00:00 Introduction to Memfault and the Hosts 02:49 The Evolution of IoT Security 06:51 Current State of IoT Security Practices 10:44 Challenges with Outdated Software and Hardware 13:41 The Importance of OTA Updates 15:32 Real-World Implications of IoT Security 18:10 Working with Third-Party Developers and Security Risks 18:54 Security Considerations in Third-Party Collaborations 21:43 Understanding Wireless Exploits and Vulnerabilities 22:50 Emerging Regulations for IoT Security 24:05 The Cyber Resilience Act: Implications for Device Manufacturers 29:25 Navigating Compliance with New Regulations 33:32 Balancing Data Collection and Privacy Regulations 37:04 Understanding Device Categories and Compliance Requirements 40:18 Exploring the Cyber Trust Mark in North America 43:59 Navigating Compliance Responsibilities in Organizations 47:00 Leveraging Open Source for Compliance and Security 49:53 Building a Foundation for Compliance with SBOMs 52:40 Integrating Security Standards and Physical Access Threats 55:28 Exploring Security in Smart Devices 56:53 The Role of Memfault in Device Security 01:00:09 Regulatory Challenges in Device Support 01:02:06 Compliance and Standards in IoT Security 01:05:59 Addressing Resource Constraints in IoT Security Coredump Sessions started at Memfault, now part of Nordic Semiconductor. We're continuing the series here with the same hosts, guests, and deep dives into embedded systems. New IoT security regulations are imminent, with businesses across the US, UK, and EU bracing for the impacts of the Cyber Resilience Act (CRA), Product Security Telecommunications Infrastructure, and Cyber Trust Mark. These are not just administrative changes; they represent a pivotal shift in how IoT devices will be developed, deployed, and managed. Ensuring security, privacy, and compliance is business-critical. Watch Memfault Co-Founders François Baldassari and Chris Coleman for an open discussion on the future of the IoT industry in light of new regulations being introduced. Key Takeaways - IoT security is no longer optional—new regulations like the CRA and Cyber Trust Mark make it mandatory. - Most connected devices today are still dangerously undersecured, with outdated stacks and poor OTA support. - Open source platforms like Zephyr can make compliance easier by pooling security resources across companies. - OTA (over-the-air) updates are now a requirement in both US and EU regulations. - The CRA introduces SBOM (Software Bill of Materials) requirements to track vulnerabilities in dependencies. - Observability, encryption, and secure boot need to be built in from the start—not as last-minute add-ons. - Compliance will vary based on device criticality, but self-certification will be the norm for most companies. - Ignoring security costs more in the long run—both in reputation and risk. Listen to the Podcast episode: https://memfault.com/resources/coredump-000-how-new-iot-security-regulations-will-shape-the-industrys-future/ Join the Interrupt Slack: [https://interrupt-slack.herokuapp.com](https://interrupt-slack.herokuapp.com/) Suggest a Guest: https://docs.google.com/forms/d/e/1FAIpQLSf76qnsUDznyIJfC2OXCC_dIwR8v9z1yvE3PPlOhfsNCR_sug/viewform?usp=header Follow Nordic Semiconductor: - LinkedIn: https://www.linkedin.com/company/nordic-semiconductor/ - Instagram: https://www.instagram.com/nordicsemi - Facebook: https://www.facebook.com/nordicsemiconductor - TikTok: https://www.tiktok.com/@nordic_semiconductor - Twitter (X): https://twitter.com/NordicTweets Follow Memfault: - LinkedIn: https://www.linkedin.com/company/memfault/ - Bluesky:https://bsky.app/profile/memfault.com - Twitter:https://twitter.com/memfault Other ways to listen: Apple Podcasts: https://podcasts.apple.com/us/podcast/coredump-sessions/id1804647817 iHeartRadio: https://www.iheart.com/podcast/269-coredump-sessions-271043539 Amazon Music:https://music.amazon.com/podcasts/a5a780d4-7f14-4ed8-bda6-dd1aa4e98479/coredump-sessions) GoodPods:https://goodpods.com/podcasts/coredump-sessions-668730) Castbox: https://castbox.fm/channel/Coredump-Sessions-id6534689?country=us Visit our website: https://www.nordicsemi.com/

Coredump #019 : END-OF-YEAR CELEBRATION: Moments You Loved, Stories You Missed, and 2026 Predictions
75 views

Coredump #018: Hidden Complexity of Sleep Tech: Power, Comfort, and 8 Hours of Reliability
75 views

Coredump #017: Building and Scaling a Startup in the Ultra-Competitive Health Wearables Market
120 views

Feature Highlight: Saved issue search and notifications
90 views

COREDUMP #016: From Startup to Global Brand: Scaling Engineering at reMarkable
145 views

COREDUMP #015: Developing kid-safe tech at Gabb: what it takes and why it’s so important
63 views