New device-centric vulnerability monitoring and threat intelligence platform delivers continuous visibility from development and certification through to deployment and maintenance
PCA Cyber Security, the embedded cybersecurity company, has launched PCA CERVUS, a device-centric vulnerability monitoring and threat intelligence platform providing continuous visibility of risks across embedded and connected products throughout their lifecycle.
Inspired by multiple cultures and traditions, where the stag (latin: cervus) appears in different mythologies and stories as a symbol of direction and the journey into the unknown, escorting people towards new discoveries, PCA CERVUS is designed to guide product security teams towards a clearer understanding of the risks affecting their products. It correlates vulnerability disclosures, threat intelligence and security research with product architecture, software components and software bills of materials (SBOMs), helping teams determine which vulnerabilities affect specific products, assess their exposure and prioritise action.
The platform continuously monitors for emerging vulnerabilities, exploits and threats from development and certification through to deployment and maintenance. It can be used across individual devices, product lines and entire portfolios, helping organisations identify common dependencies, recurring vulnerabilities and broader patterns of risk.
PCA CERVUS also supports the remediation lifecycle, enabling teams to track identified vulnerabilities, monitor and validate patches, and assess whether changes to affected components address the relevant security exposure. This helps organisations move beyond confirming that a vulnerability has been patched to gathering evidence that the security issue has been addressed.
Gianfranco Vinucci, Chief Operating Officer of PCA Cyber Security, said:
“Today’s world is connected. Businesses rely on millions of payment devices, industrial controllers, and connected vehicles to keep commerce moving and critical infrastructure running. Manufacturers, importers and operators responsible for these devices need continuous visibility of which products are exposed and where to act. PCA CERVUS connects vulnerabilities and threats with the components inside each device, helping teams prioritise risk, track remediation and demonstrate if security issues have been addressed.”
PCA CERVUS can import and validate an existing SBOM or support its generation where one does not already exist, giving organisations a more complete view of the software components and third-party dependencies within their products. The platform correlates these components with vulnerability intelligence and continuously monitors them for newly disclosed risks, helping teams identify where exposure originates and how it changes throughout the product lifecycle.
These capabilities help manufacturers, importers and operators strengthen processes supporting compliance with regulations and standards including the EU Cyber Resilience Act, PCI DSS, PCI PTS, RED and UNECE R155. By supporting SBOMs, vulnerability assessment, remediation tracking and continuous security monitoring, PCA CERVUS helps organisations build the visibility and evidence needed for their compliance processes, while they retain responsibility for meeting the relevant regulatory requirements.
PCA CERVUS can be used across embedded and connected products, from payment terminals and connected vehicles to industrial controllers and IoT devices. Its product-centric approach is relevant to sectors including financial services and payments, automotive and mobility, industrial automation, energy and utilities, manufacturing, consumer IoT, and medical and other connected devices.
Discover more about PCA CERVUS!
