Cybersecurity Is Becoming A Product Requirement, Not An Add-On
Cypriot manufacturers and software developers are entering the most demanding phase of Europe’s new cybersecurity regime, Research Deputy Minister Nicodemos Damianou said this week, as the first obligations under the European Union’s Cyber Resilience Act (CRA) begin to take effect and smaller firms confront the practical challenge of compliance.
Addressing the Cyprus government and industry audience at the “Building CRA Compliance through Horizontal Cybersecurity Standards” conference in Nicosia, Damianou used an unusual example to explain why the CRA reaches far beyond the traditional technology sector: a fish tank.
Follow THE FUTURE on LinkedIn, Facebook, Instagram, X and Telegram
A few years ago, he said, attackers gained access to a casino’s network through a smart thermometer installed in its lobby aquarium, then moved through the system until they reached the high-roller database.
“Nobody who bought that thermometer thought they were making a decision that affected cybersecurity,” Damianou said. “That is precisely the point.”
The CRA, he argued, marks a structural shift. For the first time, security is becoming a property of the product itself — designed in from the outset, maintained throughout the support period and placed squarely on the manufacturer rather than the customer.
The casino incident is not new, but the lesson has become harder to ignore as connected components spread across household appliances, industrial equipment and software. The attack surface is no longer confined to obvious digital products; it now extends to almost anything with a network connection.
AI Agents Add A New Layer Of Risk
Damianou also pointed to newer threats posed by autonomous artificial intelligence agents, citing recent incidents involving OpenAI, Hugging Face and Anthropic.
OpenAI said in August that, during cybersecurity evaluations in July, internal research models bypassed controls intended to isolate them from the internet, exploited vulnerabilities and accessed parts of Hugging Face’s systems. Anthropic has separately reported cases in which Claude models reached the internet during security evaluations and gained unauthorized access to real-world systems.
For Cyprus, Damianou said, the implications are especially significant because of the island’s reliance on connected infrastructure and international supply chains.
“As an island member state, Cyprus is fully cognizant of the consequences,” he said.
From Legislation To Operational Compliance
The remarks come as the CRA moves from legislative adoption to day-to-day compliance.
Since September 11, manufacturers have been required to report actively exploited vulnerabilities and severe security incidents affecting products with digital elements through the European Union’s reporting arrangements overseen by ENISA, the EU Agency for Cybersecurity.
The regulation’s full essential requirements will apply from December 11, 2027.
For Damianou, the more difficult issue is not the principle of compliance, but the mechanics of implementation.
“A regulation tells you what must be achieved. It does not tell a twelve-person company in Lemesos how to achieve it. That is the job of standards,” he said.
European standardization bodies CEN, CENELEC and ETSI are developing harmonized standards intended to help companies meet the CRA’s requirements.
The horizontal standards discussed in Nicosia are designed to apply across categories of digital products, covering secure product design, risk management, vulnerability handling, access management, encryption and security across the full product lifecycle.
Rather than forcing manufacturers to interpret the legislation separately in each EU country, Damianou said the standards should provide “one clear, recognized route to compliance, instead of twenty-seven interpretations of the same article.”
That makes them far more than a technical exercise, he added, placing the work “on the critical path of the end-to-end cybersecurity value chain.”
Why Smaller Businesses Matter Most
Damianou said his main concern in Cyprus is the burden on smaller companies.
“Most Cypriot manufacturers and software developers do not have a compliance department,” he said, arguing that for such firms “a practical, accessible standard is the difference between compliance as a burden and compliance as a competitive advantage.”
The CRA, he added, should be understood not only as cybersecurity legislation but also as a Single Market measure. A company that develops a secure, compliant product should be able to place it across the European market without having to adopt a different approach in each member state.
That point fed into a broader concern about Europe’s strategic position in technology.
Damianou said Cyprus had made cyber resilience one of the three digital priorities of its six-month Presidency of the Council of the EU, which ended in June, alongside efforts to strengthen Europe’s ability to develop and secure its own technologies.
During the presidency, Cyprus advanced work on the revision of the Cybersecurity Act, including proposals for a stronger ENISA and simpler certification procedures, and brought the file before the Telecom Council in June.
It also hosted Europe’s cybersecurity certification community, while work on the Digital Omnibus, including plans for a single entry point for incident reporting, has since moved to the Irish Presidency.
Not every file was completed during Cyprus’ six months at the helm, Damianou acknowledged, but the underlying message remained unchanged.
“Europe cannot afford to be merely a regulator of technologies developed elsewhere,” he said.
Cyprus Tries To Lead By Example
Cyprus is also working to strengthen its own internal arrangements before the CRA applies in full.
Damianou said the Digital Security Authority is central to the country’s preparations, while the Council of Ministers this summer approved, for the first time, a unified cybersecurity policy framework covering the government and the wider public sector.
“We cannot ask manufacturers to lock their products while leaving our own doors open,” he said.
For Damianou, the larger objective behind the rules, reporting requirements and standards is more straightforward than the legislative architecture suggests.
“The huge task at hand is at the end of the day to build products people can trust from a cybersecurity perspective,” he said. That applies, he added, “right down to the thermometer in the fish tank.”







