While digitalizing and connecting machines and systems unlocks vast opportunities, it also broadens the attack surface for cyber threats. With regulatory requirements for product cyber security tightening simultaneously, cyber security has become a critical success factor. Meeting statutory mandates like the Cyber Resilience Act (CRA), the NIS 2 Directive, and the Radio Equipment Directive Delegated Act (RED DA) is just the baseline – the key priority is protecting the resilience of your and your customers’ networks. ITK Engineering supports industrial enterprises as a specialized development partner with tailored security solutions, spanning from strategic consulting to secure operations.
Espionage, sabotage, and ransomware, connected systems and devices in industrial environments (IIoT) are increasingly exposed to cyber threats. As connectivity grows, so does the attack surface – and with it, the risk of targeted cyberattacks.
In its regular reports, the German Federal Office for Information Security (BSI) consistently warns of the elevated threat level facing the industrial sector. Despite this, many companies still underestimate their own vulnerability. A successful cyberattack can yield devastating consequences:
To counter the growing threat landscape, the EU has tightened its regulatory requirements. To succeed in the European market, companies must prove that their products and networks are protected against tampering throughout their entire lifecycle. Four key directives are particularly relevant for operators and manufacturers in the industrial sector:
| EU regulation | Deadline | Relevance to the sector |
|---|---|---|
| Cyber Resilience Act (CRA) | Adopted in October 2024; binding starting in 2027 | Transforms the cyber security of products with digital elements throughout their entire lifecycle. |
| EU Machinery Regulation (MR) | Fully enters into force on January 20, 2027 | Integrates cyber security for the first time as a mandatory requirement for the CE operational safety of machinery. |
| NIS 2 Directive | Transposed into national law since October 2024 | Sets new benchmarks for the network and information security of operators and essential/important entities. |
| Radio Equipment Directive (RED DA) | Currently in force; additional mandatory requirements active since August 2025 | Relevant for all wireless-connected devices and wireless control systems in industrial environments. |
Failing to comply with European cyber security laws leads to severe consequences, ranging from heavy financial penalties to sales bans (including the loss of the CE mark).
| EU regulation | Who is affected? | What penalties apply? |
|---|---|---|
| CRA | Manufacturers, suppliers, and importers of products with digital elements (software and hardware products with direct or indirect data connections to other devices or networks). | Fines up to €15 million or 2.5% of annual turnover, and product recalls |
| MR | Manufacturers of machinery, and all economic operators who make machinery available, place it on the market, or put it into service in the EU. | Fines up to €100,000, imprisonment, sales bans, recall orders, public warnings by competent authorities, and personal liability |
| NIS 2 | Companies operating critical or important IT/OT systems in essential or important sectors. | Fines up to €10 million or 2% of annual turnover, and personal liability for management |
| RED | Manufacturers and operators of products with radio interfaces capable of establishing a direct or indirect data connection over the internet (e.g., Wi-Fi, Bluetooth, radar, etc.). | Fines or penalties, and liability for damages caused (determined individually by EU member states) |

Viewing cyber security as a tedious compliance chore means missing out on a massive opportunity. EU regulations, from NIS 2 to the CRA, are far more than a set of rules – they define new quality standards for the industry. In an environment of automated threats, digital resilience has evolved from a pure defense strategy into a critical driver of long-term market success.
Dr. Jens Koehler, Senior Expert Cyber Security, ITK Engineering
As a software and systems engineering expert, ITK Engineering supports you with tailored cyber security consulting and customized cyber security solutions to implement regulatory mandates and efficiently fortify your organization against cyber threats. We align our services with your specific requirements, technical constraints, and existing processes. Our service portfolio spans from cyber security strategic consulting and process/methodology advisory to risk assessments, conceptual design, software development, and testing. Naturally, we always integrate recommendations from European institutions (such as ENISA), core standards like IEC 62443, and current regulatory frameworks.
With our consulting services, we help you identify security risks proactively and mitigate them effectively. Together, we develop a tailored security strategy that holistically protects your IT/OT infrastructure. We guide you through the implementation of effective security processes and methodologies – from risk analysis and vulnerability management to supplier management. This enables us to co-create a comprehensive, practical security concept that strengthens your resilience against cyber threats and attacks.
Our cyber security engineering services assist you in implementing security practically and efficiently. This includes thorough risk assessments: We identify potential damage scenarios, model attack vectors, and systematically uncover vulnerabilities. Based on these insights, we design customized architecture defining the necessary security mechanisms. We technically implement these security requirements to establish a robust and trusted software foundation. Simultaneously, we continuously verify the effectiveness of these measures through rigorous cyber security testing.
Dr. Jens Koehler
Manufacturing Industry