How to address cybersecurity in industry?

18. 7. 2025


Cybersecurity in the industrial sector must be approached comprehensively—both at the organizational infrastructure level (IT/OT systems) and at the product level for items placed on the market.

It’s essential to distinguish between security management systems (e.g., ISO/IEC 27001 or the new Cybersecurity Act based on NIS2), which apply solely to organizations and their processes. These systems, however, do not demonstrate or prove the security of specific products!

Ensuring product security, especially those with digital elements, requires:

  • Secure development (ideally according to IEC 62443-4-1)

  • Vulnerability testing (e.g., IEC 62443-4-2 and EN 18031)

  • Assessment of product compliance with legal requirements (particularly CRA and RED)

  • Preparation of technical documentation and CE marking (for RED)

  • CB certificates for IEC 62443-4-1 and IEC 62443-4-2 (globally recognized)

EZÚ offers both organizational and product-related services and helps manufacturers and suppliers manage the full lifecycle of cybersecurity—from initial GAP analysis, tailored training, and pre-assessments to successful certification.