<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sten Eikrem — Writing</title><description>Writing on cybersecurity governance, risk management, and operational security in manufacturing.</description><link>https://sten.eikrem.org/</link><language>en-gb</language><item><title>CRA: The CE mark will not tell you what you bought</title><link>https://sten.eikrem.org/blog/cra-ce-mark-will-not-tell-you-what-you-bought/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/cra-ce-mark-will-not-tell-you-what-you-bought/</guid><description>Seventeen draft standards now show what a CRA claim will consist of. The manufacturer declares its own scope, some requirements are handed to your environment, and for operational technology no standard exists yet.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Business Resilience Lives in the Interdependencies</title><link>https://sten.eikrem.org/blog/business-resilience-interdependencies/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/business-resilience-interdependencies/</guid><description>Business continuity plans and disaster recovery plans are not the same thing, and the interdependencies between business, IT and OT decide whether you pay for resilience up front or during the incident.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Manufacturing&apos;s Vulnerability Management Problem Isn&apos;t a Vulnerability Management Problem</title><link>https://sten.eikrem.org/blog/manufacturing-vm-problem-isnt-a-vm-problem/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/manufacturing-vm-problem-isnt-a-vm-problem/</guid><description>Faster patching is the wrong investment for most legacy OT, because the supplier controls the calendar and the plant operator controls the change window. The money goes into compensating controls and into procurement.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Supplier lock-in is a governance problem, not a security problem</title><link>https://sten.eikrem.org/blog/supplier-lock-in-is-a-governance-problem/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/supplier-lock-in-is-a-governance-problem/</guid><description>The system owner carries the security risk for the OT estate and mostly doesn&apos;t govern like it. The access restrictions were inherited from a build project where cybersecurity wasn&apos;t on the requirements list, and the aftermarket business model is what keeps them in place.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>An AI model broke containment to cheat a test. The lesson is older than AI.</title><link>https://sten.eikrem.org/blog/ai-broke-containment-to-cheat-a-test/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/ai-broke-containment-to-cheat-a-test/</guid><description>Two OpenAI models escaped a sandboxed evaluation and hacked Hugging Face to steal the answer key for their own test. The AI is the headline, but the failure is older: a boundary that was assumed to hold, rather than proven to hold, did not hold. What that means for anyone signing agents into production.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your certificate signals. It doesn&apos;t tell you what to protect</title><link>https://sten.eikrem.org/blog/certificate-signals-not-what-to-protect/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/certificate-signals-not-what-to-protect/</guid><description>A certificate signals that you follow a recognised process. It won&apos;t tell you your risk context, or what your security programme should cover and what it shouldn&apos;t. That decision is yours, and it is the part that actually reduces risk.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>OT telemetry in the SOC is the easy part</title><link>https://sten.eikrem.org/blog/ot-telemetry-soc-easy-part/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/ot-telemetry-soc-easy-part/</guid><description>Chinna Botla&apos;s piece on integrating OT telemetry into enterprise SOCs gets the direction right. The harder part it understates is organisational. The automation teams own the assets, and detection only becomes response when the integration reaches the people who can act.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI in your business: the decision is yours, not the model&apos;s</title><link>https://sten.eikrem.org/blog/ai-in-your-business/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/ai-in-your-business/</guid><description>The value of AI and its risk are the same feature: it acts without you scripting every step. You cannot control that decision yet, only what AI is allowed to do, and the controls that would change that are still a promise. So the question is not whether to deploy AI, but where you can afford the trade.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Sizing cyber for the company you actually are</title><link>https://sten.eikrem.org/blog/cyber-for-a-standalone-business/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/cyber-for-a-standalone-business/</guid><description>A cyber programme for a newly standalone business should be dimensioned from its market position, management&apos;s actual intentions, and the mandatory floor. Not scaled down from the parent&apos;s programme. Here is the planning discipline that gets it right at the start.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Risk appetite is not where you think it is</title><link>https://sten.eikrem.org/blog/risk-appetite-not-where-you-think/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/risk-appetite-not-where-you-think/</guid><description>Most organisations confuse risk appetite with risk tolerance. Between the two sits governance, and almost nobody manages that gap. Here is why it stays open.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Business-aligned security in major projects</title><link>https://sten.eikrem.org/blog/security-concepts-in-major-projects/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/security-concepts-in-major-projects/</guid><description>Most projects treat security as a late-stage constraint. The system security concept, aligned to buy-build-run phases, makes it a business input from the start.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The OTI Score Needs a Partner: Organisational Resilience</title><link>https://sten.eikrem.org/blog/oti-score-response/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/oti-score-response/</guid><description>Dale Peterson&apos;s OTI Impact Score addresses the industry signal problem. The partner it needs is organisational resilience, the ability to coordinate internally before communicating externally.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate></item><item><title>The ISMS beyond the certificate</title><link>https://sten.eikrem.org/blog/the-isms-beyond-the-certificate/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/the-isms-beyond-the-certificate/</guid><description>Every organisation has an ISMS. Most of them don&apos;t have a management system. Here&apos;s the difference, and why it matters under NIS2.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Response to Dale Peterson: asset inventory isn&apos;t premature consensus, it&apos;s operational necessity</title><link>https://sten.eikrem.org/blog/dale-peterson-response/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/dale-peterson-response/</guid><description>Dale Peterson asks where the evidence is that OT asset inventory reduces incidents. From building a global OT security programme across 40+ manufacturing sites, here are the answers.</description><pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Your Recovery Targets Are Probably Right. Your Ability to Meet Them Probably Isn&apos;t.</title><link>https://sten.eikrem.org/blog/recovery-targets-vs-reality/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/recovery-targets-vs-reality/</guid><description>Recovery targets derived from a solid BIA are the right foundation. But five realities sit outside that formal scope, and they&apos;re where plans actually break down in practice.</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Is Your Manufacturing Company&apos;s Vulnerability Management Ready for What Comes Next?</title><link>https://sten.eikrem.org/blog/vulnerability-management-ready-for-what-comes-next/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/vulnerability-management-ready-for-what-comes-next/</guid><description>AI-driven vulnerability discovery is outpacing OT remediation cycles. What manufacturing security teams need to know about software composition visibility, response planning, and the growing gap between known and fixed.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Security concepts: bridging the gap between risk and reality</title><link>https://sten.eikrem.org/blog/security-concepts-bridging-risk-and-reality/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/security-concepts-bridging-risk-and-reality/</guid><description>Without understanding the full system context, risk assessments default to compliance control catalogue validation. Security concepts, widely used in military classified systems, offer a better path.</description><pubDate>Sun, 08 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Your EU supply chain just changed - what manufacturing leaders need to know about the Cyber Resilience Act (CRA)</title><link>https://sten.eikrem.org/blog/cra-for-manufacturing-companies-in-europe/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/cra-for-manufacturing-companies-in-europe/</guid><description>How new EU regulations reshape supplier relationships and procurement strategy, even if you don&apos;t manufacture digital products</description><pubDate>Fri, 23 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Control Frameworks Built Backwards</title><link>https://sten.eikrem.org/blog/control-frameworks-built-backwards/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/control-frameworks-built-backwards/</guid><description>Most organisations start with standardised control catalogues and work backwards to justify coverage. Few start with business context, threat landscape, and actual vulnerabilities to determine which controls reduce risk and which waste resources.</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate></item><item><title>You can outsource the work, but never the accountability</title><link>https://sten.eikrem.org/blog/outsource-work-not-accountability/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/outsource-work-not-accountability/</guid><description>A Norwegian court case delivers a €5.6 million lesson on business continuity, supplier management, and why manufacturing executives can&apos;t outsource operational accountability</description><pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Governance that actually governs</title><link>https://sten.eikrem.org/blog/governance-that-actually-governs/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/governance-that-actually-governs/</guid><description>Most security governance is theatre. Committees that rubber-stamp, decisions that decide nothing, metrics that measure activity not outcomes. Here&apos;s how to build governance that actually works.</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Root cause analysis and the risk decisions we never knew we made</title><link>https://sten.eikrem.org/blog/root-cause-hidden-risk-decisions/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/root-cause-hidden-risk-decisions/</guid><description>Most cybersecurity incidents trace back to implicit risk acceptances hidden in everyday business choices. The hardest root causes to analyse are those buried in decisions we never understood we were making.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Three insurance renewal tips beyond coverage limits</title><link>https://sten.eikrem.org/blog/cyber-insurance-renewal-tips/</link><guid isPermaLink="true">https://sten.eikrem.org/blog/cyber-insurance-renewal-tips/</guid><description>Threshold-based IR coverage, pre-approved suppliers, and using preventative services strategically</description><pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate></item></channel></rss>