From June 30 to July 1, Gitex AI Europe took place at Messe Berlin – an international technology exhibition and conference focusing on the intersection of artificial intelligence, cybersecurity, and other future technologies. As a pioneer in AI-based security testing, Bug Bounty Switzerland naturally couldn’t miss this opportunity to participate. We had our own booth both days, where we had many exciting encounters and inspiring conversations with visitors and security experts.
One item on the event agenda stood out to us in particular: a panel discussion on the European Union’s ongoing regulation of ICT infrastructure, services, and supply chains. The panel featured Arno Spiegel, Deputy Director Cybersecurity and Crisis Data Center at the Federal Chancellery of Austria, and Miguel Ángel Cañada from the Spanish National Cybersecurity Institute INCIBE.
Genuine resilience measures along the supply chain
The session title referred to the current year as “Europe’s compliance crunch year”, and there was also talk of an “EU regulatory storm.” And for good reason: The “Network and Information Security Directive 2” (NIS2), the “Digital Operational Resilience Act” (DORA), and the “Cyber Resilience Act” (CRA) will keep many companies busy this year with IT security and cyber resilience requirements.
However, in his remarks, Arno Spiegel pointed out that very small providers, such as software manufacturers, unexpectedly fall under the CRA as well. “There will be small companies with as few as two employees that fall under the CRA. Neither they nor we know that, but they are still governed.” Both panelists also emphasized that the CRA is more than just a documentation process; it requires genuine resilience measures throughout the supply chain. They agreed that it is unlikely that anyone will be fully compliant by the 2027 deadline, which could turn into a real nightmare for some companies.
High-risk suppliers and geopolitics
And the wave of regulation continues. At the beginning of the year, the European Commission presented the Cybersecurity Act 2 (CSA2), another set of regulations that, if adopted, will have a significant impact on organizations and companies in the medium term. The CSA2 focuses on the security of ICT supply chains and aims to establish a binding framework for classifying “high-risk suppliers.”
The new regulation gives compliance requirements a distinct geopolitical dimension. At the same time, management is held to a higher standard of responsibility. According to the draft, violations of these rules could result in fines of up to seven percent of a company’s global annual revenue.
It’s no wonder that companies are looking for cost-effective ways to navigate this flood of regulations. However, they’re facing a structural problem. The two panelists cited the Europe-wide shortage of audit experts in security testing as the biggest obstacle. The regulations are in place, but there are not enough people to review and implement them.
Cyber resilience through AI-based security testing
At Bug Bounty Switzerland, we see this as an opportunity. We believe that our scalable, AI-based security testing can provide valuable support to organizations in implementing these regulations and increasing their cyber resilience.