Cyber Resilience Act · Product security

Exploited by Kai London

The Cyber Resilience Act turns vulnerability handling from good practice into a manufacturer's obligation, with reporting duties that begin as soon as a vulnerability in a product is known to be actively exploited. Exploited sets out how a product organisation builds the triage, disclosure and reporting machinery that obligation assumes.

Coming soonAll books

What the book covers

Scope and roles

Which products carry obligations, and how duties differ between manufacturer, importer and distributor.

Triage and thresholds

Judging active exploitation and severe incidents, and recording the reasoning behind the call.

Reporting workflow

The staged notification sequence, who inside the business drafts and approves, and how to run it out of hours.

Coordinated disclosure

Working with researchers and downstream users while a fix is being prepared.

SBOM and update discipline

Knowing what is in the product, and being able to ship a security update through its support period.

Technical documentation

The records that demonstrate a compliant vulnerability-handling process to a market surveillance authority.

General guidance, not legal advice; take qualified advice on the obligations applying to your products. Independent, with no endorsement by or affiliation with any regulator or standards body.

CRANIS2ISO 29147ISO 30111IEC 62443-4-1

Who it is for

Product security and PSIRT teams, engineering and release management, regulatory affairs and compliance, and executives accountable for products placed on the EU market.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.