For your industry
Security requirements differ by industry. So does the way we test.
Each page describes the regulations, the typical attack surface and the findings we see most often in one industry, and what a sensible first project looks like.
In short
Zyberum works for manufacturers of machines and industrial equipment, medical device manufacturers, automotive suppliers, software vendors, utilities and critical infrastructure operators, IoT device makers and startups. For each industry it describes the applicable regulations, the typical attack surface and the first sensible security project.
Industries and roles
Find your page
Cybersecurity for Automotive Suppliers: UN R155, ISO/SAE 21434 and the CRA
What Tier-1 and Tier-2 suppliers must deliver for cybersecurity: UN R155 and R156 via the OEM, ISO/SAE 21434 work products, CRA for aftermarket parts and a first project.
ITCybersecurity for CISOs and IT Managers: NIS2 Duties, Pentests and Detection
What CISOs and IT managers in mid-sized companies need: NIS2 and BSIG duties, management liability, internal attack surface, typical findings and a first-year plan.
IoTCybersecurity for IoT Device Makers: RED EN 18031, CRA and Device Tests
What IoT device makers must do: RED with EN 18031 since August 2025, the Cyber Resilience Act from 2026, the device attack surface, typical findings and a first project.
OTCybersecurity for Machine Builders: Machinery Regulation, CRA and IEC 62443
What machine builders must do for cybersecurity: Machinery Regulation 2027, Cyber Resilience Act, IEC 62443, the typical attack surface and a sensible first project.
IoTCybersecurity for Medical Device Manufacturers: MDR, MDCG 2019-16 and NIS2
What medical device manufacturers must do for cybersecurity: MDR Annex I, MDCG 2019-16, NIS2, the attack surface of connected devices and a sensible first project.
ComplianceCybersecurity for Software Vendors: CRA Duties, NIS2 Supply Chain and Pentests
What software vendors must do under the CRA and NIS2: reporting from September 2026, SBOM, vulnerability handling, typical API findings and a first project.
ITCybersecurity for Startups: What Investors, Customers and the CRA Expect
Startup security without a security team: CRA duties at any size, customer questionnaires, cloud and API attack surface and a first project under 20,000 euros.
OTCybersecurity for Utilities and Critical Infrastructure: NIS2, KRITIS and OT
What municipal utilities and KRITIS operators must do: BSIG duties after NIS2, BSI-KritisV thresholds, the OT attack surface and a first project without downtime.
Get started
What does this mean for your product?
In a free one-hour consultation we go through your product or plant, the regulations that apply and the first steps that bring the most security for the money.
- Applicable regulations and deadlines for your case
- Where attackers would start
- A first project with a fixed price

Your call is withTom ZaubermannFounder & CEO, Zyberum
Or send us a message
We reply within one business day.