TheRoad

TheRoad TheRoad TLV helps founders and product teams build hardware that competitors can't copy and customers won't leave.

Strategy, product definition, and industrial design for smart hardware, IoT, and software-augmented products.

do you run a business, and need to follow up on marketing motions?
05/09/2026

do you run a business, and need to follow up on marketing motions?

Single-user outreach CRM. No database, no build step, no seats. Clone, run, done. - yoelf22/barebonesCRM

In sixteen days the EU starts a clock on every connected product sold into Europe. From 11 September, once you know a vu...
26/08/2026

In sixteen days the EU starts a clock on every connected product sold into Europe. From 11 September, once you know a vulnerability in your product is being actively exploited, you have twenty-four hours to file a first report with ENISA, and seventy-two for the full notification.

That is not the requirement most hardware teams have been preparing for. The Cyber Resilience Act does not ask whether your product is secure. It asks whether you noticed. Noticing is a capability, and almost nobody bought it.

Most connected devices ship with no fleet telemetry worth the name, so you learn about exploitation the way manufacturers always have — a customer complains, a researcher publishes, or a journalist calls. In 2015 Charlie Miller and Chris Valasek took over a Jeep Cherokee on a St. Louis highway from ten miles away, and Fiat Chrysler recalled 1.4 million vehicles, mailing owners a USB stick so they could patch their own cars. That counted as a fast response at the time. Under the rule that starts on 11 September, the first report would have been due before most of that company knew anything had happened.

Here is the part worth arguing about. The teams who find this trivial are the ones who already built the dull software layer: device identity, signed over-the-air updates, telemetry that reports something other than uptime. They built it to run a business on the installed base rather than to satisfy a regulator, and the compliance falls out of it for free. Everyone else is about to find that the certificate on the box was never the security story — the ability to see and to fix was.

So which is it: a twenty-four hour clock as a compliance tax on hardware, or the first regulation that actually pays back the companies who invested in the software layer?

A $99,000,000 Right-To-Repair Problem=======================================John Deere just lost a wall it spent years b...
12/08/2026

A $99,000,000 Right-To-Repair Problem
=======================================
John Deere just lost a wall it spent years building. Last month the FTC forced it to give farmers the same repair software and diagnostics as its own dealers — for the next ten years. Second settlement this year; a $99M class action landed in the spring.

Here's why every hardware founder should care, because Deere didn't do anything exotic. It ran the playbook half the connected-hardware industry now copies: pair each part to the serial number so a swap won't work until a dealer authorizes it, put diagnostics behind a dealer login, turn repair into a channel you control. On a spreadsheet it's gorgeous — recurring revenue, a captive base, switching costs that compound every year.

But repair lock-in isn't a moat. It's a liability with a delay. It reads as recurring revenue right up until a regulator reclassifies it as an antitrust problem — and then the margin you built on becomes a consent decree you operate under for a decade. You lose the revenue and inherit the cost of proving you stopped.

The tractor is just the visible case. Every connected product now ships with the same temptation: use the software layer to decide who repairs it, which parts work, what the customer can do after the sale. The harder you lock people out, the better it looks in the board deck — and the bigger the target on your back. The durable version of that instinct was never control. It's being the product customers won't leave, not the only one that's legal.

So where's the line — which switching costs are a real moat, and which are just a toll booth waiting for a regulator?

My recent blog post discusses what happens to high hopes when base layers aren't fulfilled (in this case in connected ai...
05/08/2026

My recent blog post discusses what happens to high hopes when base layers aren't fulfilled (in this case in connected ai products)

Rabbit and Humane made opposite bets in 2024 – cheap and fast against beautiful and expensive – and died the same death, on a layer neither of them owned. An…

read my latest article:
05/08/2026

read my latest article:

A connected product keeps learning after it ships. The data payload is where a static device quietly turns into a platform.

My article on IoT For All:
03/08/2026

My article on IoT For All:

A connected product keeps learning after it ships. The data payload is where a static device quietly turns into a platform.

Address

19, Ha'Arbaah Street
Tel Aviv

Opening Hours

Monday 09:00 - 17:00
Tuesday 09:00 - 17:00
Wednesday 09:00 - 17:00
Thursday 09:00 - 17:00
Sunday 09:00 - 17:00

Alerts

Be the first to know and let us send you an email when TheRoad posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share