惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Latest news
Latest news
G
GRAHAM CLULEY
P
Privacy International News Feed
Know Your Adversary
Know Your Adversary
N
Netflix TechBlog - Medium
C
CERT Recently Published Vulnerability Notes
O
OpenAI News
T
Tenable Blog
Attack and Defense Labs
Attack and Defense Labs
S
Schneier on Security
The GitHub Blog
The GitHub Blog
M
MIT News - Artificial intelligence
PCI Perspectives
PCI Perspectives
博客园 - 司徒正美
Microsoft Azure Blog
Microsoft Azure Blog
MyScale Blog
MyScale Blog
Martin Fowler
Martin Fowler
S
Secure Thoughts
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
T
The Exploit Database - CXSecurity.com
U
Unit 42
The Register - Security
The Register - Security
Google DeepMind News
Google DeepMind News
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
WordPress大学
WordPress大学
B
Blog
Project Zero
Project Zero
NISL@THU
NISL@THU
Cloudbric
Cloudbric
TaoSecurity Blog
TaoSecurity Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
MongoDB | Blog
MongoDB | Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic
I
Intezer
L
Lohrmann on Cybersecurity
Webroot Blog
Webroot Blog
P
Proofpoint News Feed
C
Check Point Blog
Schneier on Security
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Hugging Face - Blog
Hugging Face - Blog
I
InfoQ
Recent Commits to openclaw:main
Recent Commits to openclaw:main
T
Threatpost
Apple Machine Learning Research
Apple Machine Learning Research
Spread Privacy
Spread Privacy
The Hacker News
The Hacker News

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
Who controls the fix? Colorado's repair fight tests CIO power
2026-04-10 · via informationweek

A proposed bill in Colorado is raising a much larger question for enterprise IT management across the nation. The legislation, state bill SB26-090, is titled 'Exempt Critical Infrastructure from Right to Repair' -- and it does exactly that. If approved by the Colorado House and Senate, it would carve out "critical infrastructure" from the state's right-to-repair requirements, limiting who can service and maintain key systems. 

The rationale is familiar: restrict access to sensitive equipment to reduce security risk. Supporters of the proposal argue that tighter control over repair and maintenance will protect system integrity; those supporters include vendors Cisco and IBM.

For CIOs, however, the relevance goes far beyond one state or one policy. It touches a deeper issue: who ultimately controls enterprise infrastructure once it is deployed -- and who decides how and when it is fixed?

David Linthicum, founder, Linthicum Research

                                      David Linthicum, founder, Linthicum Research

"This is part of a broader shift," said David Linthicum, a cloud and AI expert and founder of Linthicum Research. "Over the last several years, large technology vendors have been trying to keep tighter control over hardware, software, support and even the data generated by those systems."

Related:InformationWeek Podcast: The new IT architecture of cloud, edge and AI

That shift is now surfacing in policy. And as it does, it is forcing a reconsideration of a long-standing assumption in enterprise IT: that ownership of a system implies control over its operation.

Control, reframed as IT security

For much of the past decade, enterprise IT strategy has emphasized flexibility. Organizations diversified vendors, adopted cloud platforms and built architectures designed to avoid dependence on any single provider. Even where vendor lock-in existed, it was treated as a risk to manage.

The right-to-repair debate introduces a different framing. It is not about lock-in; it's about security. Yet the outcome can look similar: tighter vendor control over how systems are maintained, who can access them and what options exist when something goes wrong.

Linthicum said he sees a convergence of incentives behind this shift. "Security is a valid concern, especially in critical infrastructure," he said. "But vendors also know that control over repair creates control over service contracts, upgrade cycles, spare parts and customer dependence."

Niel Nickolaisen, a technology leader advisor at VLCM and chairman of the CIO Council at FC Centripetal, questioned both the framing and the intent. "What problem are they trying to solve?" he asked. "If they could articulate that clearly and tightly define who this impacts, my skepticism would shrink."

Related:Memory shortage doesn't have to spell disaster for IT budgets

Without that clarity, policies risk reshaping control structures in ways that extend beyond their original purposes -- for better or worse.

Where risk actually shows up

The case for restricting repair access rests on reducing the likelihood of tampering or misconfiguration. In theory, fewer hands touching critical systems means fewer opportunities for compromise. But critics argue the theory is far from reality.

"In practice, delayed access is often the more immediate operational risk," Linthicum said. "Most enterprises already have strict controls around who can access sensitive systems. But when something fails, downtime is real, expensive and public."

If repair is limited to vendor-approved channels, response times depend on external capacity, such as support queues, the availability of parts and scheduling constraints. That delay can turn a contained issue into a broader disruption.

Nickolaisen said he sees risk on both sides, but he questions whether vendor control meaningfully reduces it. "We have processes and tools to reduce and manage access to our systems," he said. "If the manufacturer has access, how do I vet and control their people? Do I need to include them in my compliance processes?"

Related:How techno-nationalism is complicating IT resilience and supply chains for CIOs

He also pointed to the practical challenge of scale. "How does the manufacturer staff the support team to provide every enterprise customer with the support it needs in the event of an outage?" Nickolaisen said. "If they are going to take control, what service-level guarantees will they have?"

Rather than eliminating risk, the shift redistributes it, introducing new dependencies even as it seeks to reduce existing ones.

Ownership without authority

At the center of the debate is a more fundamental question: What does it mean to own enterprise infrastructure? Traditionally, organizations deploy systems and take responsibility for how they are maintained and operated. Vendors provide updates and support, but enterprises decide when and how those interventions occur.

Policies that restrict repair rights begin to unsettle that model.

"The enterprise customer is responsible for evaluating patches and upgrades and deciding what to deploy and when," Nickolaisen said. "This seems to violate those boundaries."

If vendors -- or policies shaped by vendor priorities -- gain greater control over maintenance, that authority shifts. Decisions about timing, prioritization and mitigation may no longer sit entirely within the organization.

Linthicum framed the impact in practical terms: "The biggest change is the loss of operational flexibility," he said. "Costs go up, response times can worsen, and negotiating leverage declines. But the real issue is that CIOs have fewer options."

Those options matter most during disruption, when the ability to act quickly can determine the outcome. Without them, ownership becomes more symbolic than real.

The unintended consequences

The longer-term effects of this shift may be less visible, but no less important. While the full impact is not yet clear, the experts foresee several new complications arising as a result of this kind of legislation.

Linthicum pointed to reduced competition in third-party support, higher lifecycle costs and increased pressure to replace systems rather than repair them. "Over time, that can reduce resilience rather than improve it," he said. "If organizations cannot act quickly and independently during outages, the system becomes more fragile."

Nickolaisen's concerns extend to governance and accountability. He questioned how new restrictions would interact with existing regulatory frameworks and whether they would create overlapping obligations. He also raised a practical issue: responsibility when things go wrong.

"Who is responsible for service-level breaches, and at what cost?" he asked. "How do I 'fire' a manufacturer when they have control over the maintenance of my infrastructure? Do I have to replace my infrastructure to get out of that relationship?"

These are not edge cases. They go to the heart of how enterprise IT is governed and how failure is managed.

Niel Nickolaisen, chairman of the CIO Council at FC Centripetal and director of strategic engagements, JourneyTeam

                        Niel Nickolaisen, chairman of the CIO Council, FC Centripetal

A broader shift in control

The Colorado proposal may be one example, but it points to a wider trend. As digital infrastructure becomes more critical and more complex, the pressure to secure it will continue to grow. So, too, will the incentives for vendors to position themselves as the safest stewards of that infrastructure. The question is how far that logic extends.

The Colorado bill refers specifically to "critical infrastructure," but this definition isn't fixed. As more systems become essential to business operations, the scope of what qualifies can expand. If restrictions on repair grow alongside those definitions, the affect could reach far beyond the sectors initially targeted.

For CIOs, the challenge is not just responding to individual policies but also recognizing the underlying shift and taking steps to minimize its impact. The right-to-repair debate is less about repair than about control: Who has the authority to act, under what conditions, and with what constraints?

"I am skeptical of legislation that is sponsored and driven by technology manufacturers," Nickolaisen said. "I have never seen any that turned out to benefit the customers. And I do mean never."

About the Author

Madeleine Streets

Senior Editor, InformationWeek

Madeleine Streets is a senior editor at InformationWeek, where she shapes stories and contributes news analysis through a CIO lens. 

She comes to InformationWeek from TechTarget’s Learning Content team, in which she authored explainers and features on a range of enterprise IT topics. Before moving to the field of enterprise technology, Madeleine spent several years covering retail, consumer finance, and ecommerce technology for fashion trade publication Footwear News. She has also been published in Women’s Wear Daily, TIME, Associated Press, SELF, and Observer, among others. The thread that ties her coverage together is a commitment to honest, impactful storytelling -- and insatiable curiosity.

Outside of writing, Madeleine can be found studying wine, singing in her local choir, and working her way towards her annual reading goal of 100 books. She is based in New York City, US.