WUELUG#28: Cybersecurity Reloaded

The 28th Würzburg LabVIEW User Group was all about cybersecurity — from the legal perspective (the EU Cyber Resilience Act) and technical implementation in LabVIEW (TLS, sandboxing) to the tools HSE uses to automate cybersecurity requirements as part of the release process. HSE hosted the meeting at their premises at the Bürgerbräugelände in Würzburg

Jörg Hampel, Oli Wachno, Manuel Sebald and Julian Schary – the WUELUG28 speakers

EU Cyber Resilience Act

Oli Wachno kicked off the presentations with his concise, practical overview – explicitly not legal advice – of multiple pieces of EU legislation taking effect around the same time: the Product Safety Regulation, which is already in force, the Product Liability Directive, which must be implemented by 9 December 2026, the implementation of NIS2 (since 5 December 2025) and the Cyber Resilience Act (CRA), which will be fully applicable by the end of 2027.

Oli giving an overview of the upcoming EU legislation’s implications

To summarize: Software will be considered a product in the future — with CE marking requirements. The CRA applies to all connected products with digital elements (exceptions: certain medicine products & FOSS). It requires manufacturers to carry out risk assessments, provide technical documentation, offer at least five years of support, and report through a central reporting point. For actively exploited vulnerabilities, a strict reporting timeline applies: 24 hours / 72 hours / 14 days. The specific conformity assessment procedure depends on the criticality of the product. For existing products placed on the market before 11 December 2027, obligations apply only if the product undergoes a “substantial modification” – reporting obligations, however, apply immediately.

In Practice: Anyone who distributes connected LabVIEW/TestStand systems should check early on, if and how the CRA applies – especially concerning SBOM, vulnerability management and documentation.

TLS encryption in LabVIEW

Manuel Sebald started with the basics: What is TLS (Transport Layer Security) anyway and what are its three cornerstones:

  • Confidentiality (data is transmitted in encrypted form and thus unreadable by third parties)
  • Integrity (data manipulation during transmission can’t go unnoticed)
  • Authenticity (identity of peers is verified using certificates)

Afterwards, he presented three demos of using TLS in LabVIEW, highlighting what an exterior observer can notice in the telegrams – bridging the gap between theory and actual code implementation.

Sandboxing LabVIEW

Julian Schary explained that simply installing LabVIEW already considerably increases a system’s attack surface – without adding any custom code. He pointed to two examples: outdated, included OpenSSL drivers which don’t automatically patch CVEs as well as NI Service Locator which opens various ports by default without the user noticing or configuring it.

Seeing the bigger picture: Remembering the first presentation – the CRA also requires (Article 13(5)) due diligence for third-party components like the platform foundation provided by NI.

HSE Release Automation Tools & Cybersecurity

Jörg Hampel showcased how we at HSE integrate fulfilling cybersecurity requirements directly into our Release Automation Tools – a very hands-on complement to the proceeding, more conceptual presentations. New features include among others:

  • Artifact Signing – digital signing of release artifacts
  • Hashing of Artifacts – enabling integrity checks
  • SBOM Generation (Software Bill of Materials) – automatically during the build process, also exposing third-party components like those mentioned by Julian (e.g. OpenSSL-Version)
  • Declaration of Conformity generation
  • Static Code Analysis concerning cybersecurity-related issues, e.g. secrets in the block diagram

This is HSE’s technical response to many of the requirements of the CRA (SBOM, documentation, vulnerability management) – and expands on Julian’s sandboxing approach by documentation and legal declarations.

Socializing & Networking

As always, there was enough room for interesting conversations over cool drinks and tasty pizza. 🍕🔒

WUELUG28 crowd

TL;DR: WUELUG28 has been an absolute rollercoaster starting with a lot of concern about the upcoming responsibilities, before Manuel and Julian demonstrated how to catalyze this fear into productive solutions – TLS for the exterior communication as well as sandboxing for outdated components. Finishing off, Jörg showed off HSE’s approach of automating the new technical duties. In short: tons of new information, a little bit of concern, but returning home with a good feeling (and hopefully up-to-date OpenSSL 😉).

Outlook

WUELUG29 is scheduled for some time in October of 2026. We’re certain it will be as much of a valuable event as always to share insights, demonstrate new ideas and present to the community. Furthermore, we’re still looking for a host thrilled to showcase their company and work for an evening. It’s both a great opportunity for the host and a welcome change of pace for the participants.

See you at the next WUELUG

Leave a Reply

Your email address will not be published. Required fields are marked *