Safety from the beginning, not at the last minute

It is becoming increasingly difficult to separate our daily lives from digital systems. The boiler that will warm your home tonight, the hospital monitor or the plant that produces your food: everyone works through software and connected devices. And the same goes for our critical infrastructures, from energy and water to transport. Therefore, digital security is not a computer problem: it is part of the functioning of our economy, services and society.

A chain is said to be as strong as its weakest link. It is also true in the digital world: a single sensor, device, software component or unprotected supplier can become the gateway to an entire system. The danger comes not only from criminals: digital infrastructures are also part of hybrid conflicts between states. The attack that stops such a system does not create a “computer problem”; it creates a business, service and social problem.

“Digital security is not a computer problem: it is part of the functioning of our economy, services and society.”

In this context, the European Cyber Resilience Act represents an important change of course. From September 11, manufacturers will have to report vulnerabilities and serious incidents that have been actively exploited; and from the end of 2027, products with digital elements such as sensors, connected devices, industrial equipment, software or their components will have to meet more stringent cybersecurity requirements to be commercialized.

The idea is simple, but deep: safety cannot be attached to the product at the end. From its design, it must be taken into account in its development and throughout its life cycle. It is not enough to protect the system at the end; safety must be incorporated into products and components from the beginning. And there’s the real cultural change: cybersecurity isn’t just about the IT department. The mechanical, electronic or automation engineer who designs the product must also assume this responsibility, as well as its quality or reliability.

“Does your product comply with the Cyber Resilience Act?”

This path, of course, has a cost: it requires resources, time and knowledge, and its value is often not seen until something fails. But the savings in this do not only reduce an expense, but also increase the risk of one day running out of production lines. Increasingly, cybersecurity is no longer a mere measure of protection, but a condition for an industrial product to compete in the market and gain the trust of its customers. A company that exports a machine tool will increasingly hear the question: “and does your product comply with the Cyber Resilience Act?” If you do not comply, what is at stake is not simply compliance with the regulations, but obtaining the contract.

In the Basque Country we have a solid foundation for this: technological centres specialising in cybersecurity and a critical mass of more than 90 researchers. But having the ability is not enough. The challenge is to integrate this knowledge into products, machines, processes and services from the beginning.

And here comes the question that concerns us all: how long are we going to act as if digital security were a “computer issue”? Until the weakest link stops the whole system?

Buletina

Bidali zure helbide elektronikoa eta jaso asteroko buletina zure sarrera-ontzian

Bidali

Bizitza