In this episode of Distilling Cyber Policy, hosts Alex Botting and Jen Ellis engage in a thought-provoking discussion with cybersecurity expert and Member of European Parliament, Bart Groothuis. The conversation centers around the Cyber Resilience Act (CRA), its implications for cybersecurity globally, and how to address untrustworthy vendors in European networks..

MEP Groothuis, drawing from his experience as Parliament's cybersecurity rapporteur, sheds light on the extensive influence an individual can have in shaping legislation. He emphasizes the importance of understanding the subject matter and leveraging expertise to convince stakeholders, ultimately shaping the language and provisions of the CRA. This insightful perspective highlights the significant role of security professionals in driving meaningful change.

The conversation then delves into the concept of software liability. Groothuis explains how the legislation provides a framework for legal disputes arising from cybersecurity incidents. He emphasizes the need for clear legislation concerning risky vendors, particularly those associated with countries known for offensive espionage programs. Groothuis advocates for de-risking practices and the incorporation of non-technical factors when evaluating software for critical infrastructure.

Throughout the episode, Groothuis’ expertise and passion for cybersecurity legislation shine. His calls for stronger measures against risky vendors and his efforts to ensure the protection of critical infrastructure create a compelling narrative. Listeners gain valuable insights into the complex world of cybersecurity legislation and the vital role it plays in securing our digital landscape.

Ines Jordan Zoob

Read Next

Examining the White House’s National Cyber Strategy Webinar

A webinar that featured cyber experts who discussed the White House's latest National Cybersecurity Strategy.

Refreshing America’s Cyber Posture: The New National Cybersecurity Strategy and How to Make Sure It Succeeds

The White House released its highly-anticipated 2026 National Cybersecurity Strategy, outlining how the U.S. federal government intends to protect government systems, critical infrastructure, businesses, and citizens.

What States Can Learn from North Carolina’s Approach to Securing Government

As states across the country grapple with how to adopt AI responsibly, North Carolina offers a compelling case study - not because it has all the answers, but because it has built the institutional muscle to learn, adapt, and lead.