If an industrial firm promises uptime, cybersecurity has already moved beyond the IT department. It sits inside
the service promise.
Manufacturers are using connected products to monitor condition, predict failure, guide maintenance and
support customers remotely. Those capabilities make advanced services possible. They also create
dependencies. The device, sensor, communications link, cloud platform, service team and external partners all
contribute to the outcome the customer experiences.
A vulnerability anywhere in that chain can interrupt visibility or control just when the customer needs it. For a
manufacturer paid according to availability, performance or usage, this becomes a service-delivery problem
with direct consequences for revenue and trust.
01
The deadline is close
From 11 September 2026, the EU Cyber Resilience Act requires manufacturers of in-scope products with
digital elements to report actively exploited vulnerabilities and severe security incidents. An early warning is
generally required within 24 hours of awareness, followed by a fuller notification within 72 hours. The wider
set of requirements applies from 11 December 2027.
24H
Early warning after awareness of an actively exploited
vulnerability. Fuller notification within 72 hours.
The reporting deadline is a practical test of organisational readiness. A manufacturer needs to know which
products are in scope, what is operating in the installed base, how vulnerabilities will be detected, who will
assess severity, who will submit the report and how affected customers will be informed.
The threat itself is already operational. ENISA’s 2025 threat landscape identified ransomware as the most
impactful cyber threat in the EU. Its manufacturing analysis found cybercrime to be the sector’s primary threat
by activity and reported impact, with ransomware incidents causing prolonged business disruption at
European manufacturers.
02
The customer sees one promise
A customer buying availability does not experience the product, software, platform and service network as
separate management structures. The customer experiences one outcome. When that outcome fails, internal
boundaries offer little reassurance.
This is why cyber resilience belongs inside service design. In our work at the Advanced Services Group, we
encourage firms to examine value creation, value delivery, value capture and the wider competitive landscape
together. Cyber risk cuts across all four. Connectivity can create value through faster diagnosis and better
decisions. Secure systems and capable partners are needed to deliver it. Revenue is exposed when service
levels are missed. Customer confidence can shift the competitive position rapidly.
An outcome commitment can extend beyond the boundaries of the organisation
delivering it.
The same logic applies to the ecosystem. Connected services frequently depend on cloud providers, software
suppliers, dealers, maintainers and customer systems. An outcome commitment can therefore extend beyond
the boundaries of the organisation delivering it. That makes visibility, responsibility and response routines
essential parts of the business model.
03
Contract language cannot create capability
Outcome-based agreements necessarily allocate risk. Contracts may define exclusions, update responsibilities,
response times and liability. Those clauses still depend on operational capability. A response promise has
limited value when service operations, product engineering, cybersecurity, legal teams and external partners
have never rehearsed the same incident.
Before scaling a connected advanced service, I would ask four questions.
D E P E N D E N C I E S – Can we identify every digital dependency behind the promised outcome?
D E T E C T I O N – Can we detect and assess a serious vulnerability quickly enough?
C O O R D I N A T I O N – Do all parties understand their role in customer communication and recovery?
R E H E A R S A L – Have we tested the response under realistic conditions rather than discussed it around
a table?
The CRA reporting clock is a useful forcing mechanism. Its commercial significance reaches further than
compliance because it reveals the maturity of the service surrounding the connected product.
The industrial firms that earn long-term trust will be able to explain how they prevent, detect, communicate
and recover. Cyber resilience becomes evidence that a provider is ready to carry greater responsibility for
customer outcomes. The regulation provides a deadline. The business model provides the reason to act.
If your connected service failed tomorrow, could you still tell the customer who owns the outcome and what happens next?