Masterclass

Cybersecurity for digital service builders: building trusted applications in times of NIS2 and CRA

18 October is critical for cybersecurity, as many companies using digital products and software must follow NIS2 and CRA regulations. These companies need to be able to trust their software and digital component providers to protect themselves and their customers. As a digital service builder, how will you reassure your customers when they have questions about your security posture, application security, SBOM and data privacy? What should be your priorities when building trusted applications?

Is this your company?

You rely on external services and components - are you sure they are trustworthy? You give all developers access to all customer data. You blindly trust the backend of rented cloud services. You use passwords that appear on the notorious rockyou.txt list. If any of this sounds familiar, it is time to rethink your security approach.

The course targets digital service startups and scale-ups across all sectors in Belgium. It will specifically concentrate on CEOs, COOs, VPs of Sales, VPs of Marketing, developers, QA engineers and support staff.

Why does cybersecurity matter?

  1. USE TRUST AS A COMPETITIVE EDGE - In the digital age, trust is crucial. With stricter GDPR and upcoming CRA regulations, companies demand secure handling of sensitive data. Strong cybersecurity is not just compliance — it is a competitive advantage, especially when selling to corporates. 
  2. PROTECT YOUR BRAND AND HARD WORK - Cybercriminals are more aggressive and tech-savvy than ever. Data breaches are soaring, affecting more than just financial data. To stay in the game, you must meet strict cybersecurity standards such as the NIS 2.0 EU Directive. Secure-by-design is your ticket to retaining and attracting customers — no trust, no business. 
  3. SECURE-BY-DESIGN: DEVELOPERS HOLD THE KEYS - Over 80% of security breaches stem from human error. Cyber-literacy among your team is critical, and it’s about culture, not just tech. Developers are pivotal — since they often operate in small teams with diverse tasks and without dedicated security specialists. That is why we have worked out a programme to help them start with application security and security-by-design.  

What does this masterclass bring you?

  • It consists of one theory session and one practice session, both on-premise. The theory session contains a case-specific, actionable and implementable roadmap on software assurance and supply chain security.  
  • You will receive preparatory materials and questions before the masterclass for the interactive Q&A part. During this part, we will tackle your specific challenges in building trusted applications. You will leave the room with all the `how to do it' answers.
  • In the afternoon threat modelling workshop, you will identify top doomsday scenarios of your app, evaluate and prioritise risks and make informed decisions regarding your application. In this workshop, you will learn how to use diagrams and graphic representations of attacks and risks to efficiently decide what changes or mitigations need to be applied to your application. Gain a clear vision of your three biggest threats. You will leave with tools to tackle them and sleep better. Plus, you will be ready to answer customer security questions and build trust.

 

What is NIS2 (Network and Information Security Directive)? 

 

Why is supply chain security critical? 

  • This EU regulation aims to raise the cybersecurity bar for various sectors, including manufacturers and their providers – digital services and machine builders.
  • The directive emphasizes accountability (with a strong focus on incident reporting), supply chain security, collaboration and significant fines for non-compliance.
  • Implementation deadline: October 2024.
 
  • It is critical in light of recent supply chain attacks (Solarwinds, Log4j and the most recent one, on Crowdstrike this summer) and NIS2 requirements emphasizing supply chain security.

 

This master class is right on time for us! We constantly get questions from customers; they want proof that we can be trusted. We came to understand that this is a moment to take the lead in security. The master class is an important support for this decision. We think it can be of great value for many companies as it approaches security from a practical "sprint" viewpoint. It presents tools and actions for a good starting point.

Michael Mattan, CEO, prosoccerdata

 

You hosted a great workshop today. Thank you. Participants really appreciated the content, speed, and depth. Once more, it confirmed to me that digital product companies do need more knowledge of cybersecurity. Well done!  

Patrick Coomans, cyber security expert
 

Programme

9:00-9:30Welcome and coffee
9:30-12:00
  • Theory session on software assurance and supply chain security:
  • Standards, paradigms and maturity models  
  • How to design and develop secure applications
  • Intro to OWASP ASVS and OWASP DSOMM
  • Getting reliable and practical  information: OWASP Cheat Sheets
  • Writing code that is safe and sound: static code analysis
  • Using SCA tools and starting your SBOM, tools, and standards
12:00-13:00Short maturity scan, interactive session
13:00-14:00Lunch and networking
14:00-17:00Hands-on threat modelling workshop  

Working language

English

Thanks to the support of VLAIO within the framework of the #industrypartnership project, companies located in Flanders pay only 235 euros, Flemish Sirris members pay 195 euros. The participation fee for this crash course is 1.302 euros for companies outside of Flanders.

This programme is part of Industriepartnershap in which 13 Flemish innovation partners offer an integrated service to stimulate growth and innovation in the Flemish industry in the 6 following themes: AI, Circular economy, Digitisation, Industry 4.0 and Climate & Energy. They do so under the leadership of Agoria and Sirris and with the support of Agentschap Innoveren & Ondernemen. 

 

Banner Industriepartnerschap Sirris-Agoria thema's

Date

28 novembre 2024 09:00 - 17:00

Location

Sirris Gent

Technologiepark 48
9052 Zwijnaarde
Belgium

Google maps

Prix

€195,- companies in Flanders, members Sirris | €235,- companies in Flanders, non-members Sirris | €1302,- other companies

Personne de contact

En savoir plus sur cette expertise

Date

28 novembre 2024 09:00 - 17:00

Location

Sirris Gent

Technologiepark 48
9052 Zwijnaarde
Belgium

Google maps

Prix

€195,- companies in Flanders, members Sirris | €235,- companies in Flanders, non-members Sirris | €1302,- other companies