|  By Claire Tennant
This year marks a pivotal shift in global cybersecurity regulation. Mandatory cyber incident reporting is no longer a recommendation—it is a legal obligation. Across major jurisdictions, regulations such as the EU’s Cyber Resilience Act (CRA), the NIS2 Directive, and the U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) are introducing strict reporting timelines, expanded scope, and significant penalties for non-compliance.
  |  By Claire Tennant
A global leader in point-of-care ultrasound and medical imaging solutions has transitioned to a dedicated KeyScaler-as-a-Service (KSaaS) environment, marking a significant step forward in its ability to scale securely, optimise performance, and gain deeper operational insight across its connected device ecosystem.
  |  By Claire Tennant
In automotive and manufacturing, digital transformation is no longer a future ambition—it’s operational reality. Connected vehicles, smart factories, and increasingly complex supply chains have introduced a new dependency: trusted device identity and secure key management at scale. And yet, many organisations are still: This gap is no longer just a technical issue—it’s a business risk.
  |  By Claire Tennant
The latest European Commission guidance on the Cyber Resilience Act sends a clear message to manufacturers of connected products: cybersecurity must be designed in from the start, maintained throughout the product lifecycle, and supported by demonstrable processes for risk management, vulnerability handling and ongoing support. For organizations building, deploying and managing connected devices, this is a significant shift. The CRA is not simply another compliance exercise.
  |  By Claire Tennant
RSAC remains the cybersecurity event. It is where the industry gathers to compare notes, pressure-test assumptions, spot the next wave of market change and, just as importantly, build the partnerships that will shape what comes next. This year in San Francisco, that energy was unmistakable. There was real buzz across the city, from the show floor and executive meetings to the side events and industry gatherings that increasingly define RSAC week.
  |  By Darron Antill
by Darron Antill, CEO Device Authority Across the automotive and wider manufacturing industry, conversations around PKI and key management have moved from technical design discussions to board-level priorities. Regulatory frameworks such as UNECE WP.29, ISO 21434, and the emerging EU Cyber Resilience Act are fundamentally reshaping how OEMs and supply chain partners must think about cryptographic control.
  |  By Claire Tennant
The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for most products with digital elements placed on the EU market. It raises the baseline for secure-by-design/default engineering and, critically, makes post-market security support and evidence production a compliance obligation.
  |  By Claire Tennant
Automotive engineering teams are being asked to deliver faster, with less tolerance for failure. Software-defined vehicle programmes, secure OTA rollouts, zonal and service-oriented architectures, and continuous feature delivery are now baseline expectations. In parallel, regulatory pressure is increasing — from WP.29 (R155/R156), ISO/SAE 21434, and the forthcoming EU Cyber Resilience Act — tightening requirements around software integrity, traceability, and lifecycle governance.
  |  By Claire Tennant
As IoT and operational technology environments expand, organisations are discovering that a large portion of their device estate simply cannot be secured using traditional methods. Many devices cannot run agents, cannot be patched regularly, or cannot tolerate downtime. In 2025, this reality is no longer the exception—it is the norm.
  |  By Claire Tennant
The rapid expansion of connected devices has fundamentally changed how organisations operate. From smart sensors and industrial controllers to gateways, cameras, and embedded systems, IoT has become integral to modern business. Digital transformation is accelerating the adoption of IoT technologies, increasing the attack surface and making IoT security a critical component of modern cybersecurity strategies.
  |  By Device Authority
Secure Code Signing and Update Delivery for the Internet of Things (IoT) with Venafi CodeSign Protect and Device Authority KeyScaler platform
  |  By Device Authority
Using Device Authority's KeyScaler platform to manage PKI certificate provisioning to Microsoft Azure Sphere devices.
  |  By Device Authority
Automated Certificate Provisioning and Management with Device Authority's KeyScaler and Azure IoT Central

Device Authority is a global leader in Identity and Access Management (IAM) for the Internet of Things (IoT). Our KeyScaler™ platform provides trust for IoT devices to help enterprises protect their investment and their customers from cyber attacks. As the professional IoT world rapidly expanded, our founders saw a need for a centralised security solution to help enterprises keep their devices safe from malicious attacks.

The state-of-the-art KeyScaler™ platform has been continuously developed over the years to provide advanced technology for customers. Device Authority helps well-renowned customers around the world protect their brand integrity, and develop new IoT devices with built-in security measures from the start.

A single platform to manage your device permissions, secure your data’s privacy, automate security protocols, and maintain compliance:

  • KeyScaler Identities: Increase efficiency and reduce IT overheads with automated password/ certificate management.
  • KeyScaler Data Security: Patented technology automates compliance and prevents disruption, espionage, and attacks.
  • KeyScaler Secure Updates: Your best defence against security breaches through unauthorised software or firmware updates.
  • KeyScaler HSM Access Controller: Mitigate security risks, accelerate time to market, and protect brand reputation with HSM Access Controller
  • KeyScaler Edge: Manage authorisation at scale with device identity, integration, and automation.

Your company’s ultimate cybersecurity protection.