Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Firmware and Bootloader: The Verification Gap in OT Infrastructure
Deep Dive, Policy Pulse Sandra Weiss Deep Dive, Policy Pulse Sandra Weiss

Firmware and Bootloader: The Verification Gap in OT Infrastructure

Proving that the code running on a field device is what the vendor shipped is one of the hardest problems in industrial security. This second report in the series compares four verification mechanisms, from SHA-256 hashing to remote attestation, and maps them to the revised Network and Information Security Directive (NIS2), the Cyber Resilience Act (CRA), and Germany's BSI Act. It also looks at what US utilities learned under NERC CIP, and which compensating controls work for legacy controllers that cannot verify their own firmware.

Read More
The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock
The Execution Layer Gap, Policy Pulse Sandra Weiss The Execution Layer Gap, Policy Pulse Sandra Weiss

The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock

Many European critical infrastructure operators are planning around December 2027, when the Cyber Resilience Act (CRA) fully applies. Its vulnerability reporting duty under Article 14 took effect on September 11, 2026, and it covers products already deployed in the field. This Foundation report, the first in a six-part series, looks at why regulators are turning to the firmware and bootloader layer below the operating system, how the CRA and the revised Network and Information Security Directive (NIS2) reach it, and what Germany's implementation adds.

Read More