Skip to content

Commit f5b3c65

Browse files
authored
Merge pull request #64 from trifectatechfoundation/mem-safety-statement
Draft mem safety statement post
2 parents 45ee567 + a8dcbf3 commit f5b3c65

6 files changed

+110
-1
lines changed

content/_index.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ supporters = [
3030
]
3131

3232
blogposts = [
33-
"Support the call for memory safety incentives in EU cybersecurity policies",
33+
"Calling for memory safety incentives in EU cybersecurity policies",
3434
"Canonical releases Ubuntu 25-10 with sudo-rs as the default sudo",
3535
"ntpd-rs now supports version 5 of the Network Time Protocol",
3636
"zlib-rs is faster than C",
Lines changed: 108 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,108 @@
1+
+++
2+
title = "Calling for memory safety incentives in EU cybersecurity policies"
3+
slug = "calling-for-memory-safety-incentives-in-eu-cybersecurity-policies"
4+
authors = ["Hugo van de Pol"]
5+
date = 2025-12-17
6+
7+
[taxonomies]
8+
tags=["announcement"]
9+
10+
[extra]
11+
image = "/blog/mem-safety-statement-share-image-w1600.jpg"
12+
13+
+++
14+
15+
![Improving Europe's cybersecurity posture through memory safety](/blog/mem-safety-statement-share-image-w1600.jpg)
16+
17+
**Today we publish the statement *"Improving Europe's cybersecurity posture through memory safety"*, calling on European and national policymakers to provide clear incentives and support for the large-scale adoption of memory-safe technology.**
18+
19+
<!-- more -->
20+
21+
The statement is a joint effort by secure-by-design experts at leading organizations, including Siemens Mobility, Sovereign Tech Agency, OpenSSF, Google, the Linux Foundation, the Rust Foundation, and national cybersecurity committees.
22+
23+
It has been endorsed by European companies at the forefront of technology, such as Infineon Technologies AG, as well as industry and academic experts, including specialists at Signify, Volvo Cars, Radboud University, and Delft University of Technology.
24+
25+
Executive summary:
26+
27+
> “The number of cybersecurity incidents that affect European citizens and businesses is rising at an alarming rate. 70% of the vulnerabilities in major digital systems built on decades-old technologies share the same root cause and can be prevented by using modern, memory-safe technology.
28+
<br/> <br/>
29+
This technology is mature, perfectly fits Europe’s forthcoming secure-by-design approach to cybersecurity, and is the most effective way to protect Europe’s cybersecurity, to reduce cybersecurity costs, and to foster innovation.
30+
<br/> <br/>
31+
However, its adoption rate is slow due to a lack of short-term economic incentives. We’ve now left the door wide open: attackers eagerly exploit vulnerabilities in our major digital systems.
32+
<br/> <br/>
33+
The supporting organisations call on European and national policymakers to act, out of obligation as well as untapped opportunity: to provide clear incentives and support for the large-scale adoption of memory-safe technology.”
34+
35+
View or download the full statement **[here](/docs/improving-europes-cybersecurity-posture-through-memory-safety.pdf)**.
36+
<br />
37+
<br />
38+
39+
## The time is now
40+
41+
We have established a lack of awareness among EU and national policymakers. This contrasts heavily to [the proactive involvement of the Cybersecurity and Infrastructure Security Agency (CISA)](https://www.cisa.gov/securebydesign), among others, in the USA from 2023 onwards.
42+
43+
With the CRA on its way, now is the time for the EU to act.
44+
45+
## Looking ahead
46+
We're looking forward to presenting our point of view to EU and national policymakers, and to continuing to advocate for faster adoption of modern memory-safe technology in 2026. We're aiming to bring this statement to various events in 2026 and will keep you updated on where to find us.
47+
48+
## Get involved
49+
Our primary goal is to bring memory safety to the forefront of current policy discussions, and we need your help to do it.
50+
51+
If you are involved in relevant European or national policy making, or can put us in contact with someone who is, **please reach out to [Hugo van de Pol](mailto:hugo@trifectatech.org?subject=I'd%20like%20to%20help%20advocate%20for%20memory%20safety)**.
52+
53+
---
54+
55+
## Supporting organisations
56+
57+
- [Internet Security Research Group](https://www.abetterinternet.org/)
58+
- [Tauri](https://v2.tauri.app/)
59+
- [Rust Foundation](https://rustfoundation.org/)
60+
- [Special Interest Group Cybersecurity of ICT Research Platform Netherlands (IPN) and ACCSS](https://ict-research.nl/groups/special-interest-groups/sigsec/)
61+
- [Tweede golf](https://tweedegolf.nl/en)
62+
- [Trifecta Tech Foundation](https://trifectatech.org/)
63+
- [Stackable](https://stackable.tech/en/)
64+
- [OpenPrinting](https://openprinting.github.io/)
65+
- [Systemscape](https://www.systemscape.com/)
66+
- [Ferrous Systems](https://ferrous-systems.com/)
67+
- [Infineon Technologies AG](https://www.infineon.com/)
68+
- [AboutCode Foundation](https://www.aboutcode.foundation/)
69+
- [BlueBird Power](https://www.bluebirdpower.com/)
70+
71+
## Supporting individuals
72+
73+
- Leon Bouwmeester, director of engineering at Hue Connected, Signify
74+
- Julius Gustavsson, Expert System Architect, Volvo Cars
75+
- Till Kamppeter, lead of OpenPrinting
76+
- Mario Goffredo D'Andrea
77+
- Matthias Endler, Corrode
78+
- Bernard van Gastel, Radboud University
79+
- Frederic Ameye
80+
- Irakli Tabagari
81+
- Prof. Achim D. Brucker, University of Exeter (Chair in Cybersecurity)
82+
- Mathias Payer, Associate Professor at EPFL Alexios Voulimeneas, Assistant Professor at TU Delft
83+
- Prof. dr. Jaap-Henk Hoepman
84+
85+
<br />
86+
87+
## Contributors
88+
89+
Contributions to this statement were made by:
90+
- Josh Aas, Internet Security Research Group
91+
- Rebecca Rumbul, Rust Foundation
92+
- Thomas Rooijakkers, TNO
93+
- Jeffrey Vander Stoep, Google
94+
- Benjamin Schilling
95+
- Christian (fukami) Horchert, CrabNebula Ltd.
96+
- prof. dr. H.J. Bos, Vrije Universiteit Amsterdam
97+
- Erik Poll, Radboud University
98+
- Harry van Haaren, Openchip,
99+
- Marius Gläß, Bundesamt für Sicherheit in der Informationstechnik
100+
- Joao Rebelo, S2E Systems B.V.
101+
102+
---
103+
104+
## About the authors
105+
[Tara Tarakiyee](https://www.linkedin.com/in/tarakiyee/) is a Technologist at [Sovereign Tech Agency](https://www.sovereign.tech/), who works on designing supporting and mobilizing resources to encourage, sustain and maintain our open digital infrastructure.
106+
107+
[Hugo van de Pol](https://www.linkedin.com/in/hugo-van-de-pol-90665215/) is Director at [Tweede golf](https://tweedegolf.nl/en) and Board member at [Trifecta Tech Foundation](https://trifectatech.org/), who has been advocating the use of memory-safe technologies like Rust for years.
108+

content/news.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@ template = "news.html"
55

66
[extra]
77
blogposts = [
8+
"Calling for memory safety incentives in EU cybersecurity policies",
89
"Emulating avx-512 intrinsics in Miri",
910
"Support the call for memory safety incentives in EU cybersecurity policies",
1011
"Frequently Asked Questions about sudo-rs",

static/docs/.DS_Store

0 Bytes
Binary file not shown.
Binary file not shown.
Binary file not shown.

0 commit comments

Comments
 (0)