Shaping Cybersecurity: How Regulation Shapes Operational Cyber Defense

Christiane Kirketerp de Viron (Director for Digital Society, Trust & Cybersecurity, DG Connect · European Commission), Tim Maurer (Senior Director, Global Cybersecurity Policy · Microsoft), Ari Schwartz (Managing Director, Cybersecurity Services · Venable LLP), Josephine Wolff (Associate Professor of Cybersecurity Policy · Tufts University, The Fletcher School), Florian Schütz (Director, NCSC · National Cybersecurity Centre (Switzerland))

RSA Conference 2025 · Day 1 · Policy · Policy & Government

Overview

Cybersecurity regulation has expanded dramatically over the past decade, but the proliferation of jurisdiction-specific rules is creating a compliance burden that may actually impede the security outcomes regulators are trying to achieve. A high-level panel at RSA 2025 — drawing on perspectives from the European Commission, the Swiss National Cybersecurity Centre, industry, and academia — examined the state of global regulatory fragmentation, identified five areas where international coordination would have the most impact, and debated what "good" regulation actually looks like in practice. ---

Watch on YouTube

Visual summary for Shaping Cybersecurity: How Regulation Shapes Operational Cyber Defense by Christiane Kirketerp de Viron, Tim Maurer, Ari Schwartz, Josephine Wolff, Florian Schütz
Visual summary for Shaping Cybersecurity: How Regulation Shapes Operational Cyber Defense by Christiane Kirketerp de Viron, Tim Maurer, Ari Schwartz, Josephine Wolff, Florian Schütz

Key moments

  1. 3:53 Patchwork of sector-specific cyber rules creates compliance overload without security gains
  2. 12:31 EU's NIS2 places cybersecurity accountability at boardroom level across 27 member states
  3. 8:26 Industry ranks reciprocity over harmonization as most achievable regulatory coordination
  4. 9:06 Five industry priority areas: critical infra, post-quantum, software supply chain, incident reporting, AI
  5. 21:51 Conflicting global incident reporting timelines create compliance paralysis for multinationals
  6. 29:56 Liability shift toward software vendors for insecure-by-design products gaining regulatory traction
  7. 38:13 Regulators urged to measure actual security outcomes, not just compliance checkbox completion

Shaping Cybersecurity: How Regulation Shapes Operational Cyber Defense

Speakers: Tim Maurer (Microsoft, moderator), Christiane Kirketerp de Viron (European Commission), Florian Schütz (Swiss NCSC), Ari Schwartz (Venable LLP), Josephine Wolff (Tufts University)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=FZKUxDYHVLI

Reading time: ~9 minutes

TL;DR

Cybersecurity regulation has expanded dramatically over the past decade, but the proliferation of jurisdiction-specific rules is creating a compliance burden that may actually impede the security outcomes regulators are trying to achieve. A high-level panel at RSA 2025 — drawing on perspectives from the European Commission, the Swiss National Cybersecurity Centre, industry, and academia — examined the state of global regulatory fragmentation, identified five areas where international coordination would have the most impact, and debated what "good" regulation actually looks like in practice.

Introduction

On the final day of RSA Conference 2025, a room that might have been expected to be sparsely populated was instead packed with practitioners willing to spend the last morning of the conference grappling with one of the most consequential — and least glamorous — topics in cybersecurity: how government regulation shapes, or fails to shape, actual security outcomes.

Moderated by Tim Maurer, Senior Director for Global Cybersecurity Policy at Microsoft, the panel brought together Christiane Kirketerp de Viron (Director for Digital Society, Trust & Cybersecurity at the European Commission's DG Connect), Florian Schütz (Director of Switzerland's National Cybersecurity Centre and Chair of the OECD Working Party on Digital Security), Ari Schwartz (Managing Director at Venable LLP and advisor to multiple industry coalitions), and Josephine Wolff (Associate Professor of Cybersecurity Policy at Tufts University's Fletcher School). The conversation moved from diagnosis to practical recommendations — and surfaced genuine tensions between regulatory ambition and operational reality.

From Patchwork to Proliferation: The State of Global Cyber Regulation

Josephine Wolff opened with an academic survey of the regulatory landscape's evolution. Until roughly ten to fifteen years ago, cybersecurity regulation was minimal and sector-specific — a few requirements in healthcare, some in finance. What changed, she argued, was a cascade of high-profile incidents that pushed sector after sector to demand rules.

"We go from a regulatory landscape where regulation really isn't shaping operational cyber defense... to a moment beginning I would say five to eight years ago where a lot of different sectors are starting to think about: we need some kind of cybersecurity standards or requirements," Wolff said. ▶ Watch: The shift in regulatory landscape (3:42)

The result in the United States has been a patchwork of sector-specific rules — separate requirements for health, transportation, energy, pipelines, finance — that often focus on the same underlying controls (encryption, multi-factor authentication, network segmentation) but with their own vocabulary, thresholds, and interpretations. Organizations providing shared cloud infrastructure across multiple regulated sectors face the challenge of compliance with dozens of overlapping frameworks that disagree on details like whether SMS-based MFA is acceptable.

Europe's approach, as Kirketerp de Viron explained, has been more explicitly harmonizing. NIS2 spans multiple critical sectors, places responsibility at the boardroom level, and is designed to prevent the EU's twenty-seven member states from developing incompatible requirements that would fragment the internal market. ▶ Watch: NIS2 logic explained (11:44)

The Industry View: Five Areas Where Coordination Would Help Most

Ari Schwartz reported findings from a study conducted with the Coalition to Reduce Cyber Risk — a group of major regulated companies spanning banking, energy, telecoms, and large technology firms. The study asked companies to rank the types of international coordination they most needed, and to identify the specific regulatory domains where divergence was most harmful.

On the question of coordination type, respondents ranked reciprocity — mutual acceptance of certifications and standards, with limited supplementary requirements — as the most helpful and realistic approach. Pure harmonization (agreeing on a single global standard from scratch) and blanket alignment (mapping existing rules to each other) were seen as less achievable. ▶ Watch: Reciprocity as the realistic path (8:11)

The five priority areas the industry identified, in order:

  1. Critical infrastructure controls and certifications — where duplication of certification requirements creates the most friction for globally operating firms.
  2. Post-quantum cryptography standards — where a scenario of multiple incompatible PQC standards would be, in Schwartz's words, "a total disaster."
  3. Connected devices (IoT) — mutual recognition for consumer and industrial device security certifications.
  4. Incident reporting — harmonizing threshold, information type, common form, and timing — in that order of priority.
  5. Secure software — development controls and third-party assessment methodologies. ▶ Watch: The five coordination priorities (8:40)

Schwartz was notably candid about incident reporting being the hardest area to resolve. The problem has four distinct sub-components — when to report, what to include, in what format, and by what deadline — and different jurisdictions disagree on all four. The 24-hour, 48-hour, and 72-hour reporting windows in common use reflect different threat models and different understandings of what "significant" means.

Europe's Regulatory Toolkit: NIS2 and the Cyber Resilience Act

Kirketerp de Viron walked through the European Commission's two landmark instruments: NIS2 for critical infrastructure and the Cyber Resilience Act (CRA) for products. The logic, she explained, is layered: NIS2 addresses the entities that operate critical services, while the CRA addresses the products those entities — and millions of consumers — use.

The CRA is particularly significant for global supply chains. It requires that digital products sold in the EU be secure by design and maintained with security updates over their lifecycle. Because the EU market is large enough to create de facto global standards (the "Brussels effect"), product vendors will increasingly need to meet CRA requirements regardless of where their primary customers are. ▶ Watch: Cyber Resilience Act rationale (12:24)

Kirketerp de Viron also highlighted an underappreciated implementation challenge: the EU is actively working to unify incident reporting across three overlapping regimes — NIS2, GDPR, and sector-specific rules. A company experiencing a major breach should not have to file three separate reports to three separate authorities. A single-report, single-track architecture backed by a shared technology platform is the goal.

Switzerland's Pragmatic Model: Incident Reporting That Actually Works

Florian Schütz offered the perspective of a national cybersecurity center that operates as both a regulator and an operational defender — and that has thought carefully about what regulation can and cannot accomplish.

"Regulation is one of the tools that we have in our policy-making toolbox and we need to use it carefully," Schütz said. ▶ Watch: Regulation as a policy tool (17:22) Switzerland introduced mandatory incident reporting for critical infrastructure on April 1, 2024, after twenty years of voluntary reporting that produced limited results. Critically, the Swiss model draws a sharp distinction: only incidents with operational impact trigger reporting obligations, not mere intrusions or reconnaissance activity. This narrower definition reduces the burden while capturing information that actually improves collective defense.

The Swiss NCSC also built its reporting system with deliberate trust protections. Reported incidents are not automatically forwarded to law enforcement or intelligence services — the NCSC handles them as a confidential national risk assessment function. This design choice encourages honest reporting from organizations that might otherwise stay silent for fear of triggering an investigation or damaging their reputation.

Schütz raised a concern that undercut the entire day's discussion: "Compliance is not equal to security." ▶ Watch: Compliance vs. security (27:18) A heavily regulated company can satisfy every checkbox while remaining fundamentally vulnerable. The goal of regulation, in his framing, is to prevent market failure and maintain fair competition — not to be a substitute for genuine security practice.

The Governance Gap Nobody Wants to Acknowledge

One of the session's sharpest moments came from moderator Tim Maurer, who closed the discussion by naming a structural problem that the panel had danced around for an hour: there is no single annual forum where regulators from different jurisdictions meet to compare notes.

"If you ask ten regulators what is the one place a year where they get together and meet, you will get ten different answers," Maurer said. ▶ Watch: The governance gap (50:44) The fragmentation is not just a symptom of national interest — it is partly a symptom of a missing institutional layer. The OECD Working Party that Schütz chairs is one of the closest things that exists, but it operates on long time horizons and focuses on principles rather than operational convergence.

Wolff pinpointed the emotional dimension of the harmonization problem: when one jurisdiction suggests accepting another's standards, the instinctive response from domestic regulators is often "How dare you suggest we lower the level of our cybersecurity." ▶ Watch: The 'lower the bar' objection (30:49) The same political dynamics that make global trade agreements difficult apply to cybersecurity regulation — with the added complication that national security considerations make transparency even harder.

Notable Quotes

"We go from a regulatory landscape where regulation really isn't shaping operational cyber defense... to a moment where a lot of different sectors are starting to think: we need some kind of cybersecurity standards or requirements."

— Josephine Wolff, Tufts University ▶ 3:42

"Reciprocity would be the most helpful and most realistic situation."

— Ari Schwartz, Venable LLP ▶ 8:11

"Regulation helps to focus the mind. It helps to actually drive investments in cybersecurity."

— Christiane Kirketerp de Viron, European Commission ▶ 12:18

"Regulation is one of the tools that we have in our policy-making toolbox and we need to use it carefully."

— Florian Schütz, Swiss NCSC ▶ 17:22

"Compliance is not equal to security."

— Florian Schütz, Swiss NCSC ▶ 27:18

"There is a governance gap right now where if you ask ten regulators what is the one place a year where they get together and meet, you will get ten different answers."

— Tim Maurer, Microsoft ▶ 50:44

Key Takeaways

  • Regulatory proliferation is now a security problem. Organizations managing shared cloud infrastructure across multiple regulated sectors are drowning in overlapping, contradictory requirements — and compliance with all of them does not guarantee better security outcomes.
  • Reciprocity, not harmonization, is the realistic path. Industry groups do not expect a single global standard; they want jurisdictions to accept each other's certifications with minimal supplementary requirements.
  • Five areas need urgent coordination: critical infrastructure certifications, post-quantum cryptography standards, IoT device security, incident reporting formats, and secure software development practices.
  • Europe's CRA will have global reach through the Brussels effect: vendors selling into the EU will need to build secure-by-design products that meet CRA requirements, regardless of where their primary market lies.
  • The Swiss model offers a workable incident reporting template: narrow scope (operational impact only), confidential handling, no automatic law enforcement referral, and a digital platform for ease of submission.
  • A governance gap exists at the international level. No single forum convenes regulators from major jurisdictions annually. Closing that gap — perhaps through the OECD Working Party on Digital Security — may be the most important structural reform available.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured panel on regulatory fragmentation that actually produces a prioritized list of coordination targets rather than dissolving into 'more cooperation is good' platitudes. The Swiss incident reporting model is the most operationally instructive content here. Schütz saying 'compliance is not equal to security' from inside the regulatory system is worth more than a thousand CISO conference talks saying the same thing.

Heather Calloway (CISO) — STRONG ACCEPT

Panel on cyber regulatory fragmentation: organizations are navigating 100+ overlapping regulations across HIPAA, PCI, SOX, DORA, NIS2, NIST frameworks, and sector-specific requirements, with compliance pulling security talent off security work. The case for regulatory consolidation is made with specificity.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025