Session

The Cyber Resilience Act as a Catalyst for OT Cybersecurity Modernization

The EU Cyber Resilience Act (CRA) introduces a major shift in how industrial organizations must design, secure, and maintain Operational Technology (OT) systems. Taking effect in 2026, (vulnerability reporting from September 2026, full applicability from December 2027), the CRA mandates security by design engineering, continuous vulnerability management, and 24-hour reporting of actively exploited vulnerabilities. These requirements drive significant changes to organizational processes, including formalized vulnerability intake, standardized triage workflows, coordinated disclosure procedures, and updated risk reporting policies that align engineering, security, and compliance teams.
For OT environments—where legacy systems, long equipment lifecycles, and limited patching windows have historically constrained security—the CRA acts as both a catalyst and a compliance driver. This session explores the CRA’s strategic impact on industrial cybersecurity/automation solutions and outlines the governance, engineering, and process transformations needed to build a resilient, future ready OT ecosystem.

Daniel Paillet

Schneider Electric, Senior Prinicple Cybersecurity Architect

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top