Exploited by Kai London
The Cyber Resilience Act turns vulnerability handling from good practice into a manufacturer's obligation, with reporting duties that begin as soon as a vulnerability in a product is known to be actively exploited. Exploited sets out how a product organisation builds the triage, disclosure and reporting machinery that obligation assumes.
What the book covers
Scope and roles
Which products carry obligations, and how duties differ between manufacturer, importer and distributor.
Triage and thresholds
Judging active exploitation and severe incidents, and recording the reasoning behind the call.
Reporting workflow
The staged notification sequence, who inside the business drafts and approves, and how to run it out of hours.
Coordinated disclosure
Working with researchers and downstream users while a fix is being prepared.
SBOM and update discipline
Knowing what is in the product, and being able to ship a security update through its support period.
Technical documentation
The records that demonstrate a compliant vulnerability-handling process to a market surveillance authority.
General guidance, not legal advice; take qualified advice on the obligations applying to your products. Independent, with no endorsement by or affiliation with any regulator or standards body.
Who it is for
Product security and PSIRT teams, engineering and release management, regulatory affairs and compliance, and executives accountable for products placed on the EU market.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.