Marc Herren
Senior IT-Beratung | Kubernetes Experte | DevOps Spezialist | ML/AI Enthusiast
remmen.io

The presentation begins with an overview of the CRA’s purpose and scope. It examines how this regulation addresses growing cybersecurity concerns, from vulnerabilities in connected devices to supply chain security issues, and its relevance to engineering teams.
The second part outlines what organizations can expect as the CRA is implemented, including adaptation periods, reporting requirements, and compliance considerations that will affect product development cycles.
The main focus highlights a practical DevSecOps approach to address CRA requirements through automation. The concept of not only «shifting left» (integrating security earlier in development) but also «shifting down» (embedding security into the platform layer) demonstrates how open-source tools create a security foundation that reduces manual overhead.
Making complex DevSecOps challenges disappear through platform engineering magic! I work as a platform engineer with Kubernetes, cloud-native technologies, and AI-enhanced automation. As such, I do a lot of development using infrastructure as code and CI/CD pipelines.
I’m also the founder of remmen.io GmbH, where I work as an AI coach, helping teams and individuals navigate AI implementation, digital sovereignty, and automation workflows.
With 25 years of experience in datacenters, networking, and automation, I’ve helped numerous teams master platform engineering challenges. My Linux journey started in 1995, and I’m passionate about emerging technologies, especially AI in automation. I regularly speak at conferences and events, sharing insights on platform engineering and AI adoption. Outside of work, you’ll find me spending time with family, strategizing over board games, mixing tracks as a DJ, or diving into sci-fi literature.