H-X Tech.

H-X Tech. We assess, develop, implement, certify and maintain secure systems. We teach security. Add our deep IT and cybersecurity expertise to your projects.

Mandatory CRA reporting starts on 11 September 2026On 27 July 2026, the European Commission published new practical guid...
07/08/2026

Mandatory CRA reporting starts on 11 September 2026

On 27 July 2026, the European Commission published new practical guidance on applying the Cyber Resilience Act. It clarifies the scope of the CRA, substantial product modifications, support periods, cybersecurity risk assessments and reporting obligations. With 67 practical examples and visual decision aids, the non-binding guidance shows how the Commission expects organizations to apply the Regulation in practice.

Most CRA requirements take effect on 11 December 2027, but Article 14 reporting obligations begin much earlier — on 11 September 2026.

Learn more at https://www.h-x.technology/news/mandatory-cra-reporting

H-X Technologies expands its compliance practice across SOC 2, NIS2, DORA, and MiCAFor many years, some of the most requ...
05/08/2026

H-X Technologies expands its compliance practice across SOC 2, NIS2, DORA, and MiCA

For many years, some of the most requested H-X Technologies services have been security compliance audits, together with the implementation and ongoing support of ISO 27001 and GDPR. These projects help organisations not only prepare for an external assessment but also establish effective risk management, data protection, incident response and business continuity processes.

More recently, we have seen a notable increase in requests related to SOC 2, NIS2, DORA and MiCA.

Learn more at https://www.h-x.technology/news/iso27001-gdpr-soc2-nis2-dora-mica

H-X Technologies at Incrypted Conference 2026In June 2026, the H-X Technologies team attended Incrypted Conference 2026 ...
22/06/2026

H-X Technologies at Incrypted Conference 2026

In June 2026, the H-X Technologies team attended Incrypted Conference 2026 — one of the most visible meeting points for the Eastern European Web3 community. Web3 and AI are moving closer together, and both areas need security from the earliest stages of design. The risks are technical, organizational, legal, and reputational at the same time. Learn more https://www.h-x.technology/news/h-x-technologies-at-incrypted-conference-2026

AI Security in 2026.LLMs have become part of real business processes. RAG, AI agents, MCP, and corporate integrations ha...
11/06/2026

AI Security in 2026.

LLMs have become part of real business processes. RAG, AI agents, MCP, and corporate integrations have expanded the attack surface. Direct and indirect prompt injections, data leaks, supply chain risks, RAG weaknesses, excessive agent autonomy, and insufficient monitoring have become practical problems, not merely research topics. OWASP, NIST, ISO/IEC, SANS, and the EU AI Act have formed a more mature set of reference points, but they have also shown that it is impossible to create one universal engineering or regulatory structure for all AI systems. A combination of strategic governance, architecture, controls, testing, and operations is required.

Learn more https://www.h-x.technology/blog/ai-security-in-2026

Developers across the planet are under attack. Mythos showed this is only the beginning.Every so often the industry gets...
09/06/2026

Developers across the planet are under attack. Mythos showed this is only the beginning.

Every so often the industry gets news after which you can no longer pretend everything is following the old script. In the spring and summer of 2026, two such pieces of news arrived at once.

The first is a new wave of attacks on software supply chains. Attackers have shifted their focus far deeper — away from users’ computers and servers and onto the machines and tools of the developers who build software. This isn’t a single attack or a single compromised package, but a whole tangle of them: Megalodon, Mini Shai-Hulud, Glassworm, and compromises of npm, PyPI, GitHub Actions, VS Code and OpenVSX extensions, as well as CI/CD environments and OIDC tokens.

The second is the interim results of Anthropic’s Project Glasswing and its Claude Mythos Preview model. It has already found thousands of serious vulnerabilities in critically important software. Its productivity is telling. In just a few weeks, Mythos and around 50 Anthropic partners uncovered roughly 23,000 findings, of which more than 6,000 are high- and critical-severity vulnerabilities. For comparison: across all of 2025, about 48,000 CVEs were registered worldwide. In other words, a single tool produced, in weeks, a stream of findings comparable to several months of vulnerability registration across the entire planet.

Both stories are signs of a new front line in the war with attackers — and of a fundamental shift in application security. Let’s look at this news more closely, starting with the first.

Learn more https://www.h-x.technology/news/new-front-line-application-security

From vendor dependency to digital resilienceDigital resilience is no longer only about firewalls, backups and incident r...
18/05/2026

From vendor dependency to digital resilience

Digital resilience is no longer only about firewalls, backups and incident response. For many European organisations, it is also about understanding how much of their critical work depends on a limited number of external technology providers — and what would happen if those dependencies became legally, commercially or operationally difficult to maintain.

This does not mean that every organisation should immediately replace well-known commercial software. In many cases, products from global vendors remain secure, mature and cost-effective. But it does mean that boards, CISOs and IT leaders should understand their dependency map, know where vendor lock-in exists, and have a realistic exit strategy for the systems that matter most.

At H-X Technologies, we approach this topic as a cybersecurity and resilience challenge, not as an ideological choice.

Learn more https://www.h-x.technology/blog/from-vendor-dependency-to-digital-resilience

30/04/2026

In our new video, we share a black box pentest case study for a SaaS company in the United States. ✅

Our team conducted the assessment without any prior access to internal information to evaluate which vulnerabilities could be identified from an external attacker’s perspective. ⚠️

The main goal of the project was to uncover weaknesses in the IT infrastructure and help the client strengthen their cybersecurity posture.

In the video, we walk through our approach, key stages, and the results of the engagement.

https://www.h-x.technology/case-group/penetration-testing-audit

In 2025–2026, we updated our standards for external projects, report preparation rules, confidentiality requirements, ap...
28/04/2026

In 2025–2026, we updated our standards for external projects, report preparation rules, confidentiality requirements, approaches to working with AI, document management, BCP, and methods for verifying pentest results. These improvements help us deliver cybersecurity projects in a predictable, evidence-based, and client-focused way. Learn more https://www.h-x.technology/news/kaizen-continuous-improvement.

27/04/2026

Are you confident your business is truly protected or just hoping for a break?

ISO 27001 isn't about paperwork and routine. It's about managing risks that could cost you customers, money, and reputation.

Why companies pursue certification:

- To avoid having to justify themselves to clients after an incident
- To win deals where security is a must-have
- To resolve regulatory concerns before they become a problem
- To stop "putting out fires" and start managing risks

What this means:

- Fewer vulnerabilities mean fewer losses
- More trust and more contracts
- Clear processes instead of chaos

ISO 27001 isn't an expense.
It's a filter: either you're playing at the market level, or you're left out.

Ready to find out for free where you really stand?

https://service.h-x.technology/iso-27001-checklist

Address

Colentina

Alerts

Be the first to know and let us send you an email when H-X Tech. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to H-X Tech.:

Share