Insights
Notes on building compliant, secure products
Practical writing on the Cyber Resilience Act, IEC 62443-4-1, and the engineering practices that turn a compliance obligation into a defensible product. New articles are added over time.
- Security management
What I keep noticing about secure development: it works when interest meets expertise
After enough years around development teams, I have stopped believing that tools decide whether a secure SDLC works. The teams that got there all had the same thing at the base — the right people, genuinely interested, actually equipped. IEC 62443-4-1 names that base as SM-2 and SM-4, and I think the standard is quietly right about it.
Read the article5 min read - AI & the secure SDLC
Let AI write your IEC 62443-4-1 SDLC documentation — and keep it true to the code
A reflection on why hand-written SDLC documentation always drifts, and what changed for the teams I watched solve it: write their own SDLC policy against IEC 62443-4-1 in a machine-readable form, keep it beside the code, and let AI generate the evidence under human review.
Read the article7 min read - Vulnerability management
Why vulnerability management is the engine of a secure-by-design product
A reflection on why "secure by design" never lasted on its own in the teams I worked with — and why vulnerability management, the least glamorous practice in IEC 62443-4-1, is the one that decided whether a product stayed defensible.
Read the article6 min read
Get in touch
Want help putting any of this into practice?
These notes are the short version. If a topic here maps onto a problem you are actually facing, tell us what you build and where you are in the process — we will come back with where we would start.
We reply within two working days.
Full contact detailsOpens our scheduling page in a new tab — pick a slot that suits you.
Worth including in a first message
- What the product is, and whether it contains software or connects to a network.
- Which markets you sell into, and your role — manufacturer, importer, or distributor.
- Any date you are working towards — a launch, an audit, or a customer deadline.
Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.