-
Continue reading →: Beyond Delivery: How CRA Article 14 Is Reshaping Cybersecurity Partnerships in Europe’s Energy Sector1. Introduction: incident response becomes a routine obligation For most of the last decade, a cybersecurity incident in a distributed renewable generation or storage asset was handled as a one-off. Something broke, an engineer investigated, a support ticket closed. Major installations have long run structured return of experience; fleets of…
-
Continue reading →: Cybersecurity Risk in Energy Infrastructure: Why Labels Are Not a Substitute for Technical AssessmentThe energy sector is changing quickly. Solar plants, battery energy storage systems, hybrid renewable projects, grid-connected inverters, monitoring gateways, energy management platforms, and cloud-connected maintenance tools are now part of critical digital infrastructure. What used to be mostly electrical engineering is now also software engineering, communications engineering, and cybersecurity engineering.…
-
Continue reading →: Connected or Disconnected? Cybersecurity Responsibility in Energy InfrastructureI. Introduction For a long time, a power plant was something you could touch. You fenced it, locked it, and posted guards around it. That world is gone. Energy infrastructure is now digital infrastructure. Solar inverters, battery controllers, substations and industrial controllers sit on networks, take instructions remotely, and receive…
-
Continue reading →: The Speed of Trust: Why Europe’s Defenders Need Faster Collaboration, Not Just Faster Rules
Authors: Ali Khalil, Ayman Khalil A recent companion analysis on this publication argued that artificial intelligence did not create the buried flaws in the world’s software; it simply made them cheap to dig up. That observation reframes the entire defensive challenge. For most of the history of product security, the…
-
Continue reading →: Cybersecurity Must Not Become a Tool of Industrial Protectionism: Reassessing the European Debate Around Foreign Solar InvertersIntroduction Today, Europe has never produced so much solar energy. In the first quarter of 2025, solar electricity production across the European continent increased by 32% compared to the same period in 2024, reaching nearly 68 terawatt-hours. Over the full year 2025, solar accounted for a record 13% of the…
-
Continue reading →: DORA’s Legislative Breakthrough: How TLPT and Advanced Testing Are Redefining Financial Sector ResilienceAuthor: Romain Muguet 1. Introduction: A Regulation Born from Necessity The financial sector remains a high-value target for cybercriminals, hacktivists and state-aligned actors, with attacks growing in both sophistication and frequency. Data from ENISA’s 2025 Threat Landscape Report, released in October 2025, underscores the sector’s persistent exposure: out of 4,875…
-
Continue reading →: SBOM Is Not Enough: Supply Chain Transparency in the Age of AI-Driven ExploitationAuthor: Paul Gedeon Supply chain security has become a question of visibility before it is a question of control. Modern organizations rarely buy a single product from a single supplier. They buy systems assembled by integrators, built on third-party libraries, cloud services, firmware, subcontracted components, and open-source projects maintained by…
-
Continue reading →: As a European Security Expert, I Am More Concerned About Politicized Procurement Than About Vendor NationalityI work in security, so I understand why people are nervous about critical infrastructure. Energy systems are not ordinary commercial assets. If something goes wrong, the consequences are not limited to a delayed software release or a bad quarterly report. They can affect hospitals, transport, industry, households, public services, and…
-
Continue reading →: Certification Is Not the Finish Line: What Happens After a Product Gets Approved?Authors: Ayman Khalil & Romain Muguet Why EUCC certification increasingly depends on what happens after the certification ends European cybersecurity certification is shifting toward operational concerns. Previously, discussions centered on frameworks, recognition, and regulatory alignment. While this initial certification is now well-established, attention is increasingly focused on the subsequent phase:…
-
Continue reading →: AI Vulnerability Discovery Just Changed the Clock Speed of Product SecurityAuthor: Paul Gedeon Anthropic’s Project Glasswing should not be read as another impressive AI demo. It should be read as a warning about time. According to Anthropic and reporting from TechCrunch, Claude Mythos Preview, a restricted frontier model used by a small group of partner organizations, identified thousands of zero-day…
