Navigating the Compliance and Regulation Maze: What You Need to Know – From The Source EP3
Transcript
Hey everyone, and welcome to another episode of From The Source with your hosts, uh, me, Ilka Turnin. And hi, I am Brian Fox. And today's, uh, fantastic topic.
Brian, uh, is going to be about, uh, the compliance and regulation maze and what you need to know, uh, in order to survive it. Um, Brian, though, I love your hat. Yeah.
Um, so last week with all day DevOps, um, and they made special hats and, uh, and I was told I had to wear it, so I figured I'd wear it here today. Um, because all the sessions are still online on demand, so you can sign up and, and go watch them. It's like 24 hours, uh, of live broadcast stuff across what, like six channels.
Like, I, I don't want to do the math on that, but there's a lot of really interesting sessions. com. You can sign up and you can watch all of them on demand.
And I actually did the maths for you. It's 180 individual talks, uh, across all of those tracks. So it's, it's some of the best of the best.
And, uh, I think you and I both also gave talks. You can safely skip those, but absolutely do look at the back catalog if they're really, really good. Um, but hey, so today's theme, um, uh, on our episode is as governments and regulatory bodies worldwide continue to tie in their focus on software security compliance has become more and more complex, uh, than ever before.
So, uh, in today's episode, what we really wanted to do was do a little bit of a fly by on some of the regulation that's been passed that's about to pass, uh, across the world, and what does that, what does that mean in terms of, uh, compliance? And finally, obviously we'll talk a little bit about what we've seen, uh, organizations do to actually survive this sort of tsunami of, uh, regulation. So why don't we, uh, start off by talking about, uh, my favorite, uh, part of the world, which is where I live, uh, Europe, and talk a little bit about some of the regulation, uh, that's, uh, been passed, uh, over here.
Before we set there, though, regulation in EU is like super complex. Um, there's, there are acts, there are directives, there are other sort of elements, uh, over there. So why don't we, why don't we start there?
Why do, why do, why don't we define, so what does each of these mean? And then let's, let's do a little bit of a drive by on, um, some of the, some of the ones that have been recently passed. Yeah, so I'm not from Europe, so I'll try to explain it and you can, you can, uh, correct me or confirm.
Um, but, uh, I, I was confused about this. So there's two, two main things, um, that have been going on in Europe in this space. There's the Cyber Resiliency Act, and then there is a related product liability directive.
And, um, I was a little bit confused on that. I didn't really pay much attention to the fact that one's an act, one's a directive, but it was recently explained to me that, um, an act is basically a direct, um, set of legislation that basically applies to the entire European Union. You know, it is effectively a past law.
And, um, a directive, however, is more like a set of principles that then the member, uh, countries, the member states have to pass their own, uh, legislation or up their, update their own legislation to comply with, you know, the spirit of what the directive is. Um, and so I think that's important because, uh, one of them would be sort of very uniform across the union. The other one might have country by country nuances.
And also it takes time, once a directive is passed, there's a timeline for which then the, the country legislatures have to do their thing, so it takes even longer to roll it out. Is that a fair description? I, I think that's a really, really good description.
I think my high school, uh, social, uh, social matters teacher would be, uh, very proud of that explanation. So basically, unlike the states, the European Union is sort of a alliance of, of, uh, all of its member states. And what they basically said is, Hey, we'll meet up, um, in, uh, Brussels and in Strasberg and in a bunch of other places, and essentially we'll delegate some of the legislative, uh, ways.
So an act essentially is sort of a very similar thing as a federal, uh, law over in the States. It just automatically, when when an act is passed, it applies exactly as written across all of the member states. There's sort of no room for interpretation versus a directive is really, uh, more of a, every single member state should pass a law that fulfills these criteria and check these checks, these boxes.
You know, every, every country can kind of tweak the act a little bit or the directive a little bit. They can add their own things. Some countries have more strict regulation than others in certain elements, but roughly, uh, roughly they need to comply with the demands.
And if they don't, they actually get a very stern letter from the European Commission saying, you're not in compliance. Uh, and you should go and fix that. So, um, I guess an analogy from a US perspective would be state law versus federal law.
State law might apply locally, might be tighter than federal requirements, but federal law applies uniformly, uh, no matter what. I think that's how I, yeah, We don't have, we don't have the exact equivalent of like, all the states must pass the law, except in certain cases where the federal government might say, uh, the one that comes to mind is the old, uh, speed limit law, you know, and they would say like, if you, if you didn't have a speed limit that was capped at a certain amount, we're not gonna give you as much money for the, for your roads or something like that. So it was, uh, it was not a requirement.
It was, uh, choose your own, but we're not paying you if you don't do what we ask. That's the closest I can think Of. That's a very American interpretation.
I think that's where we kind of differ. We're all like, you know what? Control you shall do it or otherwise there will be, there will be stern telling off, uh, uh, which nobody wants.
So, uh, so you mentioned two things there. You mentioned the Cyber Resilience Act, uh, and you mentioned the product liability directive. And these are pretty huge momentous, uh, momentous, uh, pieces of regulation no matter what, no matter sort of the flavor of it because, uh, each of them have just been cleared by the commission.
I believe that they're just expecting, uh, Ursula on the line, the pre president of the European, uh, council to uh, sign on the dot line, and then it'll get published into essentially the European Journal of Regulation, which makes it, you know, set in stone, uh, and sort of starts an implementation starting gun, uh, starting gun for about 36 months or so. So the CRA especially, I think is pretty monumental 'cause it really changes the way the minimum security requirements for software and a lot of other things. So why don't you give us a quick overview of, uh, kind, kind of what's, uh, embedded in there, because there's quite a lot of history in that.
Yeah, I mean, there, there's, it, it's been quite a long time actually since I read the meat of it. Most of where my focus last year was on trying to ensure that the CRA didn't in inadvertently penalize open source or, or worse cause open source to basically withdraw from the European Union market. Um, which was, uh, a pretty significant outcome last year that could have happened.
We managed to change that and, and, and it's open source is now excluded more or less from, from the CRA, but the, the, the requirements basically lay down things like, you know, uh, honestly sensible best practices. The things you and I talk about all the time, that not shipping with known vulnerabilities that are not mitigated, you know, having bills of materials, um, you know, there's a, there's a whole litany of things in there, but I think the bottom line is that failure to comply can come with pretty significant penalties, um, based on your worldwide revenue up to, I believe, uh, 15 million euros for failing to comply. So it's a pretty, pretty hefty, uh, uh, stick they're gonna hit you with there potentially, if you're not doing these sensible things, It's, it is in fact 50 million euros or 3% of your global annual turnover, whichever is higher.
So, Oh, It's the higher, it's, it's, right. So it's an even sharper stick. Yeah.
Right. And, and so I think that's pretty significant in terms of getting, getting organizations to fa face the, the music and, and, um, and, and do some of the, the right things. Um, and there's, there's been a lot written a lot, you know, um, a lot of thought into the CRA.
And so this one as a directive, you know, once it gets published into the, the journal, as you said, 21 days later, it, it starts to come into effect the actual penalties phase in over two to three years. Um, but that clock basically starts, let's say, a couple months from now. Um, once, once it gets signed and gets published.
Um, you know, I, I think the, I think the product liability directive, however, might be a sleeper changer, and it may, um, may have a much more profound impact, in my opinion. 1000%. Yeah.
Um, so, so, you know, you've heard me talk a lot about, you know, my frustration with the industry not really doing the right thing for the right reasons and, and kind of, um, you know, uh, checking the box, if you will. And then when they screw up and all of our data gets leaked, you know, the, the downside is they buy us credit monitoring. At least that's what happens in the, in the us, you know, like That's pretty much exactly what Yeah, yeah, that's exactly what happens here as well.
You know, have a have a one year annual subscription to this paid for service that you automatically get, uh, rolled into a Subscription to, right? And, and you've got 10 of them because 10 companies have leaked your data all over the place. It's, it's a ridiculous situation where the, the cost of failure is not high enough for organizations to invest appropriately, right?
So that's, that's my opinion. I've spoken and written on this for, for a while, and I think it's actually happening now in Europe, right? So the product liability directive is not actually new.
There are, there is an existing, uh, EU wide PLD, uh, for many years ago, but the, the important part is it carved out digital goods. So software, other things that were digital in nature were not included in that PLD. What the change this year is, is basically removes that exemption and provides a little bit more clarity.
Um, and so basically it means, you know, software that causes harm, um, that loses data, destroys things. Um, now those organizations, um, can be sued, um, you know, like any other product, uh, failure. And so I think that will change the, change the economics quite a bit for companies will now have to focus not only on checking the box and being compliant like the CRA requires them to do, but now they will ultimately be on the hook for the final outcome.
So even if you do all those things and you still bring a, a product into market that causes harm or leaks data or does whatever, you might be susceptible to lawsuits. Now where it gets a little bit more complicated is because the European Union only can control what's going on inside their borders. There's this whole concept of importing software and distribution, you know, and these things make sense in the physical, uh, goods world, but it's a little bit harder to get your head around in terms of the software, who in fact is the importer and distributor may be unclear.
And so I think that's going to be where some of the nuances, um, you know, the PLD also pretty clearly excludes the makers of open source, but not when somebody includes open source in a product and then sells it or distributes it, they are on the hook for that, as I believe they should be, right? So if you're choosing to use a thing for free, great, but you're still producing a product, you, you bear the responsibility of that. And I think ultimately that's where it's going to change some of the behaviors for the better.
Yeah, I think, I think it's a, it, it's a very big mental change. 'cause up to this point, um, you know, the way that the software industry and liability has worked is we also have an unusual, some agreement. There's big indemnity clauses there that basically say, uh, you know, you, you agreed to basically waive all of our rights, you know, just, just like this famous Disney Plus case.
Like, hey, somebody signed on a Disney plus eula, so they can't sue Disney, the corporation, uh, for any of his aspects. Uh, allegedly. So, so, uh, you know, the Yes.
Yeah, like the liability li like, it, it's that, it's like that, it's, it's a contract, right? People are Wondering what you're talking about. Somebody, I, I believe his wife got injured or maybe killed at a Disney park, and they were trying to claim because they signed up for Disney plus the video streaming service Like two years ago, Two years prior during some trial, that they basically waived all indemnification against the company for all things.
Um, I've lost track of where that is, but it's certainly, um, an, an aggressive interpretation of that law. Yeah. And it, it's sort of a good example of how it actually works in software when you think about it, right?
You know, we, we signed this U list, uh, and that EULA basically always without exception, says, Hey, by the way, you get the software as is, it's up to you to maintain it. Uh, no guarantees. And you can't sue us for any losses because it's up, it's up to you.
So really what each of these laws to me, uh, kind of mean is, um, first of all just, you know, find any piece of electronics. Like I've got this wireless charging pad here, uh, that's sat at my desk. Um, you'll actually usually find like a little stencil, like a CE stencil, uh, on each and every one of them.
And that's like, like in here, if you can kind of see on my video here. Um, that's really what they're applying to software. Now, every piece of software made available in the European Indian market, regardless of where it was manufactured.
You build it in the states, you put it in, in Europe, you're gonna need this. Um, you build it in Europe, you're still gonna need this, it needs to attain per version of software a CE mark. That's, that's, that's in on itself already a pretty interesting thing that you have to sort of self-certify every single one of your releases to be compliant with those security best practices that, you know, we've, we kind of think are pretty much aligned with industry best practice anyway.
But if you haven't been thinking about it now, you actually genuinely do. And what the product liability directive does is if somebody then takes your software, even if they misuse it and it causes data loss, like let's say, I don't know, they like feed all the fields really stupid stuff, and they like manage to craft the server and whatever, if that leads to data loss and you didn't certify your software up to that standard, that means that you can be sued for, I think it's limitless li uncapped liability essentially in a court of law law. Like even if they misuse the product and used it wrong, but you manufactured it wrong, you're liable.
And that applies in any other good. Like of course, if I crash a car by speeding, and it turns out the car was mismanufactured, I'm gonna take the manufacturer the cord, that's like a known, uh, brainer. But, uh, extending that line of thinking now into software is, is, is what's happening with these regulations.
And that I think is going to be the big, uh, big sort of, uh, uh, hitter that's gonna really start making this, uh, sort of regulation sinking in. I think we've had sort of industry best practice and self-regulation for quite a many years, and some companies do it really well, some do it less so well. Um, but to have something this deep, like essentially it's all the regulators, you know, especially in Europe, but also in the states, you guys have had passed some fairly similar laws and, uh, Jan Lee from CSIS made some very similar liability sounds, uh, as well in public, uh, engagements.
Yeah, but we're, we're, we're only just talking about it and only very circles about it. So I'm, I'm particularly, particularly interested to see how this rolls out. Um, in, in Europe, of course, it's gonna take several years.
I think, um, the, uh, it's gonna take two years, or at least up to two years for the member states to pass their own version of the laws. Who knows how long those things will take to phase in if they're, if they're, if they apply, um, instantly, if there's backwards com, you know, uh, compatibility or any, you know, anything like that that happens, um, uh, will, will remain to be seen. The other interesting part is it doesn't stop there.
Uh, we were chatting before the recording, there is also the draft AI liability directive. Um, and, um, that one is still very early. Uh, I think they were waiting to see how the PLD and some of the other things unfolded, whether they even need it for reasons I don't completely have my head around.
Um, apparently they feel like they need additional liability directives on ai, which is a little perplexing to me because AI is software and it's a product, and so therefore it seems like it would be covered by default with the new change. But I'm sure there's some nuances there. Um, the current draft, I'm told does not have an exclusion for anything open source.
So we're kind of back to the, the starting point. But, uh, I think the community feels pretty good that, that those exceptions will be made because it needs to be aligned with the PLD and the CRA. It wouldn't make sense for it to be more punitive around open source.
Um, but you know, as with all things, you know, the battle continues. Um, there's more coming more to figure out. Um, But, and, and that's not all The, the bottom line for companies is, you know, if you've been in denial that nothing's gonna happen.
Especially if in your, you're in the US and you feel like, yeah, Congress isn't gonna change the liability laws and the contract laws to, to, you know, preclude you from disclaiming liability in the eula, you might be right. And also, it probably doesn't matter because Europe is, is kind of leading the way on the liability side. And basically every company is a global company these days, and that means you're gonna have to pay attention and follow these regulations.
So, you know, I think it's sort of a matter of, uh, how quickly can you turn your own organization around to be in a place where you feel like you, you are covered from both A CRA and A PLD versus how long is it gonna take to phase? In many large organizations, it may take them longer than two years to clean up their mess. Um, and so that means you're already behind the scenes, behind, behind the time.
Yes, you've got two years before the hammer comes down, but if you're not ready by then, good luck to you. So I think that's the kind of takeaway, you better get started now if you're not ready. And if 1000%, I mean, um, I mean it's like DDPR to be honest.
Uh, you know, I think, um, it's gonna follow a very similar path. I think, uh, a lot of organizations will forget about it for a while and then it'll come back with a bang. And when the first big fines are coming out, that's really when the big, uh, sort of drive for change is gonna start happening.
Um, and I wish, you know, we we're actually, uh, uh, starting to run out of time for this episode, but that's not even all of the regulation that's come out recently, like in two days time. At the point of this recording, we are going to see something called network and infrastructure directive, uh, uh, pass in the u in, in the eu. And what that already does is take some of those requirements from the CRA and applies it vertically to some sort of more in societally critical industries.
You know, things like transport, energy, banking, financial markets, postal careers, but also digital service providers, online marketplaces, search engines, social networking, uh, cloud computing seems like all the Things. Basically all, all of the things, I mean, I, I could be reading this list, uh, forever and ever, but basically this, there's also something called the, the Digital Operational Resilience Act, or Dora, um, uh, which is another directive that's been, um, uh, that's been passed to, uh, in past the financials. Basically what all of these are saying is there's now a minimal level of cybersecurity that's expected of you as a service provider, as a software manufacturer, as a product developer.
And if you fail to demonstrate that you've done those things, you have those, uh, steps as well as the policies, as well as demonstrate that when you built the software at the time that you did all of those things, the regulators are going to come after you. I think that's the big sort of takeaway. So if you haven't been thinking about, thinking about having some minimal level of understanding, I think now is high time.
Uh, otherwise it's gonna be way, way, way too late. Yep. I, I, I think that's exactly right.
Right. Well, um, uh, uh, one of the things, uh, that you can actually do if you want to see, uh, what you, what you should do is we've actually published a lovely little regulations hub, uh, because there's so many of these, and each of 'em have these, uh, have these sort of super big requirements. So we've, uh, published these sort of very handy, uh, checklist actually, uh, that you can take a look, you know, kind of goes through each of the regulations, kind of tells you a little bit about what you need to do.
And on the flip side, we also have a pretty picture that kind of shows you what you need to be doing, uh, across the sdlc. So we'll put that on the show notes. Go, go take a look.
There's a lot of things to be understanding there, but Brian, um, any closing thoughts of, uh, part on this? I mean, it sounds like a big tsunami of our change coming our way. Yep.
Um, you know, it's, it's time to get out of the denial phase and into acceptance phase and start getting your organization ready. I mean, it's just as simple as that. I couldn't have said it, uh, better than that, man.
I still am jealous because they actually, uh, ran outta my size, uh, on that cap. So I, I'm still waiting for my back. Well, this would Make you happy if heard you.
I had another one here. What? Oh man.
Well on that, we'll see you next time. Alright, bye everyone.

