From 11 September the clock is running. And it runs for 24 hours.

Gap analysis, cyber risk assessment, incident response team and process for a machinery and plant manufacturer — including a tabletop exercise for the real thing.

Symbolic image: three people stand in a meeting room in the evening in front of a wall screen showing charts and dashboards; a laptop and technical drawings lie on the table, a clock hangs on the wall, and an illuminated industrial plant is visible through the window.
Image: AI-generated
Client
anonymised
Industry
Machinery and plant engineering, DACH region
Period
April to September 2026
Framework
Regulation (EU) 2024/2847, aligned with IEC 62443
  • Gap analysis
  • Cyber risk assessment
  • Incident response team
  • SecDev/SecDevOps
  • Tabletop exercise

Starting point

Anyone placing connected products on the market falls under the Cyber Resilience Act. From 11 September 2026 the reporting obligations of Article 14 apply: actively exploited vulnerabilities and severe security incidents must be reported to the responsible CSIRT and to ENISA at the same time — in stages, with very short deadlines.

  1. 24 h Early warning to the CSIRT and ENISA via the Single Reporting Platform
  2. 72 h Detailed report: product affected, nature of the exploitation, measures taken
  3. 14 days Final report once the fix is available; one month in the case of security incidents

Approach

First a gap analysis against the requirements of the regulation: which products are affected, what is missing in terms of structures, processes and evidence. On top of that a cyber risk assessment on a real plant project rather than a textbook example — risks, impacts, measures, documented and repeatable. The gaps became an action plan with owners and deadlines.

Able to report within 24 hours

Setting up an incident response team with named roles, availability and decision-making authority — plus the process behind it: from the incoming report through assessment to reporting on time. The initial assessment of whether a report is relevant at all can be supported by AI — around the clock, without an on-call rota at first contact.

Security in development

SecDev and SecDevOps: security requirements from the risk assessment move into development, dependencies and the supply chain become traceable, vulnerability management runs across the entire support period instead of stopping at delivery.

The real thing, rehearsed once

To conclude, a tabletop exercise: an actively exploited vulnerability, reported on a Friday afternoon. That is exactly where a process on paper shows what it cannot show otherwise — who is reachable, who is allowed to decide, when the clock starts running and how customers are informed while no fix is available yet. The gaps from the exercise went back into the process before they would have surfaced in a real incident.

Whether an incoming report is relevant at all can be pre-assessed by AI today — around the clock, without an on-call rota. The team still has to respond: deciding, reporting and fixing stay with people who have the authority.
Christoph RanalterRaDigSol e.U.