Structuring IoT Cybersecurity for Decathlon’s eBike System

Author
Regulations

CRA

GDPR

Decathlon set out to strengthen cybersecurity across its IoT product portfolio. The eBike system was chosen as the pilot because it packed several security-relevant components into one product: the bike itself, its control unit, embedded software, external suppliers, and the associated cloud services — a realistic cross-section of everything Decathlon would face across its connected range.

Client / Project Need

Objectives & drivers

The goal was never just to secure one bike. It was to define a structured cybersecurity approach — repeatable across future connected products — using the eBike as the proving ground. Securing the pilot mattered, but the real deliverable was a method Decathlon’s teams could run again without starting from scratch each time.

Challenge

Key hurdles

The hardest part was organizational, not technical. The eBike’s lifecycle spanned several internal teams, each with its own processes, vocabulary, and priorities. Security couldn’t be dropped in as a checkpoint at the end — it had to run through the full lifecycle, from product inception to end-of-life, in a way that fit how Decathlon’s teams already worked rather than fighting it. Getting teams that didn’t share a security vocabulary to align on one was the core of the job.

Approach

What we did

01

Mapped the full product lifecycle, from early design phases to end-of-life.

02

Identified the internal teams responsible for each part of the eBike system.

03

Organized cross-functional workshops with four internal teams covering the different parts of the solution.

04

Analyzed the system as a whole to ensure risk consistency across the bike, control unit, embedded software, suppliers, and cloud services.

05

Defined security profiles for the different products and components involved in the eBike solution.

06

Prepared the basis for a cybersecurity process that Decathlon could reuse beyond the pilot project.

07

Supported the definition of a certification strategy for the different components.

08

Structured a cybersecurity questionnaire to help assess supplier security practices and reduce supplier-related risks.

Key outcomes

Impact delivered

Lessons learned

What we took away

IoT security can’t be added at the end of development — it has to be embedded into each step of the lifecycle. But the sharper lesson is that technical expertise alone isn’t enough for complex connected products: security only takes hold when it’s translated into the language and workflows each team already uses. The challenge isn’t just identifying risks — it’s making them actionable for the specific teams that have to act on them. Decathlon already knew connected products carried cybersecurity risk; the value of the project was turning that awareness into a structured, cross-functional process spanning product security, supplier management, and future regulatory readiness.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

CRA Box Unified Standard for HWSB

Read case study →

O-RAN Security Test Plan and Assurance Program Development

Read case study →

Security Analysis of 5G Network Products

Read case study →

Contact us

Request this document

We’ll send you access by email.