惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tailwind CSS Blog
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
The Cloudflare Blog
博客园 - 聂微东
博客园 - 司徒正美
量子位
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Y
Y Combinator Blog
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
有赞技术团队
有赞技术团队
A
About on SuperTechFans

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
EU Cybersecurity Act 2.0: When good regulation goes bad -...
Help Net Security · 2026-06-16 · via Help Net Security

Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter.

The problem with CSA 2.0

The original EU Cybersecurity Act, which came into force in 2019, was a solid foundation. CSA 2.0 was supposed to be a measured evolution to deal with the current threat landscape. What has emerged instead is something more ambitious and more troubling: For the first time, the European Commission would gain the power to designate certain countries as “high-risk,” with vendors from those countries automatically inheriting that label and facing strict restrictions across the EU.

The consequences of this are potentially enormous and could cause more harm than good. The old saying “the road to hell is paved with good intentions” is starting to ring true for CSA 2.0.

The Irish Business and Employers Confederation (IBEC) has warned that the proposed changes could threaten stability across 18 critical sectors in Ireland alone, and land the Irish telecoms industry with a bill of approximately €730 million for ripping out and replacing equipment.

Research prepared by my firm, BH Consulting, for Digital Business Ireland, found that companies well outside the direct regulatory scope of CSA 2.0 will still be hit hard through tighter supply-chain requirements, procurement rules, and investor caution.

But the question I think too few people are asking publicly is “who exactly ends up on that “high-risk” list, and how?”

The honest answer is that nobody knows yet. The current framing ties high-risk status primarily to geopolitical origin rather than to verifiable technical failings. A vendor could find itself shut out of the EU market not because its code is insecure or its patch management is weak, but because of the physical address of its corporate headquarters.

Potential for costly disruption

The obvious targets are the ones western governments have discussed for years such as China, Russia, North Korea, Iran. But the mechanism being created is not written narrowly to focus on those countries. Rather, it is a general power that is applicable to any third country, and the current geopolitical environment should give every European policymaker serious pause.

A prime example is how the relationship between the EU and the United States has shifted measurably over the past two years. Trade disputes, disagreements over defence spending, threats to invade Greenland, pushback against EU regulations, and broader tensions around technology policy have introduced a level of friction that would have seemed implausible not too long ago. Under the CSA 2.0’s proposed new framework, there is nothing in principle to prevent the European Commission from designating the United States as a high-risk country at some future point.

Consider what that would mean in practice. Large parts of European critical infrastructure, cloud platforms, cybersecurity tooling, and enterprise software originate from US-headquartered vendors. A designation, even a partial or conditional one, would trigger mandatory migration obligations, procurement exclusions, and supply-chain reassessments across thousands of organisations. The disruption would dwarf anything currently being discussed in the context of Chinese telecoms vendors.

One estimate cited in European media suggests that applying hard restrictions to Chinese vendors across 18 sectors alone could cost the EU approximately €368 billion over five years once direct and indirect effects are counted. Extend that logic to any other major technology-supplying nation and the numbers become difficult to absorb.

The deeper problem is that this approach inverts good security practice. Sound risk management starts with evidence: what are the actual technical vulnerabilities, what are the realistic threat vectors, what do independent audits and certifications tell us? Geopolitical context is a legitimate input into that assessment, but it should not replace it.

CSA 2.0 could destroy SMEs

Where genuine systemic risk exists, proportionate responses are available: segmentation, monitoring, conditional use in less sensitive environments, phased transition plans with realistic timelines and financial support. Blanket bans and compressed rip-and-replace mandates, triggered not by technical evidence but by political geography, are the least targeted and most disruptive option available. They should be the last resort, not the starting point.

There are also serious concerns on how CSA 2.0 will impact small and medium enterprises (SMEs). While large organisations such as multinationals can absorb sudden regulatory upheaval, a regional managed service provider, a small med-tech company, or an industrial automation specialist operating on thin margins cannot.

SMEs do not have the same reserves, in cash, people, or expertise, that larger organisations do. If a core component they depend on is suddenly reclassified as coming from a high-risk supplier, they face a stark choice between an expensive re-architecting and refitting or losing key customers.

Don’t get me wrong: I am not arguing that we ignore supply chain risk. The EU is right to want more coherence and discipline in this space. But CSA 2.0 needs to be anchored in objective, verifiable criteria such as technical risk assessments, secure development practices, vulnerability management, independent certification, and transparency. The passport held by a vendor’s executives is not a security control.

There is still time to rebalance this legislation. The question is whether there is the political will to do so.