
Threat Talks · 2026-03-03 · 30 min
China is Already Inside your infrastructure. And the EU is done ignoring it. In this exclusive first discussion of the upcoming EU Cybersecurity Act revision, Bart Groothuis, MEP, joins Lieuwe-Jan Koning, CTO and Co-Founder, to explain why vendor dependency is now a board-level security risk. Groothuis breaks down how the revised EU Cybersecurity Act will shift Europe from soft guidance to hard enforcement - introducing formal “high-risk vendor” treatment inside critical infrastructure. This isn’t about secret backdoors. It’s about who controls the next update. Who enters your data center. And who can one day - switch off the grid. The revision brings non-technical risk - state influence, intelligence laws, geopolitical leverage - directly into cyber certification decisions. That means supply chain risk is no longer theoretical. It’s regulatory. And the impact goes far beyond telecom. Energy. Cloud. Transport. Enterprise IT. If your infrastructure depends on a vendor tied to a high-risk state, this conversation matters.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.