The Cyber Security Review | Tuesday, November 29, 2022
Manufacturers selling in the EU may soon become responsible for the cybersecurity of a product throughout its lifecycle under proposed rules.
FREMONT, CA: To improve the security of hardware and software products supplied, the European Commission has presented its suggestions. The Cyber Resilience Act aims to hold manufacturers of internet-connected products accountable for cybersecurity throughout the product lifecycle. Additionally, it would enable customers to receive accurate information about the security of the goods they use and purchase.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
In a Q&A, the European Commission stated that while manufacturers of products with digital elements sometimes face reputational damage when their products lack security, the cost of vulnerabilities is primarily borne by professional users and consumers. This lessens manufacturers' incentive to spend on a secure design, development, and security updates.
The act aims to ensure that only products that meet specific essential cybersecurity requirements and take security into account during the product's design and development are allowed to be sold in the EU. Digital elements are defined as anything that can connect to the internet and may be vulnerable to cyberattacks. The Cyber Resilience Act will ensure the connected objects and software consumers buy comply with strong cybersecurity safeguards. It will place the accountability where it should be: on those who place the products on the market.
Europe is just as strong as its weakest link regarding cybersecurity, be it a susceptible member state or a dangerous product in the supply chain. Hundreds of millions of linked gadgets, including smartphones, PCs, cars, and virtual assistants, might serve as entry points for hackers. And yet, most hardware and software solutions on the market today are exempt from cybersecurity requirements. The Cyber Resilience Act will contribute to safeguarding both collective security and Europe's economy by adopting cybersecurity by design.
The European Parliament and Council are presently examining the act. Member states would have two years to adjust to the new rules if they were implemented, except for the need for manufacturers to disclose vulnerabilities, which would take effect after one year. The EU has pioneered creating a cybersecurity ecosystem through rules on critical infrastructure, cybersecurity preparedness and response, and the certification of cybersecurity products.
Taking a step that will bring security into every person's home, every business, and every connected object. Cybersecurity is no longer a business concern but a social one.
More in News