Making Software Safer

Reflections on a seminar held in Malta at the dawn of the Cyber Resilience Act

denjell 29 de julio de 2024
Making Software Safer

On the 24th of July, 2024, at the Malta Chamber, Jean-Marie Mifsud (Chief Innovation Technology Officer, Malta Digital Innovation Authority) and Ian Gauci (Managing Partner, GTG Advocates) joined me (CEO, CrabNebula), on stage to talk about the Cyber Resilience Act. A livestream was provided, with support of NGI, so please feel free to read to the end of this post to listen to the full recording of the conversation.

The Cyber Resilience Act (CRA) is a piece of European legislation (expected to enter force in September of 2024) that places cybersecurity requirements on the manufacturers of software who sell their digital products on the European Single Market.

This is important, because all of us are touched by software, and when things go wrong, people's lives can be negatively impacted. Indeed, the world was still recovering from Crowdstrike's botched update just a few days before the seminar, so the impact of poor software controls was particularly present in the mood of the room. Malta, after all, is really a place that most people reach by airplane - and many cash machines still use Windows operating systems.

The panel discussion introduced key aspects of the CRA, including what types of products needs to comply with its regulations (any product with data connectivity), what the regulation itself consists of, and when the rules will be applied. There was an introduction to the Blue Guide, as well as a presentation about risks and opportunities within the business field.

Aside from the academic and faithful representation of the act from the Regulatory, Legal, and business perspectives, I found four insights to be particularly interesting.

  1. We already have a solid understanding about the liabilities and requirements of the manufacture and dissemination of products on the European market, thanks to the Blue Guide. Indeed, terms have not been invented to describe the relations between a Manufacturer and an End-User. This has benefits and challenges in and of itself.
  2. It seems like "local-first" or more properly"local-only" software might not have to comply with the CRA, because it does not have external data connectivity. I will have to do more research into how to prove the "local-first" nature of a piece of software, but it is an exciting perspective.
  3. Ian made a very interesting point about European-based companies, and that is that even if your company has no users in Europe, you will still have to comply with the CRA. In this case, his recommendation was for your operations to move out of the European Union!!!
  4. Open Source Software Stewards can also be companies, but you will have to be very careful about how you describe and declare the project - to differentiate it from other potential software-product liabilities.

There is a great conversation in the full audio recording, so please feel free to listen to it here: Making-Software-Safer.mp3

Photo: Luis Alberto Sanchez