Insights 4 min. read — Sep 15, 2026
Why product cybersecurity matters for connected critical infrastructure
Digital technology is becoming an increasingly important part of telecom networks and other critical infrastructure. Connected controls, monitoring capabilities, and remote management can help operators improve visibility, respond to issues, and manage equipment across distributed locations.
These capabilities bring clear operational benefits, especially at remote sites where uptime and effective maintenance are essential. However, as physical infrastructure becomes more connected, cybersecurity becomes an increasingly important part of product reliability and long-term support.
Recent developments under the EU Cyber Resilience Act reinforce the importance of taking a structured approach to product cybersecurity and vulnerability handling.
What is the Cyber Resilience Act?
The Cyber Resilience Act, or CRA, is a European Union regulation introducing cybersecurity requirements for hardware and software products with digital elements made available on the EU market.
It takes a lifecycle approach, to product security. Among other requirements, manufacturers are expected to consider cybersecurity during product design and development, and to establish processes for identifying, handling and responding to vulnerabilities throughout a product’s lifetime.
The CRA entered into force in December 2024 and will become fully applicable in December 2027. However, from 11 September 2026, specific reporting obligations already apply to manufacturers. These include reporting actively exploited vulnerabilities and severe security incidents affecting products with digital elements through the EU’s Single Reporting Platform.
How does this relate to infrastructure equipment?
The CRA is not limited to traditional software. It also applies to hardware products that include digital functions and connect directly or indirectly to another device or network.
For infrastructure equipment, applicability therefore depends on the individual product and its digital functions, how it connects to other systems and the role of the company making the product available on the market. Some infrastructure products are mainly mechanical or electrical, while others include digital controls, monitoring features, communication capabilities, software or remote access.
For Vikinor, this means considering the digital functions used in relevant products and integrated solutions. Because products and configurations differ, a product-specific approach helps ensure that cybersecurity is considered in relation to how the equipment is designed, configured, and used.
Why vulnerability reporting matters
A potential security weakness may be identified after a product has been installed or put into service. It could be discovered by a customer, integrator, service partner, supplier, security researcher, or another party familiar with the product.
When a potential vulnerability is reported, this allows Vikinor to:
- identify the affected product and configuration
- assess the nature potential impact
- involve the appropriate technical teams or suppliers
- determine whether guidance, mitigation, or corrective action is required
- communicate with affected customers appropriately or other relevant parties
A reported concern does not need to be a confirmed vulnerability. Timely reporting allows the issue to be properly reviewed and helps determine whether further action is required.
A dedicated reporting route therefore supports both effective product security management and the ability to respond appropriately when a concern requires further action.
Supporting resilient telecom infrastructure
Telecom and critical infrastructure sites often operate continuously, across distributed locations, and with limited opportunities for on-site intervention. Equipment may remain in service for many years and incorporate technology from several suppliers, making effective coordination particularly important when a potential vulnerability is identified.
In this environment, a cybersecurity issue may have consequences beyond a single digital function. A weakness affecting a controller, communication interface or management function could interfere with monitoring, maintenance, equipment operation, or site availability.
Product cybersecurity therefore contributes to wider operational resilience. As infrastructure becomes more connected, protecting digital functions and responding effectively to product vulnerabilities become increasingly important to maintaining reliable and secure operations.
Vikinor’s approach
Vikinor has established a structured approach for receiving, assessing, and following up on potential product security vulnerabilities. A dedicated reporting channel helps ensure that concerns are directed to the appropriate teams and can be evaluated in coordinator with our customers, technology partners, manufacturers, and suppliers where relevant.
This supports timely assessment of reported concerns and helps us coordinate appropriate guidance, mitigation, corrective action, communication and regulatory reporting where required.
As part of this approach, Vikinor has introduced a dedicated Product Security Vulnerability Reporting channel, which is open globally to:
- customers and product users
- partners, integrators, and service providers
- suppliers and technology providers
- security researchers and CERTs/CSIRTs
- other parties with relevant information
The reporting channel is supported by Vikinor’s Product Security Vulnerability Disclosure Policy, which explains what is covered, our expectations for responsible disclosure, and how reports are handled.
Together, the dedicated channel and supporting policy provide a clear and responsible way to raise potential security concerns affecting Vikinor products and help us coordinate the appropriate response when a vulnerability is identified.
Report a potential vulnerability
If you become aware of a potential cybersecurity vulnerability affecting a Vikinor product, we encourage you to report it through our dedicated channel.
Providing clear information about the affected product, configuration and nature of the concern will help us assess the report and coordinate the appropriate next steps.
Product cybersecurity is an ongoing process. By making it easier to report potential vulnerabilities and establishing a structured approach to assessing and responding to them, we aim to support the long-term reliability and resilience of the infrastructure our products and solutions form part of.




