New Law Demands Five Years Of Security Patches
Tougher rules mean digital device and software manufacturers will have to report security breaches more quickly. They'll also have to offer security patches for at least five years.
The rules come from the European Union. They technically only cover products sold in EU member countries, though in many such cases manufacturers change their behavior worldwide to comply with the rules. The financial penalties for breaking the rules take into account global turnover.
The rules, which will become the Cyber Resilience Act, cover "products with digital elements." These include smart and connected devices, plus software with a security element such as a password manager, virtual private network or antivirus tools. (Source: insideprivacy.com)
Automatic Patches Required
The final version of the law will specify which products come under the rules. It will also designate some as being "important" or "critical", which will determine the precise requirements. The rules don't apply to any open-source software that is produced outside of any commercial activity.
Manufacturers and developers will need to build cyber security into the products from the beginning, including assessing the potential risks, and fully document security processes. They'll also have to issue security patches for five years and allow for automatic updates. This must be separate from any updates that fix performance issues or add new features.
They'll also need to tell national cyber security authorities about any breach within 24 hours of discovering it. For more severe breaches they'll need to tell users of the device or software.
The rules also mean anyone who imports products with digital elements from outside the EU will need to take adequate steps to make sure it is secure.
Hefty Penalties
The maximum penalty for a breach is €15 million or 2.5 percent of global revenue for the year, whichever is higher. (Source: theregister.com)
While the rules have been under discussion since September last year, members of the European Parliament have now completed negotiations with the relevant departments of national governments. It will require a final approval vote which looks almost certain to pass. Once the law comes into force, businesses will have three years to fully comply.
What's Your Opinion?
Are these rules sensible? Would you like to see them applied in other countries? Do you take security policies into account when buying gadgets or software?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Tougher?
The problem with government providing all the guardrails, is the average consumer will become totally ignorant of what security policies actually do, and since they won't care, will be "surprised" when they get compromised and the "too big to fail" companies will pay fines and move on, leaving the end user with the mess. And the lawmakers will pass more laws to make certain "this never happens again".
"surprised" when compromised?
No, the bigger problem is that the COST for all this rulemaking is passed on to the consumer and THAT is when the surprise will happen. Let's face it, any time the companies are forced by law to do or provide something, it is something that the consumer has not requested or it would already be provided. The various government decrees rarely, if ever, take into account the additional cost to the ultimate consumer, whether digital demands or vehicle demands or airplane demands or health demands. When was the last time a government allowed the consumer to choose to pay a lower price and do without those "demands"?