Compliance · · 4 min read

EU cyber law forces vendors to rethink product security

The Cyber Resilience Act is pushing technology companies toward faster reporting, integrated security data and protection built into products from the start.

The European Union’s Cyber Resilience Act is set to change how technology companies develop, monitor and sell connected products, according to reporting by CSO Online. The regulation requires manufacturers to notify authorities within 24 hours when they discover an actively exploited vulnerability or a serious incident affecting a product with digital elements.

The reporting rule, introduced on September 11, creates an EU-wide legal framework for the security of internet-connected hardware and software. Its reach is not limited to companies based inside the bloc. Any business seeking to sell covered products in the European market can be affected, regardless of where it is headquartered.

The scope includes enterprise technologies such as operating systems, routers, firewalls, virtual private networks, identity-management tools, security software and network-management systems. The requirements also extend to hardware used for demanding computing workloads, including systems supporting artificial intelligence.

Security becomes a condition of market access

Vincent Lomba, chief product security officer at Alcatel Lucent Enterprise, told CSO Online that the legislation could make cyber resilience a basic requirement for competing in international technology markets. In his view, manufacturers have often concentrated on processing performance while giving less attention to protection built into the underlying architecture.

That balance will need to change, Lomba said. Companies supplying hardware and graphics processors to Europe may have to redesign core systems so that resilience is integrated from the beginning rather than added after a product is released.

The regulation could also give an advantage to businesses that already develop products with security controls, governance and supply-chain oversight embedded in their processes. Lomba expects the EU rules to establish a wider benchmark, forcing suppliers outside Europe to raise their standards if they want to remain competitive with European companies.

The possible international effect recalls the experience of the EU’s General Data Protection Regulation. Artem Serebrov, product director at PCA Cyber Security, told CSO Online that the early stages of the Cyber Resilience Act resemble GDPR’s introduction in some respects.

He also pointed to a potential weakness. GDPR created data-breach reporting duties without requiring companies to measure the amount of data lost, he said. That may have encouraged some organisations to limit the extent of their monitoring so they could reduce the risk of large penalties. Serebrov’s comparison suggests that reporting requirements can produce unintended behaviour when organisations lack equally clear duties to establish what has happened and how serious it is.

Twenty-four hours exposes fragmented systems

For many vendors, the central difficulty will be operational rather than legal. Information needed for a notification is commonly scattered among security information and event management platforms, threat-intelligence feeds, known-exploited-vulnerability alerts, scanning tools, asset records and software bills of materials.

Those systems are not necessarily connected in a way that allows a company to identify an affected product, confirm exploitation and report accurately within one day. Joe Brinkley, director of offensive security research and community at Cobalt, said the deadline leaves little room for analysts to perform each step manually.

A team may need to match a newly disclosed vulnerability against its software inventory, locate the relevant assets and inspect current security telemetry to determine whether attackers are using the weakness. If those tasks require separate searches across several dashboards, much of the reporting window can disappear before the organisation has established the facts.

The practical consequence is a demand for automation. When a vulnerability emerges, systems will need to check software bills of materials, identify exposed assets and compare the results with live operational data. Vendors that cannot connect these sources risk spending most of the available time investigating rather than containing the problem and applying fixes.

A test of organisational readiness

Louise Horton, head of UK government affairs at NCC Group, described the new duties as a major test of operational preparedness. Organisations will need reliable vulnerability-management procedures, a clear view of product dependencies and the ability to assess and communicate incidents quickly and correctly.

That preparation begins before an incident. It includes secure development practices, oversight of suppliers and clear responsibility for decisions across engineering, security and management teams. Horton argued that companies should treat the CRA as part of a wider resilience programme rather than as a collection of separate compliance tasks.

Heigor Freitas, head of the UK and Europe region at CREST, said the regulation could strengthen the wider digital environment by improving accountability and making security practices more consistent among hardware and software manufacturers.

The pressure will also fall on chief information security officers. Their teams will need current, searchable records of products, components and dependencies, rather than static inventories prepared only for periodic compliance reviews. Software bills of materials will have to function as active operational resources that can support immediate investigation and mitigation.

For enterprise security leaders, the new standard is therefore not simply faster paperwork. It demands continuous visibility into what an organisation runs, which components those systems contain and whether a newly discovered weakness is being exploited. Under the CRA, delays in answering those questions could threaten both regulatory compliance and continued access to the European market.

cybersecurityeu regulationcyber resilience actvulnerability managementsoftware supply chainsecure by designcompliance

Continue reading

Read this in another language