eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

213
active users

#CRA

8 posts8 participants0 posts today

🔐 Practical Industrial Security: Real-World Lessons from Complex HVDC Projects

We’re excited to announce that our colleague Jan Grotelüschen (GAI NetConsult GmbH) will be speaking at the Industrial Security Conference 2025 in Copenhagen, alongside Simon Gustafson (Amprion GmbH) and co-author Stephan Beirer (GAI NetConsult GmbH).

🎤 Topic of the presentation:
Staying on course in a volatile environment: OT security in complex large-scale HVDC projects – a real-life example

insightevents.dk/isc-cph/sessi

⚡ At a glance:

Amprion is currently implementing massive offshore grid connection projects such as BorWin4/DolWin4 and BalWin1/BalWin2. These high-voltage direct current (HVDC) lines span up to 380 km and deliver 5.8 GW of power per project – enough to supply electricity to nearly 6 million people.
In this presentation, the speakers, who are largely responsible for the specification and monitoring of the implementation of OT security for this HVDC project, will present the projects itself and report on the cyber security challenges and lessons learnt.

🔍 Key OT Security Challenges Covered:
• Dynamic regulation: Adapting to evolving frameworks like NIS-2, RCE, CRA – even mid-project
• Technology vs. longevity: IT/OT convergence meets decades-long system life cycles
• Managing uncertainty: Constant change in technologies, requirements, and stakeholders

📌 This session provides real-world insights into securing critical infrastructure under real conditions – including what worked, what didn’t, and how lessons learned are shaping better security strategies.

🔗 More about the industrial security conference: linkedin.com/company/industria

:coffeev60:
"They want an arrangement that perpetuates racial inequality indefinitely while retaining some plausible deniability, a rigged system that maintains a mirage of equal opportunity while maintaining an unofficial racial hierarchy. Like elections in authoritarian countries where the autocrat is always reelected in a landslide, they want a system in which they never risk losing but can still pretend they won fairly."

theatlantic.com/politics/archi
#DEI #DonaldTrump #USpol #CRA

The Atlantic · The Great ResegregationBy Adam Serwer

"If someone is simply a developer of open-source software, which they don't monetize, they have no obligations under the #CRA. But they can help vendors who do have those obligations choose real change over paperwork-only 'compliance' by having a clear reporting channel for security vulnerabilities and a way to announce to users when those vulnerabilities are discovered." – Rybczyńska said. lwn.net/SubscriberLink/1023306

LWN.netOpen source and the Cyber Resilience Act The European Union's Cyber Resilience Act (CRA) has caused a stir in the software-development [...]

Trying to understand how the Cyber Resilience Act (#CRA) affects open source?

Fukami, EU Policy Advisor at the OpenSSF, shared at the #CRAMondays session a visual map of the landscape — regulations, actors, responsibilities — and how it all connects.

🎧 Watch the recording: youtu.be/7CbHwsKVD80

youtu.be- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

What is the New Legislative Framework (NLF), and how does it shape EU product legislation, including the Cyber Resilience Act (#CRA)?

In this episode of #CRAMondays, Fukami, EU Policy Advisor at the OpenSSF, breaks down the NLF as the legal backbone supporting the enforcement of internal market rules in the EU.

🎥 Watch the recording to get a clearer understanding of how the NLF provides a common framework for future legislation: youtu.be/7CbHwsKVD80

youtu.be- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

Es kommt, wie es kommen musste - und das ist auch gut so: Nachdem geraume Zeit unklar war, wie sich denn nun die delegierte Verordnung zur Radio Equipment Directive (#RED) und der #EU Cyber Resilience Act (#CRA) zueinander verhalten, gibt es nun in Bälde mehr Klarheit: Der Delegated Act soll pünktlich mit dem Wirksamwerden des CRA im Dezember 2027 aufgehoben werden.

Und das macht auch Sinn, denn auch die #Funkanlagen werden vom CRA erfasst:

circabc.europa.eu/ui/group/433 #cybersecurity