Search

CRAcademy Use Case Workshop: Cybersecurity affects us all – including small and medium-sized enterprises

Date: 6. 08. 2026

REGISTER HERE

Cybersecurity incidents don't wait for companies to have a dedicated security team. For small and medium-sized enterprises (SMEs), a critical vulnerability can turn into a stress test overnight - chasing down which products are affected, which customers are exposed, and whether a fix even exists, all while trying to keep daily operations running. 

In this webinar, Erminas - a software SME building solutions for industrial digitalisation, and a partner in the CRACoWi project — shares a first-hand, practical perspective on what it actually takes to respond to a security incident without a large security organisation behind you. 

Drawing on real scenarios from day-to-day SME life, the session shows how a few well-chosen practices - rather than a heavy security function - can turn chaotic incident response into a structured, confident process. The Cyber Resilience Act (CRA) is presented not as a compliance burden, but as the framework that makes this structure possible: demanding traceability, not perfection. 

Some question that will be answered: 

  • Why SMEs carry the same cybersecurity responsibility as large enterprises - with far fewer resources 
  • How to walk through a real vulnerability scenario step by step: using an SBOM to scope affected products, checking patch status, applying a lightweight threat model, and communicating clearly with customers 
  • Practical, low-overhead approaches - Security Champions, regular awareness training, and frameworks like the NIST Cybersecurity Framework - for building traceability without building a full security department 
  • Why clear processes reduce stress and build customer trust, especially in critical moments 

Who should attend 
Founders, engineering leads, and product teams at SMEs developing or maintaining software or connected products, especially those without a dedicated cybersecurity function and looking for realistic, teamwork-based ways to prepare for CRA compliance. 

The presenter: Jonas Gerlach - Cybersecurity Team Lead & IIoT Developer with 8 years of hands-on experience designing, implementing, and securing industrial systems. Passionate about bridging operational technology (OT) and information technology (IT), leading technical teams, and delivering secure, scalable IIoT solutions.

 

This is a practical SME-focused session on cybersecurity and the CRA, with real examples and Q&A. It will show you a simple way to handle security incidents and realistic steps to improve structure and customer trust

Help
Increase your chances - contact us. Do you need help with EU funding? Contact us
Advanced Tips
Type Example Notes
Fuzzy kettle~ Contain terms that are close to the word kettle, such as cattle
Wild cat* Contain terms that begin with cat, such as category and the extact term cat itself
Exact-Single orange Contain the term orange
Exact-Phrase "dnn is awesome" Contain the exact phase dnn is awesome
OR orange bike Contain the term orange or bike, or both. OR, if used, must be in uppercase
orange OR bike
AND orange AND bike Contain both orange and bike. AND must be in uppercase
Combo (agile OR extreme) AND methodology Contain methodology and must also contain agile and/or extreme
Results per Page:
Limit the search results with the specified tags.
Limit the search results modified within the specified time.
Limit the search results from the specified source.
Search results must be an exact match for the keywords.