Stefan Karg
Head of Competence Center Security & Team Lead Rail Security @Ics - Informatik Consulting Systems
Signup · Get unlimited contacts
WORK HISTORY
Head of Competence Center Security & Team Lead Rail Security @Ics - Informatik Consulting Systems
Stuttgart, DE
Alignment and strategic development of the Competence Center Security within ICS- Expansion of know-how and support for internal training measures- Addressing new customers- Evaluation of promising business cases- Business Team Lead for a distributed team of specialists in the field of railway security engineering- Tailoring of IEC 62443 and CENELEC TS 50701 for our customer projects- Development of specific approaches for complex project environments- Technical and commercial project management with distributed project teams- Project Security Management- Security risk assessment according to IEC 62•••32- Securing railway applications of our customers with the help of IEC 62•••33 and IEC 62•••42 requirements- Application of CENELEC TS 50701 for railway specific security cases- Application of agile development process in safety critical environment (EN50128)
EDUCATION
Ulm University
Master’s Degree, Computer Science
Ulm University
Bachelor’s Degree, Communications and Computer Engineering
ABOUT STEFAN KARG
The Cyber Resilience Act is here. And most companies building products with digital elements are not yet ready for what\'s coming.Cybersecurity risk assessments for every product. Risk-based decisions on security requirements. Vulnerability handling processes. Security updates over the entire product lifecycle. Reporting of actively exploited vulnerabilities and severe security incidents within 24 hours. The CRA doesn\'t just ask for documentation - it demands that security is engineered into products from the very beginning and maintained until end of support.For many organizations, this feels overwhelming. For me, it feels familiar.My home turf is railway cybersecurity - one of the most regulated, most safety-critical environments you can work in. For nearly eight years, I\'ve been working on securing systems where failure doesn\'t mean downtime – it means danger. I\'ve driven security risk assessments according to IEC 62443, shaped security cases following CENELEC TS 50701, and guided operators and suppliers across Europe through the processes necessary to protect critical infrastructure – from conducting assessments myself to leading distributed teams of specialists across multiple locations and countries.Before I moved into security, I spent three years as a software engineer - mostly focused on developing SIL 4 safety-critical code for the European Train Control System (ETCS). I know what it means to build products under extreme regulatory pressure, and I know the difference between compliance on paper and security in practice.That background shapes everything about how I approach the CRA. The principles are the same: lifecycle thinking, risk assessments as the foundation for risk-based decision making, traceability between requirements and evidence.Now I bring that experience also to the challenge that the CRA puts in front of product manufacturers, importers, and distributors. Helping them understand what the regulation actually requires. Identifying where the gaps are. And building the processes, the documentation, and the engineering practices that make products genuinely secure - not just compliant on paper.I\'m especially drawn to products connected to critical infrastructure. These are the systems a functioning society depends on - and the consequences of failure aren\'t abstract. That\'s exactly why I do this work: because when these systems fail, it\'s not only revenue at risk - it\'s people\'s safety.If the CRA is keeping you up at night, let\'s talk. You can reach me through Informatik Consulting Systems GmbH.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.