The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Industrial Security Podcast
The Industrial Security Podcast artwork

NIS2 and the Cyber Resilience Act (CRA) [The Industrial Security Podcast]

The Industrial Security Podcast · 2025-07-28 · 54 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber13 / 20
Specificity & Evidence11 / 20
Conversational Craft14 / 20

The European Union is reshaping its cybersecurity landscape through two major regulatory instruments. NIS2, a directive requiring national transposition, sets minimum cybersecurity standards for critical sector entities - but only ten EU member states have fully implemented it as of early 2025, with fourteen others publishing drafts and two showing no public progress. This fragmented approach creates significant compliance challenges for multinational companies, as each country adds its own interpretations and expansions; Italy included the cultural sector while France added educational institutions, moving well beyond the directive's minimum standards.

Meanwhile, the Cyber Resilience Act (CRA) represents an even broader shift: it's an EU regulation (not a directive) imposing direct cybersecurity requirements on all digital products sold in Europe - from smartphones to wearables to industrial control systems. Unlike NIS2's entity focus, CRA applies to manufacturers, importers, and distributors regardless of their location, making it potentially the world's strictest product cybersecurity regulation. Manufacturers must comply with detailed annexes (Annex One), conduct ongoing cyber risk assessments throughout product lifecycles, provide free security updates, manage vulnerabilities with software bills of materials, and report security incidents. The CRA's breadth and global applicability suggest it could become the de facto worldwide standard, similar to how GDPR shaped global privacy practices.

Key takeaways

  • →Only 10 of 27 EU member states have fully transposed NIS2 into national law despite the October 2024 deadline, forcing companies to navigate divergent national implementations with no centralized repository or single reporting portal.
  • →The Cyber Resilience Act applies directly to all digital products (software, hardware, and components) sold in the EU market regardless of manufacturer location, making it the world's first horizontal cybersecurity regulation for products and likely a global compliance baseline.
  • →Manufacturers under CRA must comply with Annex One cybersecurity requirements, conduct continuous cyber risk assessments throughout product lifecycles, provide free security updates, maintain software bills of materials, and report security incidents - obligations that extend to importers and distributors.
  • →NIS2 reporting obligations vary by member state; unlike SEC disclosure rules, incidents are reported only to national authorities (not publicly) and only if they meet 'severe' thresholds, with some countries implementing single-portal solutions while others require multiple filings.
  • →Italy, France, and Belgium have all expanded NIS2 scopes beyond the directive's minimum standard, with Italy adding cultural sector regulations and France including educational institutions, creating inconsistent compliance landscapes across Europe.

Guests

Christina Kiefer

Topics in this episode

GDPRCyber Resilience Act (CRA)software bill of materialsvulnerability managementNIS2 directiveAnnex One cybersecurity requirementsEuropean Union cybersecurity regulationCritical infrastructure designationIncident reporting obligationsProduct safety regulations

Questions this episode answers

Has NIS2 been fully implemented across all EU member states?

As of early 2025, only 10 EU member states (Belgium, Finland, Greece, Italy, and others) have fully transposed NIS2 into national law, with 14 additional countries publishing draft legislation and 2 (Sweden and Austria) showing no public progress despite the October 2024 deadline. The EU Commission launched infringement proceedings against 23 member states in late 2024 due to missed deadlines.

Do companies need to report cybersecurity incidents to each EU member state separately under NIS2?

Yes, companies must report severe security incidents to each national authority of the EU member states where they operate. There is no single EU-wide reporting portal, though some member states are implementing national portals or schemes to transfer reports to other relevant authorities. Unlike SEC rules, these incident reports are not published to the public.

What is the Cyber Resilience Act and who does it apply to?

The CRA is an EU regulation (not a directive) that applies directly and uniformly across all member states, imposing cybersecurity requirements on all products with digital elements - including software, hardware, and components - sold in the EU market. It applies to manufacturers, importers, and distributors regardless of whether they are based in the EU, giving it global impact similar to GDPR.

What are the five core obligations manufacturers face under the Cyber Resilience Act?

Manufacturers must: (1) comply with Annex One cybersecurity requirements and declare conformity; (2) conduct cyber risk assessments throughout the entire product lifecycle; (3) provide free security updates throughout the expected product life; (4) report security incidents; and (5) maintain mandatory technical documentation.

Are automobiles covered by the Cyber Resilience Act?

No, automobiles are exempt from CRA because they are already regulated by specific product safety laws. However, other products with digital elements such as wearables, headphones, and smartphones are fully covered by CRA requirements.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode provides clear regulatory overviews of NIS2 and CRA with some practical examples (Italy adding cultural sector, Belgium adhering closely to directive minimums), but much of the content consists of definitional explanations and repetitive confirmations rather than novel insights. The discussion of vulnerability management and the smart fridge example add value, but substantial portions cover ground that would be accessible through reading the regulations themselves.

Italy has expanded the scope of application so Italy has for example included the cultural sector as an additional regulated area
products with digital elements may only be placed on the EU market if they don't contain any known exploitable vulnerabilities

Originality

10 / 20

The episode largely summarizes regulatory text rather than offering fresh interpretations or contrarian takes. The smart fridge and Linux vulnerability discussions provide some practical questioning, but the core analysis follows standard legal explications. Andrew's comparison to GDPR's global impact and mention of the Maria botnet are reasonably insightful but not deeply original observations.

it sounds me like the CRA could very well turn into that kind of thing...It might be the thing that all manufacturers that embed a CPU in their product have to follow worldwide
a million fridges set to a set point that's unsafe...we need to design safety critical consumer appliances in such a way that the unsafe conditions cannot be brought about by a cyber attack

Guest Caliber

13 / 20

Christina Kiefer is a qualified legal expert from a reputable EU law firm with demonstrated deep knowledge of cybersecurity regulation. She has practical experience advising companies on compliance. However, she is a lawyer/consultant rather than a practitioner who has implemented these requirements at scale in an operating company, which limits her caliber for a B2B operations audience seeking implementation wisdom.

I'm an attorney at law working as a senior associate at our digital business unit in the law firm Vouch Law
I advise companies and also public institutions on your complex issues in the areas of data protection cybersecurity but also IT and contract law

Specificity & Evidence

11 / 20

The episode includes specific country examples (Belgium, Italy, France, Greece, Finland) and names particular regulatory instruments (NIS2, CRA, GDPR, Annex I). However, concrete implementation metrics are sparse - no dollar figures for penalties, no timelines for actual enforcement actions, and limited real-world case examples. The smart fridge and Linux kernel discussions lack specific numbers or named vulnerabilities.

ten countries have for fully transposedness to international law so for example Belgium Finland Greece or Italy
the SEC disclosures are public everyone can see them because reasonable people need information to buy and sell shares

Conversational Craft

14 / 20

Andrew asks clarifying follow-up questions and challenges vague answers (e.g., pressing on whether disclosure is actually increasing or decreasing, questioning the practical feasibility of zero-known-vulnerabilities for Linux-based devices). He also offers substantive pushback on the smart fridge safety argument. However, Christina's answers often circle back to generalities, and Andrew doesn't consistently press harder when she retreats to "it depends on risk assessment." Some interviews softer than needed.

I wonder I speculate whether increased incident disclosure rules are in fact reducing disclosures because lawyers see that disclosing too much information can result in lawsuits
Practically speaking, how does that work? I mean a lot of manufacturers in the industrial space use Linux under the hood...Do I have to suspend shipments the day that Linux vulnerability comes to light

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

national38cybersecurity37products33product31directive30security25member25obligations24market23risk23already22states22check21report19digital17first17

Episode notes

NIS2 legislation is late in many EU countries, and the new CRA applies to most suppliers of industrial / OT computerized and software products to the EU. Christina Kiefer, attorney at reuschlaw, walks us through what's new and what it means for vendors, as well as for owner / operators.

Full transcript

54 min

Transcribed and scored by The B2B Podcast Index.

SONS two is focusing on cybersecurity of entities, and the CIA is focusing on cybersecurity for products with digital elements. Welcome everyone to the Industrial Security Podcast. My name is Nate Nelson. I'm here with Andrew Ginter, the vice president of Industrial Security at Waterfall Security Solutions, who's going to introduce the subjects and guest of our show today.

Andrew, how's it gone. I'm very well, Thank you, Niate. Our guest today is Christina Kiefer. She is an attorney at law and a senior associate in the Digital Business department of Reuschlaw, and she's going to be talking to us about cybersecurity regulation in the European Union.

You know, as we all know, NIS two is coming, and there's other stuff coming too. Then, without further ado, here's your conversation with Christina. Hello Christina, and welcome to the podcast. Before we get started, can I ask you to say a few words, you know, introduce yourself and your background and tell us a bit about the good work that you're doing at Reuschlaw.

Yes, of course. So, first of all, thank you very much for the invitation. I'm very happy to be in your podcast today. So yeah to me.

My name is Christina Kiefer. I'm an I'm an attorney at law working as a senior associate at our digital business unit in the law firm Vouch Law. We are based in Germany and Reuslaw is one of Europe's leading commercial law films specialized in product law and for more than twenty years, our team of approximately thirty experts has been advising companies in dynamic industries both nationally but also internationally. And for me myself and my daily work, I advise companies and also public institutions on your complex issues in the areas of data protection, cybersecurity, but also IT and contract law.

And one focus of my work is at supporting clients in introduction of digital products in the EU market and also looking at the field of cybersecurity and IT law. Since my studies I have already focused on IT law and cybersecurity and yes I have been involved in the legal developments since then in this area. And our topic is you know, the law in Europe for cybersecurity, it's regulation. The big news in Europe is of course NIS too, and it's not a law, it's a directive to the nation states to produce laws to produce regulations.

So every country is going to have its own laws. Can I ask you for an update? How's that going? Who's got the law?

I thought there was a deadline, you know the nations of Europe have this covered or is it still coming? Yeah, so it's the last point, so it's still coming. Some countries have already transposed in this two directive international law, but also a lot of countries are still in the developing and the transposition yeah period. And that's where we YE are confusing because theen it's two directive, it's already or has already been informs since generally twenty twenty three.

And also the deadline for the new member states to impose in this two directive international law was the October twenty twenty four. So because of that, because of a lot of member states haven't transposed in this to directive international law, the YOU Commission has launched an infringement proceeding against twenty three member of states last fall in twenty twenty four. And this yeah, has led to some movements and some new member states. So as of.

Now ten countries have for fully transposedness to international law. So for example, Belgium. Finland, Greece or Italy, and then another fourteen countries have published at least some draft legislation so far, and there you can call Bulgaria, Denmark and also Germany. And then there are also two countries it's Sweden and Austria, and those two year members days they have not published neither a draft or also in final national law.

So there we have no public information available on their implementation status. Yet. You know, someone watching this from the outside with you know, a command of English and a very limited command of German. Is there sort of a standard place that a person like me looking at this from the outside could go to find and all this stuff or is it on every country's national website in a different language, in a different location.

Is there any central repository of these rules? No, not yet. At least maybe there will be some private websites where you can find all the different implementation informations. But until now, when you are a company either within the EU or rs ADU, when you are providing your services into the EU market, you have to fulfill with the IS two directive, and this means you have to fulfill with the national laws in each U member states.

And this is a big challenge. For all international companies because they have to check each national law of each EU member states and they have to check if they fall under the scope of application. And what is also very important that the different national laws have different obligations. So then is two directive has a minimum standard which a national legislators have to fulfill.

But on top of this, some EU member states have imposed more obligations or a portal for registration or new reporting obligations, so you have to check for each EU member state. But here we can also help because we see in. Our daily work that this is a very very hard you challenge for companies to check all the laws and to also understand all the national laws. We offer an to implementation guide where you can get regularly updates on an overview of how the different YOUW member states have transposedness too.

And yes, in addition to this, we also have an a. Need to reporting an obligation guide, especially looking at the reporting and registration obligations to see where you have to register in each EU member state, so you can book our full guide, but we also post some overviews on LinkedIn and in our newsletter. You touched on the you know the goal of this too was to increase consistency among the nation states of Europe in terms of their cyber regulations, and in my understanding, to increase the strength of those regulations across the board.

How's that coming. Are the regulations that are coming out stronger than we saw withiness too, and you know, are they consistent? Well, it's correct that the idea behind this too or in To directive was to create a stronger and also more consistent cybersecurity framework across the whole EU and the EU market. And also the news TO directive should also cover a crowd set of sectors for a regulated companies, so there should be some consistency within the EU.

But it's an i EU directive and not an EU regulation. So this means the two directive sets only a minimum standard to our EU member states that they can then transpose international law. And that's why the EU member states. Are allowed also to go beyond if they want to, and some of the EU member states have already done that.

This so what we're seeing right now looking at the national laws which have already been an actor, and also looking at the draft of some national laws, we see quite a mixed picture. So we don't see a whole consistency what a lot of companies we're hoping for. We see more like a mixed picture. With some countries like Belgium again, for example, they have pretty much stuck to the core of the directive and haven't added much on top.

So there you are also for you as a company, you can ensure when you're looking at his two directive, or when you have already looked at his directive, you can be positive that you also fulfill the requirements of the law of Belgium. But on the other hand, looking for example, on Italy, they have expanded the scope of application. So Italy has for example, included the cultural sector as an additional regulated area. So the sector of culture hasn't been mentioned in an IS two directive at all, but Italy had the idea, well, we can regulate also the cultural sector, so that's why they have also.

Included it into their national law. And also in France, you can see that they have imposed more obligations and also have broadened the scope of application of their national law because here they have also widened up the regulated sectors and here they have added the educational institutions for example, So yeah, you can see we have a minimum set of standard set out in ANSTUO directive, but across the EU, looking at the national laws, we have a lot of national differences and that's why it's why we're hard for companies to comply with the News Too Directive or with the national laws within the EU market.

One of the more interesting things that Christina mentioned there Andrew was Italy treating its cultural sector as like critical infrastructure, which sounds a little bit it sounds very Italian. Frankly, well, I. Don't know, it's not just the Italians. The original you know, this was back in the I don't know, the late knots.

One of the original directives that came out of the American administration was a list of critical infrastructures and at the time it included something like national monuments as infrastructure sector, and the justification was, you know, any monument or you know, cultural institution that was that was seen as essential to national identity, national cohesion. And then it disappeared in the twenty thirteen update of what were critical national infrastructure, so it's no longer on the ceases list of critical infrastructures, but it used to be, and you know, in terms of Italy, I don't you know, I don't have a lot of information about Italy.

But again you might imagine that national monuments and certain cultural institutions are vital to sort of national identity. Think the Roman Coliseum, should that be regarded as critical infrastructure? Certainly critical to tourism as for sure. So that's that's what little I know about it.

In my recollection ofness to one of the changes was increased incident this disclosure rules. Now I've you know, I've argued or I've speculated. We did a threat report at Waterfall. We actually saw numbers sort of plateau in terms of incidents.

I wonder I speculate whether increased incident disclosure rules are in fact reducing disclosures because lawyers see that disclosing too much information can result in lawsuits. For instance, Solar Winds was sued for incorrect disclosures, and so they I'm guessing that they they you know, conclude that minimum disclosure is least risk. And if they get part way into an incident and say this is not material, we don't need to disclosure, We're not going to disclose it, we actually see fewer disclosures.

Can you talk about what's happening with the disclosure rules. You know, are they how consistent are they multinational businesses? How many different ways do they have the file? And are we seeing greater disclosure or in your estimation, fewer disclosures because of these rules.

Yeah, that's a really good question, and honestly, it's something we could also ask all the time right now because once we hear again or if you operate in several EO countries, do I need to report a security incident in one you member states or we are one portal and then I'm fine? Or do we really have to report a security incident to each you member states which is kind of affected with regard to the security incident, And yeah, unfortunately the answer right now is yes, you have to report your security incident to each EU member state or to each national authority of the U member state which you fall under the scope of the national law, because the too erective does not really require one portal or one obligation registration and also reporting portal for all EU member states.

So it's up to the national authorities and also up to the EU member states to regulate this field of law. And you can see that many national authorities have already recognized this issue and they are also looking at ways to simplify the process of registration but also of reporting security incidents. And then you can see some member states try to at least include or to set up a portal, a national wide portal where you can report your security incident. Some other national authorities go even further.

They say they implement a scheme or structure where you only have to report to them and then they will transfer the report to the other relevant YOU authorities. But again this is each and in each you member states national law, so then you also have to check again all the other national laws within the EU. Yes, but also the authorities of the EU member states have already well at least indicated that they are talking to each other. So maybe in the future we will get one portal to report everything.

But as I said before, it's not regulated. Indian is too directive and it's also not foreseen for now. Yes, and to the other part of your question, well, you could think that when you're obliged to report everything and each security incident, that the reporting would degrees, but you also have to look at the at the risk of non compliance, and the risk are very high because the NESTUD directive is imposing high sanctions and also a lot of authority measures, authority market measures.

And that's why in the daily consulting work, it's better to say please report in incident because also the national authorities communicate this to the companies. They say please report something because then we can work together. So the focus after the national. Authorities, at least in Germany we see right now, is they want to cooperate together.

They want to ensure a cyber secure environment and a CyberSecure EU market. So the focus is to report something that they can work on together. And that's why it would be better to report. And I would say maybe we get also an increase of reporting.

I'm a little confused by your answer. The rules that I'm a little bit familiar with are the American Securities and Exchange Commission rules, and those rules mandate that any material incident must be reported to the public, any incident that might cause a reasonable investor to either buy or sell or put a sign of value to shares in a company, which means non material incidents can be kept quiet. And the sec disclosures are public. Everyone can see them because reasonable people need information to buy and sell shares.

Then too system is it requiring all incidents to be reported and are those reports public to. Your first part of your question, then it's too directive. And also in is too reporting obligation is kind of to say as the regulation you mentioned before, because you have to report only severe security incidents, and yeah, you as a regulated company, you are obliged to check if there is a security incident in the first step, and then the second step you have to check is there a severe security incident, and only this security incident you are obliged to report to the national authorities.

So that's kind of the same structure of or mechanism. And to the second part of your question, the report will not be published for everyone. So first of all, if you report it to national authorities, only the national authorities have the information. It can happen because we have in some member states some laws where yeah, people from the public can access or can get access to information to public information.

It can happen that information will be publicly available. But the first step is that you will only report it to the national authority and that the report will not be available for the public as such. But next to the reporting obligation to the national authorities. You also have information.

Obligations in the two directive, so it can happen that you are also obliged to inform the consumers of your services. The other big news that I'm aware of in Europe is the CRA, which you know confuses me because you know, I thought this too was the big deal. Yet there's this other thing that sort of came at me out of the blue a year ago, and I'm going, what's what's going on? Can you introduce for us what is the CIRA and how's it different from this too?

Yeah? Sure, So, as you mentioned before, the CIA is like the sister or brother and the second major piece of the new European cybersecurity framework alongside the NIS two directive. It's the Cyber Resilience Act or for short, CRA. And while then IS two directive focuses on the cybersecurity requirements for businesses or entities in critical sectors, the CIA takes a different angle and the CIA introduces uy and cybersecurity rules for products.

So NI two is focusing on cybersecurity of entities and the CIA is focusing on cybersecurity for products with digital elements and also the other. The other difference is also then is too directive. We have an EU directive, so. It needs to be transposed into national law by each member state.

And the Cyber Resilience Act is an EU regulation, so when the cub Resilience Act comes into force, it will apply directly in each you members. Stay okay, So that's how the CIRA, you know, fits into this too. What is the CIRA? What are these rules?

Is it? Can you give us a high level summary? So the CIA is the EU wide first horizontal regulation which imposes cybersecurity rules for products with digital elements. So regulated are products with digital elements, and this definition is very broad.

It covers software and also hardware and also software and hardware components if they are brought. To the you market separately. And products with digital elements are kind of like connected devices and as I said, software and hardware that can potentially post. A security risk.

Also, what is very important, the CI imposes obligations not only to manufacturers but also to importers, distributors and also to those companies which are not resident in the EU. Because the main point. For the geographical scope of application is that you put or that you place a product in the EU market, whether you are placed in the EU or not. So this means also that the Summer Resilience Act, such as the data such as the General Data Protection Regulation has a global impact for anyone selling tech products in Europe.

So let me jump in real quick here, Nate. You know what Christina has described here, the cre the scope applies to all digital products sold in Europe. To me, you know this the CIRA is in my estimation, and she's going to explain more in a few minutes. It's probably the strictest cybersecurity regulation for products generally in the whole world.

It sounds to me like this might become just like GDPR. This was a European regulation that came through a few years ago. It had to do with marketing and the use of private information, in particular my email and sending it. Basically, it was like an anti spam act.

It's the strictest in the world, and everybody who has any kind of worldwide customer base, which is almost everybody in the digital world that's sending out marketing emails, is now following the GDPR pretty much worldwide because it's just too hard to apply one law in one country and one law and the other. So what you do is you pick the strictest that you have to comply with worldwide, which is the g GDPR, and you do that worldwide instead of trying to figure out what's what It sounds me like the CRA could very well turn into that kind of thing.

It might be the thing that all manufacturers that embed a CPU and their product have to follow worldwide because it's just too hard to change what they do in one country versus another. Okay, so can you dig a little deeper. I mean an automobile. You buy a new automobile from the from the dealership.

My understanding is that it has you know, two hundred and fifty three hundred maybe three hundred and twenty five CPUs in it, all of them running software. It would seem to me that a new automobile is covered by the CIRA. What you know, what are the obligations of the manufacturer. What should customers like me expect in automobiles that might be different because of the CIRA.

First of all, looking at your example, automobiles are not covered by the CRA because the CIA has some exumptions and the CISS we are not regulating digital products with digital elements which are already regulated by specific product safety laws. And here looking at. An automotive sector, we have for sure and you very strong and very specialized regulation for product safety of cars and so on. So just for your example, but looking at other products with digital elements, for example wearabiles or headphones, smartphones, for example, you can.

Say that there are kind of five. Core obligations for manufacturers in the CIA. So the first obligation is compliance with NX one, which means you have to fulfill a list of cybersecurity requirements. And you don't only have to fulfill those cybersecurity requirements, but you also have declare and show compliance with an X one of THECIA, So it's a conformity assessment you have to undergo the other applications.

Or number two is cyber risk assessment. If you're a manufacturer of a product with the digital elements. You are obliged to assess cyber risks. And not only during the development and the construction of your product, and also not only during the blazing of your product to the new market, but throughout the whole product life circle.

So if you have a product. And you have it already based on a market, you're obliged to undergo. A cyber risk assessments. Then looking at a third oppligation, it's free security updates, so manufacturers have to provide free security updates throughout the expected product live circle.

We have also mandatory incident reporting, so we have here also reporting and registration obligations such as we already talked about looking at as two directive and also like in each product safety law in the EU, we also have the obligation for technical documentation, so this is those Those are the five core obligations compliance, cyber risk assessment, free security update, reporting and documentation. And you mentioned distributors. What are distributors and importers applied to do?

Yeah, there we have some graduated obligations so they are not such strict obligations such for manufacturers, but imports and distributors are obliged to assess if the product what they are importing and distributing to the EU market are compliant with the whole set of cybersecurity requirements of the CIA. So they have to check if the manufacturer and the product is compliant and if not, they have to inform and cooperate with the manufacturer to ensure cybersecurity compliance, but also importers are also obliged to impose.

Their own measures to fulfill with the CIA. Okay, and you said there were five obligations, you sponsor them quickly. Some of them makes sense on their own. You know, do a risk assessment, do it from time to time, see if the risk has changed.

That kind of makes sense. The first one, though, you know, comply with the NX one. That's like an appendix to the CIRE. What what's in there?

What? What are the obligations. NX one is Yeah, you can also say appendix one to the CIA, and there you can see there is a list of certain cybersecurity requirements which manufacturers have to fulfill. And the list is divided into two different main areas, and one area is cybersecurity requirement, so it focuses on no known vulnerabilities at the time of the marketplacement, securit default configurations, protection against unauthorized access, ensuring confidentiality, integrity and availability, and also secure deletion and export of user data.

So kind of all. Of cybersecurity requirements such as them which. I have mentioned. And the other area is vulnerability management.

So manufacturers have to ensure that they have an structured vulnerability management process, and they have to install the software bill of materials, they have to provide free security updates, they have to undergo cybersecurity testing and assessments. Then needs to be a process to publish information on resolved vulnerabilities. And again here we also need a clear reporting channel for known vulnerabilities. It sounds like you said that a manufacturer is not allowed to ship a product with known vulnerabilities.

Practically speaking, how does that work? I mean, a lot of manufacturers in the industrial space use Linux under the hood. Linux is a million lines of code of kernel, and these devices don't necessarily do a full desktop style Linux, but they still have a lot of code that they're pulling from an open source distribution. And in these millions of lines of code, from time to time, people discover vulnerabilities and they get announced, and so it's you know, it's almost a random process.

Do I have to suspend shipments the day that Linux vulnerability comes to light until I can get the thing patched, and then three days later start shipments again? Practically speaking, how does this zero known vulnerabilities requirement work? Basically, it is like as you said, because the cub Resilient. Act focus on.

Or no known vulnerabilities not only in your product, but also in the whole supply chain. So does sub Resilience Act focus not only on products with the elements, but also focusing on the cybersecurity of the whole supply chain. So this means, looking at an X one and the cybersecurity requirements, products with digit. Elements may only be placed.

On the EU market if they don't contain any known exploitable vulnerabilities. So it's not any vulnerability, but it's any known exploitable vulnerability that is a clear requirement under NX one. And also when you're looking at making a product available on a market, that doesn't. Just mean selling it.

It includes any kind of commercial activity. And also what is also a very good question also in our daily work, looking at making a product available on a market, a lot of companies say, well, I have a badge of products, so and if I have placed this batch of products on the new market, I have already placed the product on the market, so for I can also place the other products. Of this batch also in the future. But it is not correct because looking at EU Product safety law, the regulation is focusing on each product.

So looking at these requirements, you can say, first of all, you really have to check your own product, your own components, but also the products and the components you're using from the supply chain, and you have to check if there are any known exploitable vulnerabilities. So you have to impose a process to check the vulnerabilities and also to impose mechanisms to fix those vulnerabilities. And if you have products already on the market. You don't have to recall them because first of all, it's okay if you have a vulnerability management which is working and where you can fix those vulnerabilities.

And when you have products already in the. Shipment process, there is up to each company to assess if they have to recall the products in the shipment process or if they say, okay, we leave in the shipment process because we know we can fix the vulnerability within two or three days. So in the end, it's kind of a risk based approach, and each company has to assess what measurements are applicable and also. Necessary, So that makes a little more sense.

I mean, the Linux kernel and sort of core functions in my I don't have the numbers, but I'm guessing that you're going to see a vulnerability every week or two in that large set of software. And if that's part of a router that you're shipping, or part of a firewall that you're shipping, or part of any kind of product that you're shipping. Does it make sense that you know, you discover the exploitable vulnerability on Thursday, and you have to suspend shipment until you know three weeks out, when you have incorporated the vulnerability in your build, and you've repeated all of your product testing, which can be extensive, and by the time you're ready to ship that fix, two other problems have been developed, and now you have to you can't ship until you know.

It sounds like it's not quite that strict. It's not you know that that scenario sounds like nonsense to me. It just it would never work. You're saying that there is some flexibility to do reasonable things to keep bringing product to market as long as you're managing the vulnerabilities over time.

Is that fair? Yes? Yes, that's right, because in a CIA, we have a risk based or broad and also you have to no the basis for each measure you have to impose under the CIA is your cyber risk assessment. So you have to take what kind of product am I using or am I manufacturing?

Which kind of product am I right now placing on the you market? What are the cybersecurity risk right now? And also what of what are the specific cybersecurity risk of this known vulnerability? And then you have to check have I do I have a process?

Do I have a process imposing appropriate measures to to fix those vulnerabilities? And if I have appropriate measures to fix the wailability is in a reasonable time and manner, then it's not the no you're then then you're not obliged to recall the product itself. Yeah, but at the end, looking at a risk bace abroad, abroad abroad, it's it's up to the decision of each company. So this is a lot of a lot of change in in you know, for a lot of product vendors.

Can I ask you how is it going? You know? Is it working? Are the vendors you know confused?

Can you do you have any sort of insight in the how it's going? So what we're seeing right now a lot of companies, both manufacturers but also suppliers. Yeah, getting ahead of the curve when it comes to the Cyber Resilience Act because they see that there is a change and that there will renew strict obligations not only on manufacturers, but also in the whole supply chain. So suppliers, distributors, importers are also coming to us and asking if.

They are under the scope of the CIA. So this is the first point. If you're a distributor or an importer, you already have to check if you're in your company itself falls under the scope of the CIA, and if it is like this, then you are already obliged to ensure all. The obligations of the CIA.

But it can also happen that suppliers are under the scope of the CIA in an indirect manner, because ensuring all those new cybersecurity requirements from a manufacturer point of view, you have to ensure it within. The whole supply chain. And the main instrument to ensure this was already in the few in the in the past and will also be in the future is contract management. So you have to impose or transpose all those new obligations to the suppliers.

We are contract management and there we see different reactions, but there's definitely a growing awareness that cybersecurity needs to be addressed contractually, especially in relation to the CIA obligations. And yeah, looking at the contract negotiations, of course, we have some negotiations with the suppliers, and one of the main point which is negotiated is the regulation of enforcement, because when you have contractoral management looking at cybersecurity requirements, you cannot only transpose those obligations to the suppliers, but you also have rules on enforcing those new contractual obligations, for example, contractoral penalties.

And there we see that contractor penalties often sparks some debate during negotiations. Yeah, but to sum up, in practice, we've always been able to find a balanced solution that works for all parties involved. I suppose I could think about any number of potentially trivial electronics products Andrew. But you know, let's say that I or my neighborhoods a smart fridge, a fridge with a computer on it.

I generally assume that those devices don't even really have security in minded. And you know, a security update is like so far from the universe of how anyone would interact with such a device. And now we're saying that that kind of thing is going to be regulated in these ways. I think the short answer is yes.

You might ask what good does this regulation do for a fridge? And you know, I think about this sometimes. I think the answer is it depends. If you know, a lot of the larger home appliances nowadays have touchscreens, there's a CPU inside, there's software inside.

These are cyber devices. You might ask, well, when was the last time I updated the firmware in my fridge? How many times am I going to update the firmware in my fridge? Those are good questions.

Most people never think about something like that. But the law might, you know, very reasonably apply to the fridge if the fridge is connected to the internet, so that I can see, for example, how much power my fridge is using on my cell phone app. You know, isn't that clever? But now I've connected the fridge to the internet.

We all know what happened to What was it? The Maria botnet took over hundreds of thousands of Internet of Things devices and used them as attack tools for denial of service attacks. If you've got an Internet connected fridge, you risk that if you haven't updated the software. Worse, if someone gets into your fridge, takes over the CPU, you could change the set point on the temperature and cause all your food to spoil.

This is a safety risk. Again, how many consumers are going to update the software in their fridge realistically? I don't think you know, the majority of consumers will even if there is a safety threat to me. You know the risk this is part of the risk assessment.

If there's a safety threat because of these vulnerabilities, you might well need to I don't auto update the firmware. That might be part of your risk assessment so that the consumer doesn't have to do it, or better yet, design the fridge so that safety threats because of a call from ed CPU are impossible physically impossible. Make the temperature setting manual or something. But you know, this is a bigger problem than I think one regulation.

The question of safety critical device is connected to the cloud. Yeah, admittedly, the notion of a smart refrigerator safety threat isn't totally resonating with me. And then we haven't even discussed the matter of like, Okay, let's say that my refrigerator gets automatic updates or I just have to click a button in an app when it notifies me to do so to update my firmware at some point. You know, fridges sit in houses for a long periods of time.

I can't recall the last time that my fridge has been replaced. In that time, any manufacturer could go out of business, and then how do you get those updates right exactly? So you know to me, but this is outside the scope of the CRA But you know, to answer your question to me, the solution is two or threefold. We we need to design safety critical consumer appliances in such a way that the unsafe conditions cannot be brought about by a cyber attack.

I mean, we talk about, you know, fixing known vulnerabilities, that's only one kind of vulnerability. What about zero days? There is there's there's logically no way that someone can you know, solve all zero days. It's a nonsensical proposition.

So there's always going to be zero days. What if one is exploited and you know, a million fridges set to a set point that that's unsafe to me, We've got to design the fridges differently. But that's that's sort of a different conversation. In fact, that's the topic of my next book.

But which is why I care so much about it. But but you know, it's it's these are important questions, and I think the CIRA is a step in the direction of answering them, But I don't know that it has all the answers. What you described there makes sense for you know, manufacturers like IBM, who can you know, produce high volumes of or you know, Sony or the big fish. But you know, if I'm a small manufacturer, I produce a thousand devices a year.

I buy components for these devices, I buy software for these devices from big names like Sony and Microsoft and Oracle. And you know, I go to Oracle and say, you must meet my contract requirements or I won't buy my thousand products from you at a cost of eighty nine dollars a product. Oracle's going to say, take a flying leap, We're not signing your contract. Is this realistic?

Yes? And we see this also in practice because we are not only consulting the big manufacturers but also the smaller companies in the supply chain. And there you can have different approaches because when you're buying products from the big companies, first of all, you have to know that they are or they might be obliged. Also, on the CIA, so they are fulfilling all those new cybersecurity requirements and you also have to check it though there you also have to check their contracts because there you can see already they have a lot of new regulations looking at cybersecurity, either if it's implemented into the general contractor into the general contractor documents, or are implemented into one cybersecurity appendix.

So you see all the companies are looking at the Cyber Resilience Act and then are taking measures and also looking at. Their contract management. So if you're if you're. Lucky enough, you can see, okay, they have a contract which is already regulating all the obligations under the CIA.

And then if it's not like this, we take the approach. That we establish a cybersecurity appendix, so when you're already in contractual relationship with the big players, you don't have to negotiate the whole contract from the beginning. You can only show them your. Appendix and then on basis of this appendix you can discuss the cybersecurity requirements.

So this is kind. Of approach which has helped also smaller companies in the market. For the record, does this apply to industrial products as well? I mean, our listeners care about programmable logic controllers and uh, you know steam turbines that have embedded computer components or is it strictly a consumer goods rule?

No, And this is a very important point to highlight. Our resilience explicitly applies not only to consumer products but also to products in the B two B sector. So this means that all software and all hardware products along with any related remote data processing solutions for under the scope of the CIA, either in B two C or also in B two B relationships. Well, Christina, thank you so much for joining us.

Before we let you go, can I ask you? Can you sum up for our listeners what are the key messages to you know, take away to understand about what's happening with cyber regulations both to and CIRE in Europe and you know what we should be doing about them as both consumers and manufacturers. Yeah, sure of course. So let me give you a quick recap.

So, first of all, you see the e U legislators tightening the cyber security requirements significantly with both the NEESS two Directive and also the Cyber Resilience Act, and the new requirements affect any company that offers products or services to the EU market no matter where they are based, so it is it has a very broad scope of application. Looking at the ISS two Directive, it's very important to know that MIS two Directive is already enforced, but it has to be transposed international law which has not been fulfilled by all EU member states, and that the national implementation across the EU is still quite waried.

Looking at the Cyber Resilience Act, the CIA brings new security obligations to products with digital elements, so for all software, for all hardware products, and it also is focusing not only on the cybersecurity on products, but also in the whole supply chain. So both frameworks require companies to take proactive steps right now, looking at risk assessment, risk management, reporting and also contract management, particularly when it comes to managing their supply chain. So looking at a short implementation deadlines ahead, both from the two Directive and also CIA, it's very important for companies to act now.

And the first step we consult to do is to identify the relevant laws because we have a lot of new regulations looking at digital products and digital services. So yeah, first of all, check the relevant laws and irrelevant obligation which are applicable to your business. And here we offer a freeness To quick check and also a free CRIA QuickCheck where can where you can just click through the different questions to see if you are under the scope offness to NCIA. And then after all, when you clarified that you're affected under one or both of the new regulations, the company needs to review and adapt their cybersecurity processes both technically and also organization organizationally, so it's very crucial to continuously monitor and ensure compliance with the ongoing legal requirements, especially also looking at contract management and focusing on the supply chain.

And yeah, there we can help national but also international companies with kind of a three sixty decree approach to our security compliance because we ensure solutions with the range from product development and marketing to reporting and market measures. So yeah, we give companies practical and also action action enable guidance in an in an every step way, so looking at the first step to act and yeah, to identify the relevant laws and obligations to your business, companies, can yeah visit our free niss to quick check and our free cr A quick check which is available under nis to minus check dot com and also cr A minus check dot com.

And yeah, if you have any further question, you are free and invited to write to me. We are email, we are linked in. Yeah, I'm happy to connect and thank you very much for the invitation. Andrew.

That just concludes your interview with Christina Kiefer, And maybe for a last word today, we could just talk about what all of these rules mean practically for businesses out there, because you know, it's one thing to mention this rule in that rule on a podcast, but it sounds like the kind of stuff we're talking about here is going to mean a lot of work for a lot of people in the future. I agree completely. It sounds like a lot of new work and a lot of new risk, both for the critical infrastructure entities that are covered by this too or by the local laws, especially for businesses, the larger businesses that are active in multiple jurisdictions, and certainly for any manufacturer who wants to sell anything remotely cpu like you know, into the European market.

You know, it sounds like a lot of work, but you know, I have some hope that it's also because it's such a lot of work, it's also a business opportunity, and we're going to see entrepreneurs and service providers and even the technology providers out there providing services and tools that will automate more and more of this stuff, so that not every manufacturer and every critical infrastructure provider in the European Union or in the world selling to the European Union, not every one of them has to invent all of this the answers to these new rules by themselves.

Well, thank you to Christina for elucidating all of this for us, and Andrew as always, thank you for speaking with me. It's always a pleasure. Thank you, Nan. This has been the Industrial Security Podcast from Waterfall.

Thanks to everyone out there listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Emre Kazim (Holistic AI): Why AI Governance is Life CybersecurityThe Road to Accountable AI · on GDPR90 / 100
  • Why Digital Identity Is Broken And How Ditto Plans To Fix ItThe Business of Cybersecurity · on GDPR90 / 100
  • GRC Is an Engineering Discipline. Not a Checklist. ft Akhila Chitiprolu, Head of Security & GRC @ SierraSecurity & GRC Decoded · on vulnerability management86 / 100
  • The Hidden Risk of Your InfrastructureThreat Talks · on software bill of materials81 / 100
  • Enterprise Software Buyers Now Demand a Vendor AI Training Data Provenance AuditB2B SaaS Talks with Fexingo · on GDPR80 / 100
  • Think Like an Attacker: Microsoft Security Exposure Management with Uros Babic [MVP-MCT]M365.FM · on vulnerability management78 / 100

More from The Industrial Security Podcast

All episodes →
  • Rapid Recovery - When Security Fails [The Industrial Security Podcast]62 / 100
  • We can't - and shouldn't - fix everything [The Industrial Security Podcast]95 / 100
  • Medical Device Cybersecurity Is Tricky [The Industrial Security Podcast]85 / 100
  • Hardware Hacking - Essential OT Attack Knowledge [the industrial security podcast]95 / 100
  • Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]85 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Industrial Security Podcast episodes →