drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2026
    • Call for Presentations
    • DRJ Spring 2027
    • DRJ Scholarship
    • Tracey Rice Memorial Scholarship
    • Other Industry Events
    • Schedule & Archive
  • WEBINARS
    • Upcoming Webinars
    • On Demand
    • DRJ Showcase Series
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
    • The BCI Partnership
  • ABOUT
    • About DRJ
    • 2026 Media Kit
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

Artificial Intelligence Requires Automated Cybersecurity for Smart Products

by Jon Seals | June 23, 2026 | | 0 comments

AI systems will uncover an increasing number of security vulnerabilities. This makes it all the more important to accurately assess their significance and the need for action

Düsseldorf — Artificial intelligence is fundamentally reshaping cybersecurity. New AI models can identify software flaws and security vulnerabilities faster than ever before. For manufacturers of connected devices, machines and systems, the growing volume of newly discovered vulnerabilities can only be effectively assessed and managed through automated processes. These processes also enable organisations to demonstrate compliance with an increasing number of regulatory requirements. This is the conclusion of a recent analysis by Düsseldorf-based product cybersecurity specialist ONEKEY.

Based on current trends and expert assessments, the number of discovered security vulnerabilities is set to rise dramatically in the future due to the use of powerful AI systems. However, the real challenge begins after that. Companies must determine which vulnerabilities are relevant, their impact on specific products, and the necessary measures. This is precisely where AI-only solutions reach their limits.

“Finding a vulnerability is not the same as understanding its significance for a product, considering its areas of application and risks, or making decisions that withstand regulatory scrutiny,” explained Jan Wendenburg, CEO of ONEKEY. AI is useful for initial testing and accelerating security analyses. Additional tools are required to ensure predictable results, clearly traceable audit evidence, compliance documentation, and robust risk assessments.

Reliable Evidence for Decision-Making and Compliance

This is particularly relevant in light of new regulatory requirements, such as the Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), and the IEC 62443 series of standards. In the future, manufacturers will need to demonstrate which software components are included in their products, identify existing vulnerabilities, explain their potential impact, and detail how risks have been addressed.

While modern AI tools are increasingly capable of identifying potential vulnerabilities, the analysis indicates that companies still need transparent and robust decision-making foundations. This includes a Software Bill of Materials (SBOM), vulnerability assessments (VEX), technical evidence of a product’s actual exposure, and documentation that can withstand audits and certifications.

A Combined Approach Involving Firmware Analysis, Security Management, and AI

ONEKEY relies on an integrated approach that combines automated firmware analysis, vulnerability management, and AI-based support. The ONEKEY platform analyzes firmware directly at the binary level. It automatically generates a software bill of materials and assesses the relevance of vulnerabilities within a product’s specific context. 

This reduces the workload by more than 60 percent. Additionally, the solution effectively identifies unknown vulnerabilities, such as insecure communication channels, hard-coded credentials, and potential attack vectors through code injections.

At the same time, ONEKEY continues to expand the use of artificial intelligence across its platform. Machine learning technologies are already being used to identify additional software components automatically. AI-powered chat capabilities and an intelligent analysis assistant, which automatically classifies security findings and supports prioritization decisions, will be available this summer. In addition, the ONEKEY platform is being enhanced with agentic AI systems to provide manufacturers and operators of smart products with an effective and highly automated platform. The goal is to help organizations manage growing cybersecurity requirements and increasing volumes of security findings efficiently while minimizing the resources required.

AI, Evidence, and Security Processes

“The use of AI increases the number of results. However, professional cybersecurity decisions must continue to be transparently documented, evaluated, and monitored,” the study concluded. According to ONEKEY, relying solely on AI can actually increase risk rather than improve security without structured product security processes.

Consequently, ONEKEY is investing heavily in expanding AI within its platform. Machine learning is already being used to improve security analyses further. The development roadmap also includes new AI-based features that will support companies in assessing, prioritizing, and addressing security risks. ONEKEY will unveil its first new product features in the coming weeks.

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life. 

Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated Software Bills of Materials (SBOMs) generation. “Digital Cyber Twins” enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle. 

The integrated ONEKEY Compliance Wizard already supports compliance with requirements from IEC 62443-4-2, ETSI EN 303 645, UNECE R155, and many other standards and regulations.

As part of the EU-funded CRACoWi (Cyber Resilience Act Compliance Wizard) project, ONEKEY is collaborating with 13 European partners to develop an AI-powered assistant for the automated implementation of the EU Cyber Resilience Act (CRA).

The solution will guide companies through the entire compliance process—from the initial CRA scope assessment to the generation of the required Declaration of Conformity.

The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritization of vulnerabilities, significantly reducing the time to remediation.

Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform (OCP) and ONEKEY Cybersecurity Experts.

Further information: ONEKEY GmbH,
Sara Fortmann, email: sara.fortmann@onekey.com,
Toulouser Allee 19A, 40211 Düsseldorf, Germany,
web: https://onekey.com

Related Content

  1. Disaster Recovery Journal
    Enterprise Automation Platform from CA Technologies Delivers Intelligence for Greater Speed and Efficiency
  2. Integration of Cybersecurity into Physical Security Realm
  3. Disaster Recovery Journal
    No. 1 Cyber Threat: Software Supply Chain Attacks Targeting Industry

Recent Posts

Built for Florida First Responders: Public Safety Agencies Across the State Modernize Public Safety Operations with Mark43

August 15, 2026

95% of IT Teams Aren’t Getting the AI ROI They Were Promised – Bridging the Gap Between AI Ambition and Execution

August 13, 2026

Enterprise AI Has Entered Its Operational Era: Stack Automation by Quali Is Now Generally Available

August 13, 2026

Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus

August 13, 2026

Flashpoint Releases 2026 Global Threat Intelligence Report: Midyear Edition Revealing the Operationalization of AI-Driven Cybercrime

August 13, 2026

Rubicon Professional Services Surpasses One Gigawatt Of Battery Energy Storage Capacity As AI Accelerates Data Center Demand

August 12, 2026

Archives

  • August 2026 (38)
  • July 2026 (83)
  • June 2026 (78)
  • May 2026 (67)
  • April 2026 (70)
  • March 2026 (89)
  • February 2026 (76)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (90)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2026
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Fall 2026 | Resilience In Motion

    Leave your details below for a chance to win a free pass to DRJ Fall 2026 | Resilience In Motion. The winner will be announced on August 31. Join us for DRJ's 75th Conference!
    Enter Now