Summary is AI-generated, newsdesk-reviewed
  • Genetec advises on vendor evaluation amid EU Cyber Resilience Act cybersecurity requirements.
  • EU Cyber Resilience Act stresses secure product lifecycle, affecting manufacturers and security leaders.
  • Safe deployment needs cybersecurity transparency; evaluate provider's long-term product support strategies.

Genetec Inc. has released a set of guidelines aimed at aiding physical security leaders in evaluating how technology providers design and maintain connected security products.

This initiative comes as the European Union’s Cyber Resilience Act (CRA) intensifies cybersecurity requirements across the product lifecycle. The CRA sets out cybersecurity standards for digital products sold within the EU, focusing on secure product development, vulnerability management, and continuous lifecycle product support. While primarily targeting manufacturers, the regulations will impact distributors, installers, and operators of connected devices as well.

Evaluating technology providers

Mathieu Chevalier, Principal Security Architect at Genetec Inc., commented that the CRA strengthens several core principles that Genetec has long upheld, such as secure design and lifecycle management.

"By raising expectations for product security and transparency, the CRA regulations give buyers a clear basis for evaluating technology providers and the long-term cyber resilience of their products," he stated. With the onset of CRA's vulnerability-reporting guidelines by 11 September, organisations will depend more heavily on technology providers to meet new cybersecurity standards. Genetec advises asking technology providers five essential questions to evaluate their preparedness.

Vulnerability-handling requirements

The CRA underscores the critical need for sustained product security through its lifecycle

The CRA underscores the critical need for sustained product security through its lifecycle. Organisations should inquire about the duration and extent of security updates, vulnerability handling, and support as products reach the end of their lifecycle. Manufacturers are mandated to provide updates and address vulnerabilities for at least five years, which is a critical factor when assessing products.

Integrating cybersecurity from the initial stages of product design is another principle of the CRA. Companies should question providers about their incorporation of cybersecurity during design, development, and testing, alongside how these practices extend throughout the product's lifecycle.

Vulnerability management program

Since no software is completely immune to vulnerabilities, the responsiveness of a provider can indicate its dedication to cybersecurity. Firms should look for well-defined vulnerability management programs, which include regular security assessments, a coordinated disclosure policy, prompt risk-based resolutions, secure update delivery, and transparent advisories about resolved vulnerabilities.

Transparency is essential, as cybersecurity is a shared obligation. Responsible providers will transparently communicate how they test and maintain product security and offer clear guidance for secure deployment to customers and integrators. Inquiries should cover the provider’s processes for regular security evaluations, communication of vulnerabilities, and security updates, along with system-hardening advice.

Long-term cyber resilience

Genetec, with over 25 years of experience, embeds cybersecurity at the core of its physical security solutions

Continuous partnership with trusted technology suppliers is vital for sustained product cybersecurity. Organisations are encouraged to scrutinise how providers communicate product support periods, manage vulnerabilities, deliver security updates, ensure secure operation, and oversee product termination. They should insist on evidence confirming that the product adheres to cybersecurity standards throughout its lifetime.

Chevalier concluded, "Organisations best positioned to manage future cyber threats treat cybersecurity as an ongoing partnership, not a one-time procurement decision. The CRA helps reinforce that approach by setting common expectations for transparency, disciplined vulnerability management, and long-term product support, benefiting manufacturers, integrators and the organisations that depend on connected physical security systems."

Genetec, with over 25 years of experience, embeds cybersecurity at the core of its physical security solutions, employing open architecture, encryption, identity and access management, and ongoing monitoring. The organisation also prioritises vulnerability management and provides guidance to ensure long-term system resilience.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...