ISO 15118 and OCPP 2.0.1. ISO 15118 enables secure, automated communication between EVs and charging stations, supporting features like Plug & Charge and encrypted identification, while OCPP 2.0.1 facilitates backend interoperability between charging stations and management systems. Both frameworks rely heavily on robust cryptographic mechanisms to ensure authentication, data integrity, and confidentiality.

Internet of Things (IoT) & Industrial Control Systems (ICS)

Securing the Internet of Things (IoT) and industrial automation systems is essential as these technologies become integral to critical infrastructure and manufacturing processes. The ETSI EN 303 645, EN 18031, EN 17927 and ISO/IEC 27402 standards focus on the security requirements of IoT devices, providing a foundation for assessing vulnerabilities and ensuring compliance with recognized protection profiles.
Complementing this, the ISA/IEC 62443 framework offers a comprehensive approach to industrial cybersecurity, addressing system architecture, risk assessment, and security lifecycle management.
These frameworks highlight the need for layered defense strategies, secure device provisioning, and continuous monitoring to mitigate threats such as malware propagation, unauthorized control access, and data exfiltration.


Cyris360 BV - KVK 90766229 - All rights reserverd - 2025