Zyxel Networks has introduced a strengthened product security governance framework, cementing its long-term commitment to small and medium-sized businesses (SMEs) and managed service providers (MSPs). With this initiative, the company seeks to facilitate regulatory compliance and strengthen protection against an increasingly complex cyber threat landscape.

The entry into force of the European Union Cyber ​​Resilience Act (CRA), scheduled for September, redefines the responsibility of manufacturers by requiring transparent and verifiable security governance throughout the entire product lifecycle. At the same time, Mandiant research identifies software vulnerabilities as the main initial attack vector and warns that cybercriminals are already using artificial intelligence to accelerate these types of threats. In this context, SMEs and MSPs, often operating with limited resources, need to rely on vendors that offer demonstrable governance and security capabilities.

Following recent enhancements across its entire solutions portfolio, Zyxel Networks now unifies all of its capabilities under a comprehensive product security governance approach. The goal is to provide stronger, more integrated protection to both SMEs and MSP partners, facilitating the secure deployment and management of network infrastructures.

“Cybersecurity can no longer be based on promises alone,” said Edward Yu, Chief Information Security Officer at Zyxel Group. “As cyber threats and regulatory demands, such as the EU CRA, increase, so do expectations regarding manufacturer liability. Trust must be underpinned by verifiable and continuously enforced security governance. “Transparency throughout the product lifecycle allows us to reduce blind spots, make more informed decisions and strengthen the cyber resilience of organizations.”

For his part, Ken Tsai, President of Zyxel Networks, highlights the value of this approach for the channel: “SMEs and MSPs face constant pressure to improve their cyber resilience while managing increasingly complex IT environments. Integrating security from the source throughout the network infrastructure reduces the need for subsequent corrective measures, reduces costs and accelerates implementations. “This way, our MSP partners can deploy solutions faster, simplify compliance audits, and offer their customers a more robust and reliable network infrastructure.”

Security by design as an operational commitment

Rather than considering cybersecurity as an add-on, Zyxel Networks incorporates Security by Design principles into all phases of product development, vulnerability management, and lifecycle governance. This strategy is articulated around three fundamental pillars.

Security by design in all products and services

Zyxel Networks was the first Taiwanese company and the first global SMB networking brand to join the CISA Secure by Design Pledge, an initiative aimed at reducing operational risks and facilitating the implementation of secure environments for organizations and MSPs.

As part of this commitment, the company has incorporated passwordless login for Zyxel accounts and multi-factor authentication (MFA) across its portfolio of products and services, including wireless networks, management access and remote VPN connections. Additionally, it follows the principles established by CISA by removing default passwords and proactively reducing entire categories of vulnerabilities from the development phase.

Reference Security Governance for Manufacturers and MSPs

Zyxel Group’s Product Security Incident Response Team (PSIRT), created almost a decade ago, collaborates closely with security researchers around the world through a transparent vulnerability disclosure policy and a coordinated response and remediation process.

Thanks to its high governance standards, Zyxel is part of a small group of CVE Numbering Authorities (CNA) in the networking industry that has the dual Provider Acceptance Levels designation, along with manufacturers such as Cisco, Juniper and F5. Likewise, the Zyxel Group has recently joined as a full member of the Forum of Incident Response and Security Teams (FIRST), reinforcing its capacity for international collaboration in the coordinated management of cybersecurity vulnerabilities and incidents.

Transparent product lifecycle management

Zyxel Networks also maintains a transparent lifecycle management policy for its products, guaranteeing security updates and support during clearly defined periods.

By offering visibility into the different support phases and end-of-life dates of its solutions, the company makes it easier for both SMEs and MSPs to more safely plan their technological investments, replace obsolete equipment and protocols before they generate risks, and maintain infrastructures aligned with the requirements of the future Cyber ​​Resilience Law of the European Union.