Uploaded August 2026 | Updated September 2026, 9 minutes ago
Lisa Bradley (Dell Technologies, US), Sarah Evans (Dell, US)
The Cyber Resiliency Act (CRA) was passed into EU law in 2024, and the clock is ticking. Manufacturers of products with digital elements must begin actively exploited‑vulnerability reporting in 2026, with full compliance enforceable in late 2027.
This talk will share the approach taken by a large tech company, which includes analyzing requirements and intent into actionable items to drive product teams toward compliance and roadmap‑development efforts. The presenters will focus on managing third‑party risk and share how enterprise participation in foundations such as OpenSSF accelerates the internal CRA‑compliance journey, creating opportunities for enterprises to collaborate with others in the industry to improve OSS security across shared upstream OSS and upstream suppliers.
---
Dr. Lisa Bradley is a distinguished cybersecurity expert and visionary leader, currently serving as the Senior Director of Product & Application Security at Dell Technologies. With over two decades of experience in enterprise-class engineering, including 13 years in product security leadership, Dr. Bradley has established herself as a trailblazer in the field of cybersecurity and vulnerability management.
In her current role, she leads Dell’s Product Security Remediation efforts, driving initiatives such as Vulnerability Response/PSIRT, post-GA security findings remediation, the Bug Bounty Program, Product 360 Risk, and Dependency Management. She also plays a pivotal role in supporting Dell’s Software Bill of Materials (SBOM) initiative, ensuring transparency and security across the product lifecycle.
Her commitment to advancing the cybersecurity industry extends beyond her corporate responsibilities. She is a frequent speaker at industry events and podcasts, and a proud co-author of the FIRST PSIRT Services Framework, contributing to global standards in incident response. Outside of her professional endeavors, Dr. Bradley enjoys spending quality time with her three children and friends. Her unwavering dedication to cybersecurity, combined with her leadership and advocacy, continues to inspire innovation and build trust in the ever-evolving landscape of technology and cyber defense.
Sarah Evans delivers technical innovation for secure business outcomes through her role as a distinguished engineer and the security applied research program lead in the Office of the CTO at Dell Technologies. She is an industry leader and advocate for extending secure operations and supply chain development principles in AI. Sarah also ensures the security research program explores the overlapping security impacts of emerging technologies in other research programs, such as agentic AI. Sarah partners with engineering, product security, cyber security and IT teams to incorporate applied research to evolve product and business processes.
She leverages her extensive practical experience in security and IT, spanning small businesses, large enterprises (including the highly regulated financial services industry and a 21-year military career), and academia (computer information systems). She earned an MBA, an AIML professional certificate from MIT, and is a certified information security manager (CISM). Sarah is also a strategic and technical leader representing Dell in OpenSSF, a foundation for securing open-source software. Sarah is based in Denver, Colorado.
Lisa Bradley (Dell Technologies, US), Sarah Evans (Dell, US)
The Cyber Resiliency Act (CRA) was passed into EU law in 2024, and the clock is ticking. Manufacturers of products with digital elements must begin actively exploited‑vulnerability reporting in 2026, with full compliance enforceable in late 2027.
This talk will share the approach taken by a large tech company, which includes analyzing requirements and intent into actionable items to drive product teams toward compliance and roadmap‑development efforts. The presenters will focus on managing third‑party risk and share how enterprise participation in foundations such as OpenSSF accelerates the internal CRA‑compliance journey, creating opportunities for enterprises to collaborate with others in the industry to improve OSS security across shared upstream OSS and upstream suppliers.
---
Dr. Lisa Bradley is a distinguished cybersecurity expert and visionary leader, currently serving as the Senior Director of Product & Application Security at Dell Technologies. With over two decades of experience in enterprise-class engineering, including 13 years in product security leadership, Dr. Bradley has established herself as a trailblazer in the field of cybersecurity and vulnerability management.
In her current role, she leads Dell’s Product Security Remediation efforts, driving initiatives such as Vulnerability Response/PSIRT, post-GA security findings remediation, the Bug Bounty Program, Product 360 Risk, and Dependency Management. She also plays a pivotal role in supporting Dell’s Software Bill of Materials (SBOM) initiative, ensuring transparency and security across the product lifecycle.
Her commitment to advancing the cybersecurity industry extends beyond her corporate responsibilities. She is a frequent speaker at industry events and podcasts, and a proud co-author of the FIRST PSIRT Services Framework, contributing to global standards in incident response. Outside of her professional endeavors, Dr. Bradley enjoys spending quality time with her three children and friends. Her unwavering dedication to cybersecurity, combined with her leadership and advocacy, continues to inspire innovation and build trust in the ever-evolving landscape of technology and cyber defense.
Sarah Evans delivers technical innovation for secure business outcomes through her role as a distinguished engineer and the security applied research program lead in the Office of the CTO at Dell Technologies. She is an industry leader and advocate for extending secure operations and supply chain development principles in AI. Sarah also ensures the security research program explores the overlapping security impacts of emerging technologies in other research programs, such as agentic AI. Sarah partners with engineering, product security, cyber security and IT teams to incorporate applied research to evolve product and business processes.
She leverages her extensive practical experience in security and IT, spanning small businesses, large enterprises (including the highly regulated financial services industry and a 21-year military career), and academia (computer information systems). She earned an MBA, an AIML professional certificate from MIT, and is a certified information security manager (CISM). Sarah is also a strategic and technical leader representing Dell in OpenSSF, a foundation for securing open-source software. Sarah is based in Denver, Colorado.










