Zyxel expands security governance for SMB networking
Wed, 29th Jul 2026 (Today)
Zyxel Networks has introduced an expanded product security governance framework for its networking products and services, with a focus on supporting small and medium-sized businesses and managed service providers.
The framework embeds security governance into product development, vulnerability management and lifecycle management as cyber threats increase and regulators demand clearer product accountability.
Zyxel has signed the US Cybersecurity and Infrastructure Security Agency's Secure by Design pledge, making it the first company in Taiwan and the first global SMB networking vendor to do so. The commitment includes passwordless login support for Zyxel accounts and multi-factor authentication across products and related services, including wireless access, administrator logins and remote VPN access.
It has also removed default passwords and worked to reduce broad categories of vulnerabilities during development. The move comes as the EU Cyber Resilience Act places greater emphasis on transparent and verifiable security practices across the full lifecycle of connected products.
Security standing
Zyxel also highlighted the Zyxel Group's Product Security Incident Response Team, which has operated for nearly a decade. The team works with external security researchers through a vulnerability disclosure policy and a coordinated fix process.
The Zyxel Group is also among a small group of networking industry CVE Numbering Authorities to hold dual Provider Acceptance Levels, placing it alongside Cisco, Juniper and F5 by that measure. It has also been approved as a full member of the Forum of Incident Response and Security Teams, known as FIRST, a global body focused on incident response and security cooperation.
Those credentials matter as software exploits remain a major route for cyber intrusions. Zyxel cited research from Mandiant identifying software exploits as the leading initial attack vector, and noted that attackers are using artificial intelligence to accelerate such attacks.
For smaller businesses and service providers with limited security resources, supplier choice is becoming more closely tied to governance practices rather than product claims alone. Networking providers face growing scrutiny over how quickly they identify vulnerabilities, how openly they disclose them and how long they support products in the field.
Lifecycle focus
A central part of Zyxel's approach is a published product lifecycle management policy that sets out support phases and maintenance timelines. This gives customers clearer visibility into when products will receive updates, when support will end and when older systems should be replaced.
That visibility has become more important as businesses review the security risks tied to ageing hardware and legacy network protocols. Managed service providers in particular face pressure to keep client systems updated while controlling costs and avoiding disruption.
Edward Yu, Chief Information Security Officer of the Zyxel Group, said the emphasis on transparency reflects wider change in the market.
"Cybersecurity today can no longer rely on promises alone," said Edward Yu, Chief Information Security Officer, Zyxel Group.
"As cyber threats intensify and global regulations such as the EU CRA raise expectations for product accountability, trust must be earned through verifiable, day-to-day security governance. Transparency across the product lifecycle helps organizations reduce blind spots, make more informed decisions and strengthen overall cyber resilience."
Zyxel is presenting the framework as a response to both operational and compliance demands on its customer base. SMBs and MSPs are increasingly expected to demonstrate that systems are secure by default, patched in a timely way and supported under clear governance rules.
Gary Chen, ANZ Regional Head at Zyxel Networks, said customers want to avoid the burden of extensive manual hardening after deployment.
"SMBs and MSPs are under growing pressure to strengthen cyber resilience while managing increasingly complex IT environments," said Gary Chen, ANZ Regional Head, Zyxel Networks.
"Embedding out-of-the-box security across the entire network infrastructure minimizes the costly, time-consuming manual hardening afterwards. This empowers our partners to deploy faster, simplify compliance audits and deliver a resilient network foundation that wins client trust."