The upcoming European Cyber Resilience Act sets out to boost security for anything with “digital elements”.
The Act will apply to hardware and software. The idea is to make it easier to update devices, and to fix any vulnerabilities.
Why, then, has a group of cyber security professionals written an open letter to the European Commission asking them to change a key part of the proposed rules?
Experts are concerned that, by requiring organisations to disclose vulnerabilities within 24 hours, the Act could increase, rather than reduce, risks.
Our guest today is Christine Bejerasco, CISO at WithSecure and one of the signatories of the letter.
We asked her to set out the background to the Act, and why so many security professionals fear it could have unintended consequences.
Interview by Stephen Pritchard