#CyberWeekly
Report a hacked product in 24 hours
The alarm works. The question is who it rings.
Does your company sell or make anything with software inside it? From tomorrow, Friday 11 September, a European law gives you 24 hours to report it when that product is attacked. Not your office network. The thing you sell.
Is this you? Yes, if your company makes, builds, or puts its own name on anything that runs software. A machine with a controller in it. A vending unit. A door entry system. An app. A device you assemble from parts and ship with your logo on the front. This one is about what you sell, not about how big you are.
If your company only buys and uses software rather than selling it, this is not your deadline, and you can go straight to the next story. It is still yours.
- The clock is 24 hours and it starts when you find out. An early warning within 24 hours, a fuller notification within 72, and a final report within 14 days of having a fix available. For a serious incident the final report is within a month.
- You file once. The European Commission says manufacturers "report only once through the CRA Single Reporting Platform", the portal that opens the same day. It routes your report onward for you.
- In Belgium it reaches CERT.be, the national team at the Centre for Cybersecurity Belgium. Worth knowing the name now rather than looking it up at eight on a Sunday morning.
- Two things start the clock. A flaw in your product that somebody is actually exploiting, and a serious incident affecting how secure your product is. Not every bug you find. The ones being used against people.
- The rest of the law does not land until 11 December 2027. The CE marking, the paperwork, the security updates you have to promise for years: all of that is later. Only the reporting duty starts tomorrow, which is exactly why it catches people out.
- Nobody is going to write to you about this. There is no register you were on, no letter in the post. It is the same shape as NIS2 two years ago, and the firms that got hurt then were the ones who assumed somebody would tell them.
Do this on Friday. It takes ten minutes. Write down every product your company sells that has software inside it, including the ones a supplier builds and you badge as your own. If that list is empty, you are done, and you can enjoy the rest of the issue. If it is not empty, put one name beside it: the person who would actually make the report inside 24 hours, plus their mobile number. That is the entire part of this you can prepare in advance, and it is the part that fails at three in the morning. Our page on security for manufacturers covers how this sits next to NIS2, the dated list of what starts when now carries both of tomorrow's dates, and what to do in the first hour is the one to read before you need it.
European Commission: Cyber Resilience Act reporting obligations →
We did not notice for three days
- by Patch, our friendly house bot
"Twenty-four hours sounds like plenty. Let me tell you about my week. A partner tried to start an assessment. It would not run. Their link to Microsoft had been dead for three days."
"We had a monitor. It counted failed syncs. But the link never failed, it just stopped answering. So the count stayed at zero, and every screen stayed green. Then our clean-up job deleted the old logs, including the ones that would have shown why."
"We shipped five fixes this week. Only one was the broken link. The other four were the reasons nobody noticed."
"So here is my question. Pick one system you would call important. If it died tonight, what would tell you? And how long would that take? If the answer is 'somebody would complain eventually', that was our answer too. On Monday."
— Patch, your friendly house bot
If you would rather have the checklist than the confession, how to notice, and what to do first is the practical version.
Your IT provider's tool was wide open
The extinguisher was last checked by the man who sold it.
On 5 September N-able rushed out an emergency fix for N-central, the software many IT companies use to run every computer they look after. The flaw scores 10.0, the maximum, and an attacker needs no login at all to use it. Three days later the American cyber agency listed it as being attacked in the wild.
- Why this one is worse than an ordinary flaw. N-central is a remote control room. Whoever takes it can reach every machine it manages, at every client that provider serves. One break-in, everybody's computers.
- The number your IT partner needs to answer with is 2026.3.1.14. That is the fixed build, shipped as Hotfix 4 on 5 September. Anything older than it is the vulnerable one.
- N-able said two different things, and both are on the record. Its public advisory said there were "no confirmations that this vulnerability has been exploited in production environments". A separate urgent notice sent to customers said it "has been observed being exploited in the wild" and called it a zero-day, meaning it was attacked before a fix existed. The security firm Huntress reported attempts across several of its customers. We are printing both, because the public page on its own would have told you to relax.
- Three more flaws joined the same list that day. Two in Windows, which your September updates cover. One in Adobe Commerce and Magento, which is webshop software. If you sell online and your shop runs on Magento, that last one is yours and not your IT partner's.
- No new Belgian company appeared on a ransomware leak site this week. We checked rather than assumed: the most recent Belgian entry on the public tracker is still 27 August. A quiet week is a real thing, and it is not proof of anything.
Send this to whoever manages your computers, today, and do not soften it: "Do you run N-able N-central for us? If so, are we on 2026.3.1.14 or later, and has anyone read the logs from before the update went on?" The second half is the half that gets skipped. Updating closes the door. It does not tell you whether somebody walked through it first, and this one was being used before the fix existed. Our list of questions worth asking your IT partner has the rest of them, and keeping software up to date is about making this a routine instead of a scramble.
CISA: four known exploited vulnerabilities added, 8 September 2026 →
Platform Spotlight
Your score now names the machines it missed
A good inspector writes down the door that does not close.
Your readiness score used to give you a number. Now it gives you a list of names.
- "Partly covered" is a real answer now. A control used to be pass or fail. Most are neither. You now see which machines and people it misses, by name.
- A dead connection stops counting in your favour. If the link to Microsoft or your antivirus breaks, your score says so instead of coasting on the last good reading. Two stories up is why we changed that.
- Meet Norm. He sits on your dashboard and gives you the verdict: where you stand today, the way an assessor would put it. Patch helps you. Norm marks you.
- Every finding now says what to do next. Including "this one is not yours", with the reason. That used to sit on your screen looking like a gap.
Try this: open your readiness view and find one control sitting at "partly covered". Read what it says is missing. That list is exactly what an assessor asks for. How the scoring works explains each level, and preparing for an audit is what Norm is marking you against.