
Threat Talks · 2026-04-07 · 33 min
You don’t control the technology your business runs on. That’s an uncomfortable reality. But the truth is: your infrastructure runs on foreign technology. Your data depends on external suppliers. And if they fail - you feel it. The EU has decided to step in. In this episode of Threat Talks , Lokke Moerel (Professor of Global ICT Law at Tilburg University and leading expert in EU cybersecurity regulation) breaks down how Europe’s new cybersecurity package is reshaping supply chain security. Because this is not just about audits. From Chinese components embedded in infrastructure to US-controlled cloud services, organizations are relying on suppliers that sit outside their control. And that creates a different kind of risk. Not just technical - but strategic. The EU is now responding with a structural shift: One certification approach across Europe Clearer rules for suppliers in critical functions Separation of technical security and geopolitical risk This changes how supply chain security works. For CISOs and security leaders, the message is clear: If your cybersecurity risk mitigation strategies don’t account for dependency on external suppliers, you’re exposed.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.