3. Digitally secure hardware and software As a result of the introduction and continuous development of the Internet of Things, more and more devices are connected to the internet. Some 20.4 billion devices are expected to be connected in 2020. At least 63% of them will be consumer devices.4 The remaining 37% are devices used by businesses and for which the impact in case of disruption or misuse (on businesses’ own processes, but also further along the chain) is potentially much greater than in case of private use. It is important that everyone is able to use these products with confidence in a digitally secure manner, not only for their own digital security, but for that of society as a whole. Malicious parties can easily gain access through vulnerabilities in hardware and software in a device, and through this device to the network it is part of. Users and providers of digital products often do not or barely consider the potential harmful effects of their actions on others. This can have serious consequences, such as the misuse of the device for DDoS attacks, manipulation of the device or the theft of stored information. Digital security of hardware and software is not ensured by default. Hardware and software providers do not always resolve the security risks that are associated with their processes and production. Users have hardly any means of making a reliable assessment of the digital security level of a device that is connected to the internet - and even if they do have the knowledge, it is still difficult to make an assessment. For instance, it is difficult for users to assess the long-term impact of their decisions. Very often, specialist knowledge is needed to fully understand the digital security of a device. Users therefore need to be empowered. This is done by providing instruments, aimed at the behaviour of users, to make an estimation of the digital security of hardware and software. Research into the effectiveness of information campaigns on secure user behaviour plays an important role in this regard. OBJECTIVES A cohesive set of measures is needed to encourage and enhance the digital security of hardware and software in a balanced way, and for which various parties have a responsibility. This why the Netherlands will implement and further develop the Roadmap for Digitally Secure Hardware and Software (Roadmap Digitaal Veilige Harden Software).5 The following objectives apply here: • The Netherlands will encourage standardisation and certification initiatives and by strengthening supervision and enforcement, in order to prevent digital security risks in hardware and software. • The Netherlands will work to improve the detection of digital security risks by testing digital products and making the digital security risks clear. • The Netherlands will work on mitigating of digital security risks through a liability regime, and by increasing awareness and by offering a perspective for action for citizens and businesses. • The Netherlands will strive to for the realisation of a set of basic principles to foster the digital security of hardware and software. MEASURES o Standards and certification make an important contribution to the digital security of hardware and software. o In the negotiations in Brussels, the Netherlands will advocate the quick adoption of the Cyber Security Act (CSA), and the expeditious development of a European framework for security certification for ICT 4 https://www.gartner.com/newsroom/id/3598917. 5 Roadmap Digitaal Veilige Hard- en Software [Roadmap for Digitally Secure Hardware and Software Roadmap], Ministry of Economic Affairs and Climate Policy, 2018. A cyber secure Netherlands National Cyber Security Agenda | 27

Select target paragraph3