Product Cyber Security

Holistic product security in your organisation

Your expert for questions

Dr. Oliver Hanka ist Partner bei PwC Deutschland

Dr. Oliver Hanka
Partner at PwC Germany
Tel: +49 160 5105836
Email

Why the importance of product cyber security continues to grow

Products with digital elements and IoT (Internet of Things) - devices have become the norm in industrial companies and everyday life. Whether smart home devices, production facilities or logistics systems: many products are connected to the internet or other networks, which enhances their functionality but also offers attack surfaces for cyber criminals and other malicious actors.

The complex, unique architecture of each individual product and other factors, such as scarce computing power and memory, make it difficult to implement security measures. The variety of devices and protocols, combined with their longevity and often lack of security updates, increases the risk of security vulnerabilities. In addition, they often have to interact with other systems and devices, which can open up additional security gaps. Embedded software in IoT devices is difficult to update and many of these devices collect personal data, making them attractive targets for attacks.

Successfully exploiting a vulnerability in a product may enable further malicious actions, such as circumventing a pay-per-use rule and activating a chargeable function. Intellectual property may also be at risk, as is a backend server communicating with a compromised product, potentially enabling access into a corporate network. In such a way, a compromised product not only damages a company's image, but may also lead to financial losses or even a danger to human life (functional safety and security).

To address such issues in a holistic manner, the EU introduced the Cyber Resilience Act (CRA). It ensures that all products with digital elements offered in the EU market will meet strict security requirements. 

“According to a survey, on average only 28% of a product’s vulnerabilities are recognised by the manufacturer itself. In order to meet upcoming regulations and customer requirements, the top priority must be to secure your own products against the changed threat landscape.”

Dr. Oliver Hanka,Partner at PwC Germany

What we stand for

Technical expertise

Our team consists of technical experts with a background in engineering and information technology. We implement state-of-the-art requirements on a daily basis and review the implementation with certified pentesters.

Industry-wide expertise

Customers from various industries such as mechanical and plant engineering, automotive, as well as energy and chemicals rely on our experience. We bring both technical and procedural know-how to the table and work together with you to integrate product cyber security into your company.

Current standards and regulations

We support the identification and fulfilment of relevant industry-specific regulations, such as the CRA and the UK Product Security and Telecommunications Infrastructure Act. Depending on individual customer requirements, we draw on applicable standards such as IEC 62443, ISO 27001, ISO 21434, Common Criteria and ETSI and utilise synergies between them.

Holistic approach

Various specialist domains from our PwC network ensure a holistic view of product security in your company – from cyber security to the product life cycle to organisational development. We focus on interfaces and commonalities in IT, OT and product cyber security to ensure an efficient corporate organisation.

Our services in product cyber security

Establish product cyber security holistically in your company with a product cyber security management system.

Integrate technical and procedural security measures into your product life cycle.

Identify vulnerabilities and check whether your product offers attack surfaces for hackers.

Identify applicable laws and regulations, such as the CRA, for your products and evaluate the current maturity level for the relevant processes.

Get support for the successful integration of product cyber security in your company.

Identify threats to your products, assess risks and derive specific measures.

< Back

< Back
[+] Read More

Any questions?

Contact us

How do you protect your products and your customers?

Integrate product cyber security in your organisation along the entire product life cycle. Depending on the measures already in place and your security expertise, two approaches have proven successful, particularly in the initial stages of product cyber security:

As part of a gap assessment, the current maturity level of product cyber security can be determined based on best practices and standards, such as IEC 62443 and ISO 21434.

Regulation checks can be used to identify relevant laws for your organisation with regard to product cyber security. 

Both the gap assessment and the regulation check lay the foundation for defining a detailed roadmap to plan which specific tasks should be implemented in the future, when integrating product cyber security along the entire product life cycle.

Infografik: Secure Product Development

In order to identify all potential risks within your product, a technical Threat and Risk Analysis (TRA) can be carried out and risk-based measures can be derived. The effects of individual exploited risks are highlighted during pentesting (part of security testing) and errors in the implementation are uncovered. Vulnerability assessments can be carried out to identify current vulnerabilities in your products. These are recurring activities that we are happy to integrate into your product life cycle as a managed service.

We support you in the procedural and technical implementation of security measures along the product life cycle – from the concept through development and commissioning to the end of life – and are guided by best practices and common development models such as the V-model. By developing a technical proof of concept, we demonstrate the effectiveness and compatibility of the proposed measures.

The Product Cyber Security Management System (PSMS) defines the framework for product security. This effectively and efficiently controls and regulates the handling of product cyber security and defines roles and responsibilities in your organisation. As part of this, interfaces are identified and communication and integration into other management systems are defined.

To integrate product cyber security holistically, it is also important in the long term to address supporting processes such as the supply chain management for products and protect them against cyber-attacks.

New EU regulation: The Cyber Resilience Act

The EU has recognised the major threat for users and manufacturers and adopted the Cyber Resilience Act (CRA). In the event of a violation or non-conformity with product cyber security requirements, the manufacturers are subject to penalties of up to 2.5% of the total annual global turnover of the previous financial year or €15 million. Are you prepared?

Find out more

“Following several regulations that affect the operation of infrastructure, the EU is now also addressing product manufacturers. Many companies are overwhelmed by the CRA. High time to take action.”

Siri Sophia Oberpottkamp,Senior Manager at PwC Germany
Follow us

Contact us

Dr Oliver Hanka

Dr Oliver Hanka

Partner, Cyber Security & Privacy, PwC Germany

Tel: +49 160 5105836

Siri Sophia Oberpottkamp

Siri Sophia Oberpottkamp

Senior Manager, Cyber Security & Privacy, PwC Germany

Tel: +49 1516 4500068

Hide