|
| 1 | ++++ |
| 2 | +title = "Statement calling for memory safety incentives for EU cybersecurity policies" |
| 3 | +slug = "calling-for-memory-safety-incentives-in-eu-cybersecurity-policies" |
| 4 | +authors = ["Hugo van de Pol"] |
| 5 | +date = 2025-12-15 |
| 6 | + |
| 7 | +[taxonomies] |
| 8 | +tags=["announcement"] |
| 9 | + |
| 10 | +[extra] |
| 11 | +image = "/blog/mem-safety-statement-share-image-w1600.jpg" |
| 12 | + |
| 13 | ++++ |
| 14 | + |
| 15 | + |
| 16 | + |
| 17 | +**Today we publish the statement *"Improving Europe's cybersecurity posture through memory safety"*, calling on European and national policymakers to provide clear incentives and support for the large-scale adoption of memory-safe technology** |
| 18 | + |
| 19 | +<!-- more --> |
| 20 | + |
| 21 | +The statement is a joint effort by secure-by-design experts at leading organizations, including Siemens Mobility, Sovereign Tech Agency, OpenSSF, Google, the Linux Foundation, the Rust Foundation, and national cybersecurity committees. |
| 22 | + |
| 23 | +It has been ensorsed by European companies who are at the forefront of technologie, such as Infineon Technologies AG, as well as industry and academic experts, including experts from Signify, Volvo Cars, Radboud University, and TU Delft. |
| 24 | + |
| 25 | +Executive summary: |
| 26 | + |
| 27 | +> “The number of cybersecurity incidents that affect European citizens and businesses is rising at an alarming rate. 70% of the vulnerabilities in major digital systems built on decades-old technologies share the same root cause and can be prevented by using modern, memory-safe technology. |
| 28 | +<br/> <br/> |
| 29 | +This technology is mature, perfectly fits Europe’s forthcoming secure-by-design approach to cybersecurity, and is the most effective way to protect Europe’s cybersecurity, to reduce cybersecurity costs, and to foster innovation. |
| 30 | +<br/> <br/> |
| 31 | +However, its adoption rate is slow due to a lack of short-term economic incentives. We’ve now left the door wide open: attackers eagerly exploit vulnerabilities in our major digital systems. |
| 32 | +<br/> <br/> |
| 33 | +The supporting organisations call on European and national policymakers to act, out of obligation as well as untapped opportunity: to provide clear incentives and support for the large-scale adoption of memory-safe technology.” |
| 34 | + |
| 35 | +**Download the full statement [here](/docs/improving-europes-cybersecurity-posture-through-memory-safety.pdf).** |
| 36 | + |
| 37 | +## The time is now |
| 38 | + |
| 39 | +Having established a lack of awareness from EU and national policy makers, [Tara Tarakiyee and myself, Hugo van de Pol](#about-the-authors) initiated and led joint discussions with security experts and industry stakeholders, and authored the statement as a result. |
| 40 | + |
| 41 | +This lack of awareness contrasts heavily to [the proactive involvement of the Cybersecurity and Infrastructure Security Agency (CISA)](https://www.cisa.gov/securebydesign), among others, in the USA from 2023 onwards. With the CRA on its way, and the examples of CISA et al at our disposal, now is the time for the EU to act. |
| 42 | + |
| 43 | +## Looking ahead |
| 44 | +We're looking forward to presenting our point of view to EU and national policy makers, and to continuing to raise awareness of the need for faster adoption of modern memory safe technologie in 2026. |
| 45 | + |
| 46 | +--- |
| 47 | + |
| 48 | +## Supporting organisations |
| 49 | + |
| 50 | +- [Internet Security Research Group](https://www.abetterinternet.org/) |
| 51 | +- [Tauri](https://v2.tauri.app/) |
| 52 | +- [Rust Foundation](https://rustfoundation.org/) |
| 53 | +- [Special Interest Group Cybersecurity of ICT Research Platform Netherlands (IPN) and ACCSS](https://ict-research.nl/groups/special-interest-groups/sigsec/) |
| 54 | +- [Tweede golf](https://tweedegolf.nl/en) |
| 55 | +- [Trifecta Tech Foundation](https://trifectatech.org/) |
| 56 | +- [Stackable](https://stackable.tech/en/) |
| 57 | +- [OpenPrinting](https://openprinting.github.io/) |
| 58 | +- [Systemscape](https://www.systemscape.com/) |
| 59 | +- [Ferrous Systems](https://ferrous-systems.com/) |
| 60 | +- [Infineon Technologies AG](https://www.infineon.com/) |
| 61 | +- [AboutCode Foundation](https://www.aboutcode.foundation/) |
| 62 | +- [BlueBird Power](https://www.bluebirdpower.com/) |
| 63 | + |
| 64 | +## Supporting individuals |
| 65 | + |
| 66 | +- Leon Bouwmeester, director of engineering at Hue Connected, Signify |
| 67 | +- Julius Gustavsson, Expert System Architect, Volvo Cars |
| 68 | +- Till Kamppeter, lead of OpenPrinting |
| 69 | +- Mario Goffredo D'Andrea |
| 70 | +- Matthias Endler, Corrode |
| 71 | +- Bernard van Gastel, Radboud University |
| 72 | +- Frederic Ameye |
| 73 | +- Irakli Tabagari |
| 74 | +- Prof. Achim D. Brucker, University of Exeter (Chair in Cybersecurity) |
| 75 | +- Mathias Payer, Associate Professor at EPFL Alexios Voulimeneas, Assistant Professor at TU Delft |
| 76 | +- Prof. dr. Jaap-Henk Hoepman |
| 77 | + |
| 78 | +<br /> |
| 79 | + |
| 80 | +## Contributors |
| 81 | + |
| 82 | +Contributions to this statement were made by: |
| 83 | +- Josh Aas, Internet Security Research Group |
| 84 | +- Rebecca Rumbul, Rust Foundation |
| 85 | +- Thomas Rooijakkers, TNO |
| 86 | +- Jeffrey Vander Stoep, Google |
| 87 | +- Benjamin Schilling |
| 88 | +- Christian (fukami) Horchert, CrabNebula Ltd. |
| 89 | +- prof. dr. H.J. Bos, Vrije Universiteit Amsterdam |
| 90 | +- Erik Poll, Radboud University |
| 91 | +- Harry van Haaren, Openchip, |
| 92 | +- Marius Gläß, Bundesamt für Sicherheit in der Informationstechnik |
| 93 | +- Joao Rebelo, S2E Systems B.V. |
| 94 | + |
| 95 | +--- |
| 96 | + |
| 97 | +## About the authors |
| 98 | +[Tara Tarakiyee](https://www.linkedin.com/in/tarakiyee/) is a Technologist at [Sovereign Tech Agency](https://www.sovereign.tech/), who works on designing supporting and mobilizing resources to encourage, sustain and maintain our open digital infrastructure. |
| 99 | + |
| 100 | +[Hugo van de Pol](https://www.linkedin.com/in/hugo-van-de-pol-90665215/) is Director at [Tweede golf](https://tweedegolf.nl/en) and Board member at [Trifecta Tech Foundation](https://trifectatech.org/), who has been advocating the use of memory-safe technologies like Rust for years. |
| 101 | + |
0 commit comments