The Opportunity to Regulate Cybersecurity in the EU (and the World): Recommendations for the Cybersecurity Resilience Act

by   Kaspar Rosager Ludvigsen, et al.

Safety is becoming cybersecurity under most circumstances. This should be reflected in the Cybersecurity Resilience Act when it is proposed and agreed upon in the European Union. In this paper, we define a range of principles which this future Act should build upon, a structure and argue why it should be as broad as possible. It is based on what the cybersecurity research community for long have asked for, and on what constitutes clear hard legal rules instead of soft. Important areas such as cybersecurity should be taken seriously, by regulating it in the same way we see other types of critical infrastructure and physical structures, and be uncompromising and logical, to encompass the risks and potential for chaos which its ubiquitous nature entails. We find that principles which regulate cybersecurity systems' life-cycles in detail are needed, as is clearly stating what technology is being used, due to Kirkhoffs principle, and dismissing the idea of technosolutionism. Furthermore, carefully analysing risks is always necessary, but so is understanding when and how the systems manufacturers may fail or almost fail. We do this through the following principles: Ex ante and Ex post assessment, Safety and Security by Design, Denial of Obscurity, Dismissal of Infallibility, Systems Acknowledgement, Full Transparency, Movement towards a Zero-trust Security Model, Cybersecurity Resilience, Enforced Circular Risk Management, Dependability, Hazard Analysis and mitigation or limitation, liability, A Clear Reporting Regime, Enforcement of Certification and Standards, Mandated Verification of Security and Continuous Servicing. To this, we suggest that the Act employs similar authorities and mechanisms as the GDPR and create strong national authorities to coordinate inspection and enforcement in each Member State, with ENISA being the top and coordinating organ.


page 1

page 2

page 3

page 4


Acceptable risks in Europe's proposed AI Act: Reasonableness and other principles for deciding how much risk management is enough

This paper critically evaluates the European Commission's proposed AI Ac...

On the resilience of cellular networks: how can national roaming help?

Cellular networks have become one of the critical infrastructures, as ma...

Factors Impacting Resilience of Internet of Things Systems in Critical Infrastructure

Internet of Things (IoT) systems are recently being employed in various ...

Transparency, Compliance, And Contestability When Code Is Law

Both technical security mechanisms and legal processes serve as mechanis...

Cybersecurity of AI medical devices: risks, legislation, and challenges

Medical devices and artificial intelligence systems rapidly transform he...

From NEA and NIA to NESAS and SCAS: Demystifying the 5G Security Ecosystem

Despite the numerous pompous statements regarding 5G, it is indisputable...

Please sign up or login with your details

Forgot password? Click here to reset