Back to Webinars
Compliance & Regulations
Feb 18, 2026
1:28

Compliance Is an Artificial Adversary—Unless You Tie It to What You Ship

Compliance Is an Artificial Adversary—Unless You Tie It to What You Ship

I look at compliance and regulate regulations as kind of an artificial adversary. It's someone who's supposed to guide you towards a more secure outcome. The unfortunate reality of that, though, is it doesn't take into account the fact that your day to day risks and quantifications and mitigations don't sit at that top level in the theoretical world. They sit at the bottom level. In in this case, since we're talking specifically about software, they sit within the individual releases and products and code that's being distributed to the world. That means that as an organization, you are currently being faced with a very specific problem, which is how do I contextualize these very specific vulnerabilities, risks, attack vectors to this very kind of higher level arbitrary compliance outcome and goal. There are several different ways to do that. Many different people have accomplished it. There's checkbox exercises. I don't believe that CRA will essentially allow you to, accomplish that. But at the end of the day, you are not just likely going to be, beholden to CRA. You're likely going to be, held to several different standards.

Speakers

Dario Lobozzo
GM, EMEA at Finite StateDario Lobozzo

Share

Share on LinkedInShare on X

Related Webinars

Why Bottom-Up Vulnerability Management Breaks at Scale

Why Bottom-Up Vulnerability Management Breaks at Scale

Bottom-up vulnerability tracking works for small teams—but breaks at scale. Learn how fragmentation impacts prioritization, compliance, and security r...

eu cra
Breaking Down Silos in Product Security and Compliance

Breaking Down Silos in Product Security and Compliance

Siloed teams and one-off tools create outdated compliance. Learn why connected device security needs a continuous, cross-functional workflow.

eu cra
Why Controls-Only Compliance Fails Connected Device Security

Why Controls-Only Compliance Fails Connected Device Security

Controls assessments and gap analyses aren’t enough. Learn why compliance must connect security controls to real firmware, releases, and shipped softw...

eu cra
Explore More WebinarsExplore More Webinars

Ready to Level Up Your Security Knowledge?

Join thousands of security professionals learning from the best in the industry

Start Learning TodayStart Learning Today
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions
Finite StateFinite State
Finite StateFinite State