{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreid6zzrzmcyy77wccyjpimkst3sznngbu62mkaoud54c45kcdn75fe",
"uri": "at://did:plc:mg5ozsljpp6t5b4lvwys4t72/app.bsky.feed.post/3mhtmxy4sjo22"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreiaw2rhj4rn6vak6um5txiy4jqpi6t56e4tikctkodakf6t6tuymri"
},
"mimeType": "image/png",
"size": 1478675
},
"description": "Subsea cables crossing into Europe now fall under same security rules as power grids, says European Commission's cybersecurity chief.\n",
"path": "/eu-cyber-resilience-will-reshape-global-product-security-standards/",
"publishedAt": "2026-03-24T22:18:26.000Z",
"site": "https://broadbandbreakfast.com",
"tags": [
"Learn more about the Broadband Community...",
"Start Your Broadband Journey Here",
"face legally binding timelines",
"protect subsea cables",
"technology sovereignty package"
],
"textContent": "SAN FRANCISCO, March 24, 2026 — Artificial intelligence now drives virtually every social engineering attack targeting organizations across Europe, the EU's chief cybersecurity agency said Tuesday at the RSA Conference here, as the bloc moves to impose sweeping new product security requirements by September.\n\nThe remarks came as two major pieces of EU legislation rewrite the rules for any company selling products into European markets.\n\nThe Cyber Resilience Act, which sets mandatory security standards for any product with a digital component sold in the EU, takes effect in September 2026.\n\nLearn more about the Broadband Community...\n\n\n Start Your Broadband Journey Here\n \n\nA proposed Cybersecurity Act revision would impose legally binding supply chain requirements, forcing companies to identify and remove high-risk suppliers from critical systems across all 27 member states.\n\n**Hans De Vries** , chief cybersecurity and operational officer at ENISA, the European Union Agency for Cybersecurity, said AI-assisted attacks had grown from roughly 80 percent of attempts in early 2025 to effectively 100 percent today. He said threats now morphed faster than existing certification and detection frameworks could respond to.\n\nDe Vries spoke alongside **Despina Spanou** , deputy director general for cybersecurity and trust at the European Commission, at this annual gathering of cybersecurity professionals and policymakers.\n\n### _New product security deadline_\n\nDe Vries said ENISA held primary responsibility for implementing the Cyber Resilience Act and described compliance as mandatory for any company seeking to sell into European markets.\n\nSpanou identified supply chain security as the EU's most pressing near-term challenge, saying high-risk suppliers had embedded themselves across 70 to 80 percent of certain critical sectors, naming detection equipment, electricity and energy systems, and connected vehicle components as the most exposed.\n\n### _Huawei and the high-risk supplier problem_\n\nThe proposed Cybersecurity Act revision would classify suppliers originating from listed high-risk countries as high-risk automatically, with narrow exceptions. Companies would face legally binding timelines to remove those suppliers from critical systems.\n\nHuawei, the Chinese telecommunications equipment manufacturer, emerged as the clearest example of how deeply high-risk suppliers had penetrated European systems. Mobile network derisking had moved faster than other sectors because alternative vendors existed, Spanou said, but comparable transitions would be far harder in markets where substitutes remain scarce.\n\nIn port and airport detection equipment alone where all cross-border trade data flows - suppliers from a single high-risk country had penetrated seventy to eighty percent of total infrastructure.\n\n### _Critical infrastructure under attack_\n\nDe Vries offered concrete examples of the damage supply chain vulnerabilities had already inflicted. A cyberattack on Jaguar Land Rover, the British automotive manufacturer, left the company offline for three weeks and pushed some of its parts vendors toward insolvency.\n\nA breach at a biomedical testing facility in the Netherlands exposed breast cancer patient records across a system used nationally. The attackers published the data after the facility declined to pay a ransom, a tactic De Vries said reflected a broader shift in criminal posture.\n\nHe described cybercrime as the second-largest criminal industry globally, generating billions in annual revenue.\n\n### _Subsea cables and the new infrastructure perimeter_\n\nSpanou said the definition of critical infrastructure had expanded well beyond traditional sectors. The European Commission adopted a plan last year to protect subsea cables, the underwater fiber optic links carrying 99 percent of intercontinental data traffic, built around prevention, detection, and response.\n\nThe Commission extended the same framework to counter-drone policy after incidents disrupted airspace across multiple EU member states. Both areas are included as priority sectors in the proposed Cybersecurity Act revision.\n\n\"This is the new critical infrastructure,\" Spanou said.\n\n### _Sovereign tech and what it means for American companies_\n\nA technology sovereignty package covering cloud, artificial intelligence, and semiconductors is expected later this year. Spanou said it would give American companies a single, predictable compliance framework across all member states rather than 27 separate national regimes, an advantage she described as unique to the European single market.\n\nTransatlantic cooperation remained active despite broader geopolitical tensions, De Vries said, citing contact with CISA, the US Cybersecurity and Infrastructure Security Agency, earlier that morning.\n\nHe said ENISA was working to align a new European vulnerability database, a centralized registry tracking security flaws in software and hardware, with existing US processes.\n\nStill, Spanou said the broader direction of EU policy reflected a fundamental shift in how Europe viewed its relationship with outside technology providers. \"The age of innocence is over,\" Spanou said, paraphrasing European Commission President **Ursula von der Leyen**.",
"title": "EU Cyber Resilience Will Reshape Global Product Security Standards",
"updatedAt": "2026-07-22T22:01:52.382Z"
}