top of page
Engineering Blog for High Performance Insights


Security Update - The Four Clocks for Operators
SECURITY BRIEF: In this posting we explore the operational aspects of deploying resolution of exploitable vulnerabilities by manufacturers in the field. This article is a companion to "The Four Clocks for Manufacturers" This edition addresses the asset owner and operator: the entity running the estate at the operations level, on whom NIS2’s risk-management measures and Article 23 reporting clocks bind directly (where in scope), and whose engineering obligations run through
Scott Ludwick
Aug 86 min read


Security Update - The Four Clocks for Manufacturers
CRA Article 14 compliance for manufacturers
Scott Ludwick
Aug 86 min read


CRA - Compliance by Consortium
POSITION NOTE: Through EU legislated CRA (Cybersecurity Resiliency Act) scope is product level, efforts are made to assert compliance by way of systems architecture - will this assertion hold water? We explore this question. In late 2025, EtherCAT Technology Group consortium announced that its protocol meets the requirements of the EU Cyber Resilience Act. The initial statement, from the EtherCAT Technology Group, was carefully qualified — the protocol was said to meet IEC
Scott Ludwick
Jul 312 min read
bottom of page