• “Humans Are the Weakest Link?”

    It may be that humans are not the weakest link after all
    (photo by Travis Juntara, CC BY 2.0)

    Most fields of research and practice have their own sayings. Sayings that are said and repeated without much thinking. Sayings that are taken as truisms, but sayings that may be folklore. Cyber security is not immune either, which is curious enough given the field’s underpinnings.

    Let me demonstrate.

    Recently, I peer reviewed a manuscript that contained the age-old claim that “humans are weakest link in cyber security”. The claim has been repeated throughout the years and decades so repeatedly that its origins have been lost. Sometimes, the claim and its associated phrasings are augmented with qualifying adjectives and adverbs; sometimes it is even phrased such that humans are always the weakest link. Nouns and verbs seldom wake me up, but making an assertion even stronger with qualifying words is like morning coffee for my engine.

    Before continuing, apologies for my colleagues in usable security and related domains, legends, and some who do not know their own language. All clear, then: one, two, three. Go.

    One: as a good knowledge commons, I did a literature search. While walking in the swamp for some time, which is increasingly drowning nowadays, I came with a Master’s thesis. After walking a while further, or deeper and damper, I concluded the thesis to be the best evidence available. Already in the abstract it says that the “phrase, as well as its various versions, has been used extensively in security literature, although scientific evidence on the role of human as the weakest link was not found in the research“. I could not agree more.

    Two: the saying belongs to a whole domain of research investigating questionable, unfounded, or even faulty claims without any evidence backing them. Within computing fields, software engineering has been particularly active investigating these claims; for instance, that legal requirements are overbearing for engineers. Similarly, unhelpful assumptions have been cataloged in cyber security. In fact, so common have the sayings been that a phrasing about “Leprechaun claims” has been used.

    But what to make out of all this? After all, disinformation and misinformation are rampart. And no one would deny about weaknesses of humans in cyber security. But academics should know better and do better with language; the correct phrasing would perhaps be that “humans are a weak link”.

    Third: I recommended a revision.

  • What is Cooking in the EU for Open Source Software?

    The EU has shown interest in open source software
    (photo by RG TVL, CC BY 2.0)

    The European Union (EU) has long aspired to bolster its digital sovereignty. Also open source software (OSS) has recently been seen as a factor for strengthening digital sovereignty in Europe. Despite various related EU initiatives, such as those about interoperability, OSS is a fairly recent newcomer in EU politics. Therefore, it is worth taking a brief glance at what is currently happening in this space.

    The European Commission launched a public policy consultation in January 2026 for the EU Open Digital Ecosystem Strategy (EUODES). By and large, the strategy is about OSS. Therefore, it is not surprising that the consultation received attention both in OSS outlets and mainstream technology media. Therefore, again, it is not a surprise that the public policy consultation received as many as 1,658 responses. While trying to summarize them in the present context is neither necessary nor feasible, the perhaps most visible and consistent argument raised was about using public procurement as a lever for supporting OSS and strengthening European digital sovereignty along the way.

    The promotion of OSS in public procurement ended up also into the EUODES. In addition to OSS-friendly tendering, the strategy also emphasizes the role of public administrations in leading a transformation toward open, interoperable, reusable, and sovereign European digital infrastructures. Regarding challenges, the strategy notes fragmentation across Europe and dependence on non-European infrastructures, including for hosting OSS solutions and products. Despite promotional websites (such as this or that), also visibility of European OSS solutions was seen as a challenge. To this end and other ends, the Commission further established a new Open Source Observatory.

    The EUODES also notes funding as a challenge for OSS. Cyber security is a good example in this regard. While the situation has improved thanks to new funding bodies, many challenges still remain. Maintenance burden is among them, including with respect to slop generated by people using large language models. At the same time, the models have also improved the discovery of true positives, verified software vulnerabilities. Against this backdrop, it is worth pointing out that OSS appears also in the EU’s recently released Action Plan on Cybersecurity and Artificial Intelligence.

    And it appears in the action plan for a justified reason: as remarked in the plan, even as much as 98% of all software nowadays contain OSS components and even software powering critical infrastructures average to about a 80% rate. Even with these numbers, which may also be slightly inflated, the plan does not promise actual EU funding for OSS projects. Instead, a campaign is being prepared for improving maintenance of OSS used in critical infrastructure sectors. Though, the campaign planned includes a voluntary sponsorship scheme. “Better than nothing”, would OSS supporters supposedly say.

  • The First CRA Deadline Is Looming: What to Watch For?

    The CRA’s first deadline is about reporting incidents and vulnerabilities
    (photo by Ignas Kukenys, CC BY 2.0)

    The European Union (EU) enacted the Cyber Resilience Act (CRA) in 2024. Its full enforcement will start in December 2027. Before that deadline, however, there is another, earlier deadline: the CRA’s vulnerability and incident reporting obligations will go live on 11 September 2026. Therefore, it is a good time for a small status check on things to watch for.

    What is the earlier deadline about? It is about the mandatory reporting of severe incidents and actively exploited vulnerabilities to European public authorities.

    Although the CRA’s Article 14(5) tries to clarify what severe incidents are, the article’s wording is so broad that interpretations by vendors are the first thing to watch for. Nevertheless, severe incidents are – as the qualifying adjective hints – something more than “conventional” incidents whose reporting is voluntary. One interpretation is that they are a step in an escalation ladder toward full-fledged cyber security crises rather than mere incidents.

    An actively exploited vulnerability is “a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner“, to quote the CRA’s Article 3(42). This definition has two parts. The first is the notion of reliable evidence. To exclude the question about whose evidence, it will again be interesting to see how vendors and public authorities will interpret evidence about exploitation and reliability of it. However, the second part of the definition emphasizes that only unauthorized actions are covered, meaning that penetration testing is excluded. As further clarified in the recently released guidance, a countdown toward the reporting deadlines, which are rather strict, will only start running once a vendor has become aware of active exploitation.

    In addition to interpretations, it will be interesting and relevant to observe how the EU’s reformed incident and vulnerability reporting, coordination, and disclosure framework will perform. Today, in mid-2026, vulnerability coordination and disclosure are in a state of flux due to artificial intelligence tools and frontier large language models (LLMs) in particular. While keeping the everlasting hype in mind, frontier LLMs have accelerated the discovery of new vulnerabilities. At the same time, false positives, slop, and outright spam are causing severe problems for vulnerability disclosure. Given these points, in hindsight, the concept of actively exploited vulnerabilities, which resembles a similar concept used in the United States, seems as a strategically wise choice from the European policy-makers. Indeed: the growth rate of actively exploited vulnerabilities has not been rapid despite the overall growth rate of all vulnerabilities disclosed and reported.

    Regarding governance and public administration, it is relevant to keep an eye on the functioning of the new single reporting platform for incidents and actively exploited vulnerabilities. It may also remedy some of the potential problems that have been speculated; false positives, over-reporting, under-reporting, and reporting quality have all been perceived as potential problems in this regard.

    Analogously, the functioning of the new European Union Vulnerability Database, which was established with the NIS2 directive and which is already online, should be watched for. To put aside questions about meta-data quality and provenance, which are still among the grand challenges in software security, the coordination and reporting by the public authorities of the member states as well as the EU-level coordination and reporting are both something to keep track of. Early probes indicate that only a few European authorities have contributed thus far.

  • What Will Change in the NIS2 Directive?

    NIS2 Is About Critical infrastructures
    (photo by Denkrahm, CC BY 2.0)

     

    The European Union (EU) is implementing a so-called digital omnibus. Depending on a viewpoint, it is about regulatory simplification, deregulation, or something in-between. Also the second network and information security (NIS2 or NIS 2, as it should be officially abbreviated) directive, Directive (EU) 2022/2555, is a part of the digital omnibus. Therefore, it is worth taking a look on what changes can be expected.

    The NIS2 directive together with other recent EU regulations impose various obligations for reporting cyber security incidents. The digital omnibus will streamline the reporting obligations by providing a single entry point for incident reporting. The single entry-point will apply also to reporting of personal data breaches under the GDPR, the General Data Protection Regulation.

    What else? A recent proposal from the European Commission includes six targeted amendments to the NIS2 directive. To begin with, (1) definitions and the directive’s scope will be clarified, and (2) micro- and small-sized domain name system (DNS) providers will be excluded from the scope entirely. To reduce compliance burden, (3) a new category of small mid-cap enterprises will also appear. Furthermore, (4) the NIS2’s all-embracing risk management obligations – the “all-hazards” approach specified in Article 21 – will be supported by implementing acts involving technical and methodological requirements and guidance.

    The last two amendments proposed are perhaps the most interesting ones. The national cyber security strategies of the member states, which were obliged by the NIS2 directive, (5) should be altered by adopting policies for the migration to post-quantum cryptography. Although it is impossible to say when conventional cryptography will start breaking, the preparations seem to be thus well-underway.

    Then, (6) a harmonized scheme will be introduced for collecting data on ransomware attacks. On the operational side, data will be collected on the detection of ransomware attacks, their attack vectors, and the presence (or a lack thereof) of mitigation measures. With respect to significant incidents, which has a specific definition in NIS2, data will be collected on who received a ransom demand and, if possible, by whom, as well as on any payments made, amounts paid, means of payment, recipients, and any cryptocurrencies and their service providers involved. Confidentiality is emphasized in the proposal. In other words, data will flow only between victims and national computer security incident response teams. Given that ransomware is a global menace, open and regular releasing of statistical data can nevertheless be hoped for. After all, the EU is a member of the International Counter Ransomware Initiative.

    Finally, it should be emphasized and understood that the digital omnibus is still being negotiated. As always, nothing is absolutely certain in politics. For instance, some have criticized the streamlining of incident reporting, whereas others have signaled a preference for national entry points for incident reporting instead of a single EU-wide reporting platform. Despite these political preferences, in overall, the changes proposed seem rather noncontroversial and sensible. The political battlegrounds are largely elsewhere.

Category: Cyber security