Session 2

The Cyber Resilience Act
PBC Connect - Black Hat USA 2025

Panelists:

VP, Supply Chain Security, Cybersecurity & Product Security Office
Schneider Electric
Mark Lambert
Chief Product Officer, ArmorCode
Director, Global Product Security Operations
Wabtec Corporation
Alex Nayshtut
VP, Chief Architect, Cellebrite
Jay Wilson
CIO & CISO, Insurity


The EU Cyber Resilience Act (CRA) is poised to reshape the way software and hardware products are developed, documented, and delivered—and the clock is ticking. With new mandates on vulnerability reporting, secure-by-design principles, and third-party accountability, security and product leaders must now grapple with one of the most sweeping regulatory shifts the industry has seen.

In this timely panel at PBC Connect – Black Hat USA 2025, security leaders share how they’re preparing their organizations technically, operationally, and culturally for CRA compliance. This grounded and open discussion covers:

  • Understanding CRA scope, timelines, and uncertainty
  • Balancing risk-based security practices with unclear regulations
  • Managing complex supply chains and inherited liability
  • Aligning cross-functional stakeholders around business risk and product readiness

Whether your team is already building toward CE marking or still decoding what the CRA means for your product portfolio, this session offers practical insight from leaders facing the same challenges.