Skip to content

Commit 6d47488

Browse files
author
Hugo
committed
Draft mem safety statement post
1 parent 3fafbb0 commit 6d47488

File tree

2 files changed

+102
-0
lines changed

2 files changed

+102
-0
lines changed
Lines changed: 101 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,101 @@
1+
+++
2+
title = "Statement calling for memory safety incentives for EU cybersecurity policies"
3+
slug = "calling-for-memory-safety-incentives-in-eu-cybersecurity-policies"
4+
authors = ["Hugo van de Pol"]
5+
date = 2025-12-15
6+
7+
[taxonomies]
8+
tags=["announcement"]
9+
10+
[extra]
11+
image = "/blog/mem-safety-statement-share-image-w1600.jpg"
12+
13+
+++
14+
15+
![Improving Europe's cybersecurity posture through memory safety](/blog/mem-safety-statement-share-image-w1600.jpg)
16+
17+
**Today we publish the statement *"Improving Europe's cybersecurity posture through memory safety"*, calling on European and national policymakers to provide clear incentives and support for the large-scale adoption of memory-safe technology**
18+
19+
<!-- more -->
20+
21+
The statement is a joint effort by secure-by-design experts at leading organizations, including Siemens Mobility, Sovereign Tech Agency, OpenSSF, Google, the Linux Foundation, the Rust Foundation, and national cybersecurity committees.
22+
23+
It has been ensorsed by European companies who are at the forefront of technologie, such as Infineon Technologies AG, as well as industry and academic experts, including experts from Signify, Volvo Cars, Radboud University, and TU Delft.
24+
25+
Executive summary:
26+
27+
> “The number of cybersecurity incidents that affect European citizens and businesses is rising at an alarming rate. 70% of the vulnerabilities in major digital systems built on decades-old technologies share the same root cause and can be prevented by using modern, memory-safe technology.
28+
<br/> <br/>
29+
This technology is mature, perfectly fits Europe’s forthcoming secure-by-design approach to cybersecurity, and is the most effective way to protect Europe’s cybersecurity, to reduce cybersecurity costs, and to foster innovation.
30+
<br/> <br/>
31+
However, its adoption rate is slow due to a lack of short-term economic incentives. We’ve now left the door wide open: attackers eagerly exploit vulnerabilities in our major digital systems.
32+
<br/> <br/>
33+
The supporting organisations call on European and national policymakers to act, out of obligation as well as untapped opportunity: to provide clear incentives and support for the large-scale adoption of memory-safe technology.”
34+
35+
**Download the full statement [here](/docs/improving-europes-cybersecurity-posture-through-memory-safety.pdf).**
36+
37+
## The time is now
38+
39+
Having established a lack of awareness from EU and national policy makers, [Tara Tarakiyee and myself, Hugo van de Pol](#about-the-authors) initiated and led joint discussions with security experts and industry stakeholders, and authored the statement as a result.
40+
41+
This lack of awareness contrasts heavily to [the proactive involvement of the Cybersecurity and Infrastructure Security Agency (CISA)](https://www.cisa.gov/securebydesign), among others, in the USA from 2023 onwards. With the CRA on its way, and the examples of CISA et al at our disposal, now is the time for the EU to act.
42+
43+
## Looking ahead
44+
We're looking forward to presenting our point of view to EU and national policy makers, and to continuing to raise awareness of the need for faster adoption of modern memory safe technologie in 2026.
45+
46+
---
47+
48+
## Supporting organisations
49+
50+
- [Internet Security Research Group](https://www.abetterinternet.org/)
51+
- [Tauri](https://v2.tauri.app/)
52+
- [Rust Foundation](https://rustfoundation.org/)
53+
- [Special Interest Group Cybersecurity of ICT Research Platform Netherlands (IPN) and ACCSS](https://ict-research.nl/groups/special-interest-groups/sigsec/)
54+
- [Tweede golf](https://tweedegolf.nl/en)
55+
- [Trifecta Tech Foundation](https://trifectatech.org/)
56+
- [Stackable](https://stackable.tech/en/)
57+
- [OpenPrinting](https://openprinting.github.io/)
58+
- [Systemscape](https://www.systemscape.com/)
59+
- [Ferrous Systems](https://ferrous-systems.com/)
60+
- [Infineon Technologies AG](https://www.infineon.com/)
61+
- [AboutCode Foundation](https://www.aboutcode.foundation/)
62+
- [BlueBird Power](https://www.bluebirdpower.com/)
63+
64+
## Supporting individuals
65+
66+
- Leon Bouwmeester, director of engineering at Hue Connected, Signify
67+
- Julius Gustavsson, Expert System Architect, Volvo Cars
68+
- Till Kamppeter, lead of OpenPrinting
69+
- Mario Goffredo D'Andrea
70+
- Matthias Endler, Corrode
71+
- Bernard van Gastel, Radboud University
72+
- Frederic Ameye
73+
- Irakli Tabagari
74+
- Prof. Achim D. Brucker, University of Exeter (Chair in Cybersecurity)
75+
- Mathias Payer, Associate Professor at EPFL Alexios Voulimeneas, Assistant Professor at TU Delft
76+
- Prof. dr. Jaap-Henk Hoepman
77+
78+
<br />
79+
80+
## Contributors
81+
82+
Contributions to this statement were made by:
83+
- Josh Aas, Internet Security Research Group
84+
- Rebecca Rumbul, Rust Foundation
85+
- Thomas Rooijakkers, TNO
86+
- Jeffrey Vander Stoep, Google
87+
- Benjamin Schilling
88+
- Christian (fukami) Horchert, CrabNebula Ltd.
89+
- prof. dr. H.J. Bos, Vrije Universiteit Amsterdam
90+
- Erik Poll, Radboud University
91+
- Harry van Haaren, Openchip,
92+
- Marius Gläß, Bundesamt für Sicherheit in der Informationstechnik
93+
- Joao Rebelo, S2E Systems B.V.
94+
95+
---
96+
97+
## About the authors
98+
[Tara Tarakiyee](https://www.linkedin.com/in/tarakiyee/) is a Technologist at [Sovereign Tech Agency](https://www.sovereign.tech/), who works on designing supporting and mobilizing resources to encourage, sustain and maintain our open digital infrastructure.
99+
100+
[Hugo van de Pol](https://www.linkedin.com/in/hugo-van-de-pol-90665215/) is Director at [Tweede golf](https://tweedegolf.nl/en) and Board member at [Trifecta Tech Foundation](https://trifectatech.org/), who has been advocating the use of memory-safe technologies like Rust for years.
101+

content/news.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ template = "news.html"
55

66
[extra]
77
blogposts = [
8+
"Statement calling for memory safety incentives for EU cybersecurity policies",
89
"Emulating avx-512 intrinsics in Miri",
910
"Support the call for memory safety incentives in EU cybersecurity policies",
1011
"Frequently Asked Questions about sudo-rs",

0 commit comments

Comments
 (0)