Welcome, welcome!

This is home page of Radovan Semančík.

Does this site look strange? It does indeed. As you can see, I still maintain this 1990s-style homepage. Sidebar, menu and everything. I like it this way. Simple and efficient. Therefore you will not find any special transition effects, banners, or motivational photos on this site. There are no popups, notifications, special effects, flashing ads or social network buttons here. There are no disclaimers about cookies either, as this site does not use any cookies at all. This is Internet wilderness. Or heaven. Decide for yourself.

This is my personal site, not a professional site. While some content on this site is very suitable for work, there is also content that is not a perfect fit for most work environments. If that is a problem then just keep to the "Work" section of this site. Strange things may be found in other parts of this site. Here be dragons. You have been warned.

Latest Blog Post

Ready for CRA?

First obligations of EU Cyber Resilience Act (CRA) begin today, with much more to come next year. We are as prepared as we can be. Are you ready? I doubt it.

CRA is a major step forward in cybersecurity. CRA is not yet another cybersecurity regulation. CRA sets up an entire framework for cybersecurity of digital products. It starts a new era. Even though CRA creates a lot of work for us, I fully support it. That work is necessary. In fact, something like CRA should be already in place long time ago.

However, there are major downsides. It is very obvious that EU agencies and standardization bodies were absolutely not ready for CRA. Horizontal standards are not finished, some crucial standards are not even drafted yet. Vertical standards are not ready either. E.g. IAM vertical standard does not exist at all.

MidPoint has to fully comply with CRA requirements by 11 Dec 2027. We have 12-month development cycle, which means I need to process CRA-mandated cybersecurity requirements now, design the controls, and submit detailed specification of cybersecurity improvements to our development team. Right now. How am I supposed to do that, without appropriate technical standards in place?

As usual: A great idea, which gets crippled by implementation problems. Another lost chance for major cybersecurity improvement across the entire industry.

See more posts

Mastodon