REGISTER HERE
Cybersecurity incidents don't wait for companies to have a dedicated security team. For small and medium-sized enterprises (SMEs), a critical vulnerability can turn into a stress test overnight - chasing down which products are affected, which customers are exposed, and whether a fix even exists, all while trying to keep daily operations running.
In this webinar, Erminas - a software SME building solutions for industrial digitalisation, and a partner in the CRACoWi project — shares a first-hand, practical perspective on what it actually takes to respond to a security incident without a large security organisation behind you.
Drawing on real scenarios from day-to-day SME life, the session shows how a few well-chosen practices - rather than a heavy security function - can turn chaotic incident response into a structured, confident process. The Cyber Resilience Act (CRA) is presented not as a compliance burden, but as the framework that makes this structure possible: demanding traceability, not perfection.
Some question that will be answered:
- Why SMEs carry the same cybersecurity responsibility as large enterprises - with far fewer resources
- How to walk through a real vulnerability scenario step by step: using an SBOM to scope affected products, checking patch status, applying a lightweight threat model, and communicating clearly with customers
- Practical, low-overhead approaches - Security Champions, regular awareness training, and frameworks like the NIST Cybersecurity Framework - for building traceability without building a full security department
- Why clear processes reduce stress and build customer trust, especially in critical moments
Who should attend
Founders, engineering leads, and product teams at SMEs developing or maintaining software or connected products, especially those without a dedicated cybersecurity function and looking for realistic, teamwork-based ways to prepare for CRA compliance.
The presenter: Jonas Gerlach - Cybersecurity Team Lead & IIoT Developer with 8 years of hands-on experience designing, implementing, and securing industrial systems. Passionate about bridging operational technology (OT) and information technology (IT), leading technical teams, and delivering secure, scalable IIoT solutions.
This is a practical SME-focused session on cybersecurity and the CRA, with real examples and Q&A. It will show you a simple way to handle security incidents and realistic steps to improve structure and customer trust