Pith. sign in

REVIEW 2 major objections 5 minor 1 cited by

Risks and Compliance with the EU's Core Cyber Security Legislation

T0 review · 2 major / 5 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read Across the CSA, GDPR, CRA, CER, and NIS2, the EU's core cyber security laws all frame risk as probability times impact and cover technical, organizational, human, and national security — but none acknowledges acceptable, residual, or non-pr

desk verdict Useful map of how five EU cyber laws frame risk; trust the positive taxonomy, treat the absence claims as hypotheses until a full-text check. read the letter →

arxiv 2508.21386 v1 pith:7ZSVET63 submitted 2025-08-29 cs.CR cs.CYcs.SE

classification cs.CRcs.CYcs.SE
keywords EUcybersecuritylegislationrisk-basedregulationriskframinglegaltaxonomycomplianceNIS2ResilienceActGDPR
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Five EU cyber security laws are supposed to be risk-based, but how exactly do they define risk? The paper claims that the CSA, GDPR, CRA, CER, and NIS2 all frame risk through the same conventional formula — probability of occurrence times impact — and that together they cover technical, organizational, human, and national security concerns thoroughly. The paper's central finding is a shared blind spot: none of the five acts acknowledges acceptable risks, residual risks (what remains after countermeasures), or non-probabilistic risk concepts. If correct, this means compliance officers can rely on probability/impact risk matrices as a common substrate across all five laws, but they will find no legal guidance on when residual risk is tolerable, and the regime's risk concept has no way to express safety-style threshold risks. The paper supports these claims with a six-dimension taxonomy built by qualitative legal interpretation of selected provisions.

What carries the argument

The paper's carrying object is a six-dimension taxonomy of risk framings, built from the conventional risk-analysis vocabulary: the formula 'risk = probability of occurrence of a threat × impact of a threat', and the paired definitions of acceptable risk (a risk understood and tolerated by a system's user, operator, owner, or accreditor) and residual risk (the portion of an original risk that remains after countermeasures have been applied). The taxonomy's six dimensions — viewpoint, man-made versus other origins, probabilistic versus non-probabilistic, acceptable/residual recognition, security concept, and development versus operations — do the analytical work: each act is mapped onto the c

What would settle it

Search the full text of the five acts and their recitals for 'residual risk', 'acceptable risk', 'risk tolerance', 'risk appetite', or equivalent formulations in EU languages; a single provision instructing that a risk analysis document what risk remains after mitigation, or setting a tolerable risk threshold, falsifies the claimed gap. Separately, the all-probabilistic claim falls if any act defines or uses risk without reference to likelihood — for instance, a threshold- or impact-only definition such as the CER's 'significant disruptive effect' criteria applied without probability, or a saf

Watch

Extended reading notes

Core claim

On the paper's own terms, the central claim is that the EU's five core cyber security acts form a convergent, risk-based regulatory regime with specific missing pieces. Interpreting each act against six taxonomy dimensions — risk viewpoint (threat-, asset-, or system-centric), man-made versus other risks, probabilistic versus non-probabilistic framing, recognition of acceptable/residual risks, security concept (technical, organizational, human, national), and development versus operations — the paper finds that all five laws share the conventional probabilistic understanding of risk, that their coverage spans all four security concepts, and that three risk notions are absent everywhere: acce

Load-bearing premise

The gap findings (no acceptable, residual, or non-probabilistic risks anywhere) rest on the authors' selective reading of only 'notable risk-based aspects' of each act; if a provision they did not single out, or an interpretation via recitals, case law, or contextual reading (all excluded), acknowledges these concepts, the claimed gaps would be artifacts of the selection.

Editorial extensions

If this is right

  • Probability/impact risk matrices are a defensible common method across all five acts, since each law operates with the same probabilistic risk formula.
  • Organizations covered by several acts (e.g., a networked product processing personal data for a critical-sector customer) can legally consolidate overlapping obligations into a single risk analysis spanning the GDPR, CRA, CER, and NIS2.
  • Because no act recognizes acceptable or residual risk, nothing in the legislation itself says how much risk may remain after countermeasures; this will be settled by enforcement, standards, and future delegated acts.
  • The paper's taxonomy is explicitly provisional: new implementing and delegated acts may shift where each law maps, so the convergence-and-gap picture should be revisited as the regime develops.
  • The shared gaps count as a form of convergence: the five acts collectively decline to legislate non-probabilistic, acceptable, and residual risks, which is itself a structural feature of the regime.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A full-text, corpus-level search of the five acts and their recitals for residual-risk and acceptable-risk vocabulary (including equivalents in other EU languages) would test whether the paper's qualitative absence findings hold at scale; its method deliberately reads only 'notable' provisions, so a systematic scan could either confirm the gaps or reveal mentions the selection missed.
  • If the gaps are real, a small regulatory fix suggests itself: an implementing or delegated act under the CRA or NIS2 could require documenting residual risk after applying the essential security requirements, filling the gap without new primary legislation.
  • The paper's reading of the CSA's attacker-skill tiers as an implicit residual-risk scale suggests a bridge between certification assurance levels and the CRA's essential requirements that the paper does not itself build: an assurance level could serve as a rough measure of how much residual risk remains for a certified product.
  • Applying the same six-dimension taxonomy to neighbouring acts (DORA, the Digital Services Act, the AI Act), which the paper names only as overlaps, would show whether the convergent probabilistic risk concept extends beyond the five core acts into sectoral and technology-specific legislation.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The paper interprets the risk concepts in five EU cyber security legislative acts (CSA, GDPR, CRA, CER, NIS2) using a six-dimensional taxonomy derived from risk-management literature. It reports that the acts converge on a probabilistic, asset/system-centric framing of risk, cover technical, organizational, human, and national security to varying degrees, and contain two notable gaps: acceptable/residual risks and non-probabilistic risks. It also analyzes qualifying words that tighten or relax legal obligations and concludes with practical compliance recommendations. The main evidence is a qualitative reading of selected articles, summarized in Table 2.

Significance. If the results are correct, the paper provides a useful mapping for requirements and compliance engineering and contributes to the literature on risk-based regulation in the EU. Its positive classifications are often grounded in quoted provisions, and the authors are transparent about the qualitative, selective nature of the analysis. However, the paper's most novel negative findings — the absence of acceptable/residual risks and of non-probabilistic risks — are not supported by the corpus actually analyzed. This is a correctable but currently load-bearing weakness.

major comments (2)
  1. [Section 3 / Table 2 / Section 4.1] The negative claims in Table 2 (Dimensions 3b and 4a) and Section 4.1 ('none of the laws mention or otherwise discuss explicitly'; 'All laws rely on the conventional probabilistic understanding') assert absence across entire legal instruments. However, the analysis is explicitly selective: Section 3 states that only 'notable risk-based aspects' are considered and 'not everything about the laws is covered'; Section 2.2 excludes contextual interpretation and case law; footnote 3 lists further excluded risk-based details. Because no full-text search for 'acceptable risk', 'residual risk', 'remaining risk', or 'non-probabilistic risk' equivalents is reported, the P=0 entries may be artifacts of the selection. This is load-bearing because the abstract and conclusion present these gaps as the main novel finding. The authors should either perform a systematic corpus check (at least for English
  2. [Section 2.2.3 / Table 2] The convergence result is partly an artifact of the coding design. The six taxonomy dimensions are imported from the risk-management literature, the categories are coarse, and each law is allowed to map to multiple categories in dimensions (1), (5), and (6). The check-mark table therefore summarizes the authors' classifications, but the table alone does not let a reader verify each cell. I recommend a supplementary table with representative quotations per cell, or an explicit caveat that the convergence claim is descriptive of the authors' interpretive mapping rather than an independent property of the legal texts. This would align the strength of the claim with the evidence.
minor comments (5)
  1. [Section 3.3.3] Typo: 'ENISA will nothing other national authoritative CSIRTs' should read 'ENISA will notify other national authoritative CSIRTs'.
  2. [References] Reference [71] gives the year as '201'; this should be '2021'.
  3. [Figure 1] The figure contains the misspelling 'inreases'; it should be 'increases'.
  4. [Section 3.4.2 / Table 2] Article 13(1) CER explicitly requires 'technical, security and organisational measures', yet Table 2 does not mark CER under 'Technical security' (5a). If the coding criterion is the presence of concrete technical requirements rather than the mere mention of technical measures, this should be stated in Section 2.2.1 and applied consistently; otherwise the table conflicts with the text.
  5. [Section 3.5.1] Minor grammar issue: 'the NIS2 directive have already involved' should be 'the NIS2 directive has already involved'.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity; the taxonomy is an interpretive classification of primary legal texts, and self-citations are ancillary rather than load-bearing.

full rationale

The paper's central claims are qualitative classifications of EU legal provisions against a six-dimension taxonomy adapted from risk-management literature. The convergence claim ('All laws rely on the conventional probabilistic understanding'; 'the five acts have an encompassing coverage') is a summary of Table 2, which is constructed from quoted provisions and the authors' interpretations. This is not a derivation that reduces to its inputs: the dimensions come from external literature, the mappings are grounded in specific articles/recitals, and the authors explicitly allow overlaps. No fitted parameters are renamed as predictions, no uniqueness theorem is imported, and no central claim is defined in terms of itself. Self-citations are present ([56], [58], [60], [61]) and [58] is used when asserting that residual/acceptable risks remain unacknowledged in the CRA. However, this citation supports a qualitative interpretive conclusion that the paper also reaches through its own analysis of CRA Articles 3, 13, 14–20, 54, and 56; it is not the sole or formal basis for the claim. The paper is self-contained against the primary legal texts, and the taxonomy could in principle have revealed different mappings or gaps. The main weakness is not circularity but an evidentiary/scope mismatch: Section 3 states 'only considering notable risk-based aspects... not everything about the laws is covered', and Section 2.2 excludes contextual interpretation and case law. Yet Section 4.1 claims that acceptable/residual and non-probabilistic risks are aspects 'none of the laws mention or otherwise discuss explicitly'. Negative gap claims are broader than the deliberately selective sample and could be artifacts of selection. This is a correctness risk, not a circular reduction: the absence is not forced by the taxonomy's definitions or by a self-citation chain. For that reason, the circularity score is low.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The paper introduces no new entities or numeric free parameters. Its central claims rest on four interpretive premises: the probabilistic risk definition used as a benchmark, the choice of six dimensions, the flexible notion of 'asset', and the adequacy of a selectively read, context-free legal interpretation. These are all acknowledged in the paper but are nonetheless load-bearing.

assumptions (4)
  • domain assumption The conventional probabilistic definition of risk (probability of a threat times impact) is the reference standard for determining whether a law's risk concept is probabilistic.
    Introduced in Section 2.2.1 (citing [11,13,64,76]) and used to classify each law; the paper explicitly treats non-probabilistic risk as the antonym, so this definition drives the 'probabilistic' column in Table 2.
  • ad hoc to paper The six taxonomy dimensions and their categories are sufficient to capture the relevant differences between the laws.
    Section 2.2 states only six dimensions are considered 'to minimize redundancy and to ensure feasibility (B8)'; the choice is a design decision, not derived from the laws. It shapes the convergence conclusion.
  • ad hoc to paper The asset concept can be stretched to include natural persons, the EU internal market, and critical infrastructures.
    Section 2.2.1 acknowledges 'the concept of asset is problematic and requires flexibility in interpretation' and uses it to maintain coherence with the risk-management literature. This flexibility is necessary for the asset-centric mappings in Table 2.
  • domain assumption The analysis of selected provisions without contextual interpretation or case law is adequate to answer the research questions.
    Section 2.2 explicitly excludes contextual interpretation and case law ('Thus, a contextual interpretation, including case law, is excluded.'). This is a background methodological assumption for qualitative legal interpretation.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Risks and Compliance with the EU's Core Cyber Security Legislation." pith.science (2026). https://pith.science/paper/7ZSVET63

@misc{pith2026250821386,
  author       = {Pith},
  title        = {Pith review of: Risks and Compliance with the EU's Core Cyber Security Legislation},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/7ZSVET63}},
  note         = {Machine review of arXiv:2508.21386}
}
read the original abstract

The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal interpretation and taxonomy-building. Results: The five acts have an encompassing coverage of different cyber security risks, including but not limited to risks related to technical, organizational, and human security as well as those not originating from man-made actions. Both technical aspects and assets are used to frame the legal risk notions in many of the legislative acts. A threat-centric viewpoint is also present in one of the acts. Notable gaps are related to acceptable risks, non-probabilistic risks, and residual risks. Conclusion: The EU's new cyber security legislation has significantly extended the risk-based approach to regulations. At the same time, complexity and compliance burden have increased. With this point in mind, the paper concludes with a few practical takeaways about means to deal with compliance and research it.

Figures

Figures reproduced from arXiv: 2508.21386 by the authors.

Figure 1
Figure 1. The Risk and Requirements Engineering Concepts Used [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Risks and Legal Semantics As also seen from Figs. 1 and 2, the qualifying words are interpreted to either tighten or relax a legal require￾ment for a cyber security countermeasure. As such, the constraints or unconstraints emerging from these contex￾tualized semantics are weaker and usually vaguer than ex￾plicit exemptions or other provisions often embedded to laws. Thus, a so-called keyword trap [9] should be kept … view at source ↗
Figure 3
Figure 3. A Fairly Conventional Elaboration of Resilience [PITH_FULL_IMAGE:figures/full_fig_p009_3.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Rapid Review Regarding the Concept of Legal Requirements in Requirements Engineering

    cs.SE 2025-09 conditional novelty 4.0 of 10

    A rapid review finds that requirements engineering research lacks a shared definition of legal requirements and that common claims about them are not backed by empirical evidence.

Reference graph

Works this paper leans on

78 extracted references · 78 canonical work pages · cited by 1 Pith paper

  1. [1]

    M., Woody, C., Bandor, M., and Merendino, T

    Alberts, C., Wallen, C. M., Woody, C., Bandor, M., and Merendino, T. (2023). Security Engineering Frame- work (SEF): Managing Security and Resilience Risks Across the Systems Lifecycle. CMU/SEI-2024-SR-022, Carnegie Mel- lon University, Software Engineering Institute (SEI), avail- able online in July: https://www.sei.cmu.edu/documents/6121/ security-engin...

  2. [2]

    and Petit, N

    Almada, M. and Petit, N. (2025). The EU AI Act: Between the Rock of Product Safety and the Hard Place of Fundamental Rights. Common Market Law Review, 62:85–120

  3. [3]

    and Moore, T

    Anderson, R. and Moore, T. (2009). Information Security: Where Computer Science, Economics and Psychology Meet. Philosophical Transactions of the Royal Society A: Mathemati- cal, Physical and Engineering Sciences, 367:2717–2727

  4. [4]

    Backman, S. (2023). Risk vs. Threat-Based Cybersecurity: The Case of the EU. European Security, 32(1):85–103

  5. [5]

    and Knoll, A

    Bernhard, J. and Knoll, A. (2021). Risk-Constrained Interac- tive Safety Under Behavior Uncertainty for Autonomous Driving. In Proceedings of the IEEE Intelligent Vehicles Symposium (IV 2021), pages 63–70, Nagoya

  6. [6]

    and Chishman, R

    Bertoldi, A. and Chishman, R. (2007). Improving Legal On- tologies Through Semantic Representation of Adjectives. In Pro- ceedings of the International Conference on Semantic Computing (ICSC 2007), pages 767–774, Irvine. IEEE

  7. [7]

    Bygrave, L. A. (2017). Data Protection by Design and by Default: Deciphering the EU’s Legislative Requirements. Oslo Law Review, 4(2):105–120

  8. [8]

    E., Greitzer, F

    Carroll, T. E., Greitzer, F. L., and Roberts, A. D. (2014). Security Informatics Research Challenges for Mitigating Cyber Friendly Fire. Security Informatics, 13:1–14

Show all 78 references
  1. [9]

    and Larouche, P

    Chirico, F. and Larouche, P. (2013). Convergence and Diver- gence, in Law and Economics and Comparative Law. In Larouche, P. and Cserne, P., editors, National Legal Systems and Globaliza- tion: New Role, Continuing Relevance, pages 9–33. Asser Press, Berlin

  2. [10]

    Chockalingam, S., Nystad, E., and Esnoul, C. (2023). Capa- bility Maturity Models for Targeted Cyber Security Training. In Proceedings of the 5th International Conference on HCI for Cy- bersecurity, Privacy and Trust (HCI-CPT 2023), pages 576–590, Copenhagen. Springer

  3. [11]

    and Daniel, E

    Crotty, J. and Daniel, E. (2022). Cyber Threat: Its Origins and Consequence and the Use of Qualitative and Quantitative Methods in Cyber Risk Assessment. Applied Computing and In- formatics, pages 1–12

  4. [12]

    H., and Pieters, W

    de Bruijne, M., van Eeten, M., Ga˜ n´ an, C. H., and Pieters, W. (2017). Towards a New Cyber Threat Ac- tor Typology: A Hybrid Method for the NCSC Cyber Security Assessment. TU Delft, available online in July 2025: https://repository.wodc.nl/bitstream/handle/20.500. 12832/2299...

  5. [13]

    Interoperable EU Risk Management Toolbox

    ENISA (2023). Interoperable EU Risk Management Toolbox. The European Union Agency for Cyberse- curity (ENISA), available online in July 2025: https: //www.enisa.europa.eu/sites/default/files/publications/ Interoperable%20EU%20RM%20Toolbox.pdf

  6. [14]

    Best Practices for Cyber Crisis Management

    ENISA (2024). Best Practices for Cyber Crisis Management. The European Union Agency for Cybersecurity (ENISA), avail- able online in January 2025: https://enisa.europa.eu/sites/ default/files/2024-11/ENISA%20Study%20Best%20Practices% 20Cyber%20Crisis%20Management.pdf

  7. [15]

    European Union Vulnerability Database

    ENISA (2025). European Union Vulnerability Database. The European Union Agency for Cybersecurity (ENISA). Available online in March 2025: https://euvd.enisa.europa.eu/

  8. [16]

    EU (2008). Decision No 768/2008/EC of the European Parlia- ment and of the Council of 9 July 2008 on a Common Framework for the Marketing of Products, and Repealing Council Decision 93/465/EEC (Text With EEA Relevance). The European Union (EU), available online in July 2025: h...

  9. [17]

    Charter of Fundamental Rights of the Eu- ropean Union

    EU (2016a). Charter of Fundamental Rights of the Eu- ropean Union. The European Union, available online in July 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/ ?uri=celex%3A12016P%2FTXT

  10. [18]

    EU (2016b). Consolidated Text: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons With Regard to the Process- ing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC ...

  11. [19]

    EU (2019). Regulation (EU) 2019/881 of the European Par- liament and of the Council of 17 April 2019 on ENISA (the Eu- ropean Union Agency for Cybersecurity) and on Information and Communications Technology Cybersecurity Certification and Re- pealing Regulation (EU) No 526/201...

  12. [20]

    EU (2022a). Directive (EU) 2022/2555 of the European Parlia- ment and of the Council of 14 December 2022 on Measures for a High Common Level of Cybersecurity Across the Union, Amend- ing Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and Repealing Directive (EU) 201...

  13. [21]

    EU (2022b). Directive (EU) 2022/2557 of the European Parlia- ment and of the Council of 14 December 2022 on the Resilience of Critical Entities and Repealing Council Directive 2008/114/EC (Text With EEA Relevance). The European Union (EU), avail- able online in March 2025: htt...

  14. [22]

    EU (2022c). Regulation (EU) 2022/2065 of the European Par- liament and of the Council of 19 October 2022 on a Single Market for Digital Services and Amending Directive 2000/31/ec (Digital Services Act) (Text With EEA Relevance). The European Union (EU), available online in Mar...

  15. [23]

    EU (2022d). Regulation (EU) 2022/2554 of the European Par- liament and of the Council of 14 December 2022 on Digital Oper- ational Resilience for the Financial Sector and Amending Regula- tions (EC) no 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 20...

  16. [24]

    EU (2024). Regulation (EU) 2024/2847 of the European Parlia- ment and of the Council of 23 October 2024 on Horizontal Cyber- security Requirements for Products With Digital Elements and Amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cybe...

  17. [25]

    Faisal, K. (2023). Applying the Purpose Limitation Principle in Smart-City Data-Processing Practices: A European Data Protec- tion Law Perspective. Communication Law and Policy, 28(1):67– 97

  18. [26]

    Fridgen, G., Klier, J., Beer, M., and Wolf, T. (2014). Im- proving Business Value Assurance in Large-Scale IT Projects— A Quantitative Method Based on Founded Requirements Assess- ment. ACM Transactions on Management Information Systems, 5(3):1–17

  19. [27]

    Gellert, R. (2016). We Have Always Managed Risks in Data Protection Law: Understanding the Similarities and Differ- ences Between the Rights-Based and the Risk-Based Approaches to Data Protection. European Data Protection Law Review, 2(4):481–492

  20. [28]

    Guerra, G. (2018). An Interdisciplinary Approach for Compar- ative Lawyers: Insights from the Fast-Moving Field of Law and Technology. German Law Journal, 19(3):579–612

  21. [29]

    Haelterman, H. (2022). Breaking Silos of Legal and Regulatory Risks to Outperform Traditional Compliance Approaches. Euro- pean Journal on Criminal Policy and Research, 28:19–36

  22. [30]

    B., Moffett, J

    Haley, C. B., Moffett, J. D., Laney, R., and Nuseibeh, B. (2006). A Framework for Security Requirements Engineering. In Proceed- ings of the International Workshop on Software Engineering for Secure Systems (SESS 2006), pages 35–42, Shanghai. ACM

  23. [31]

    Hall´ e, S. (2024). Column: Is Theory (Still) Welcome in Software Engineering Research? ACM SIGSOFT Software Engineering Notes, 49(2):19–21

  24. [32]

    Hanif, H., Constantino, J., Sekwenz, M.-T., van Eeten, M., Ubacht, J., Wagner, B., and Zhauniarovich, Y. (2024). Navigat- ing the EU AI Act Maze Using a Decision-Tree Approach. ACM Journal on Responsible Computing, 1(3):1–16

  25. [33]

    Hildebrandt, M. (2020). Law for Computer Scientists and Other Folk. Oxford University Press, Oxford

  26. [34]

    Hildebrandt, M. (2024). The Future of Computational Law in the Context of the Rule of Law. Journal of Cross-Disciplinary Research in Computational Law, 2(2):1–11

  27. [35]

    B., and Glinz, M

    Hotomski, S., Charrada, E. B., and Glinz, M. (2016). An Ex- ploratory Study on Handling Requirements and Acceptance Test Documentation in Industry. In Proceedings of the IEEE 24th International Requirements Engineering Conference (RE 2016), pages 116–125, Beijing. IEEE

  28. [36]

    M., Liebel, G., de Souza Santos, R., and Baltes, S

    Hyrynsalmi, S. M., Liebel, G., de Souza Santos, R., and Baltes, S. (2025). Not Real or too Soft? On the Challenges of Publishing Interdisciplinary Software Engineering Research. InProceedings of the IEEE/ACM 47th International Conference on Software En- gineering: Software Eng...

  29. [37]

    Jasmontaite, L., Kamara, I., Zanfir-Fortuna, G., and Leucci, S. (2018). Data Protection by Design and by Default: Framing Guiding Principles into Legal Obligations in the GDPR. European Data Protection Law Review, 4:168–189

  30. [38]

    and Farhadi, S

    Kalatpour, O. and Farhadi, S. (2017). The Content Analysis of Emergency Scenarios: Thematic Survey of the Context in the Process Industries. Safety Science, 92:257–261

  31. [39]

    V., and Tanas, A

    Kloza, D., Van Dijk, N., Casiraghi, S., Maymir, S. V., and Tanas, A. (2021). The Concept of Impact Assessment. In Burgess, J. P. and Kloza, D., editors, Border Control and New Technolo- gies: Addressing Integrated Impact Assessment, pages 31–48. ASP Academic and Scientific Pub...

  32. [40]

    Kosenkov, O., Elahidoost, P., Gorschek, T., Fischbach, J., Mendez, D., Unterkalmsteiner, M., Fucci, D., and Mohanani, R. (2025). Systematic Mapping Study on Requirements Engineering for Regulatory Compliance of Software Systems. Information and Software Technology, 178:107622

  33. [41]

    Labaka, L., Hernantes, J., and Sarriegi, J. M. (2016). A Holistic Framework for Building Critical Infrastructure Resilience. Tech- nological Forecasting & Social Change, 103:21–33

  34. [42]

    S., Werner, C., Ernst, N., and Damian, D

    Li, Z. S., Werner, C., Ernst, N., and Damian, D. (2022). To- wards Privacy Compliance: A Design Science Study in a Small Organization. Information and Software Technology, 146:106868

  35. [43]

    and Dhirani, L

    Meagher, H. and Dhirani, L. L. (2024). Cyber-Resilience, Prin- ciples, and Practices. In Qureshi, K. N., Newe, T., Jeon, G., and Chehri, A., editors, Cybersecurity Vigilance and Security Engi- neering of Internet of Everything, pages 57–74. Springer, Cham

  36. [44]

    Mendes, J. P. (2023). Model-Based Risk Analysis for System Design. Systems Engineering, 27(1):5–20

  37. [45]

    Michalec, O., Milyaeva, S., and Rashid, A. (2022). When the Future Meets the Past: Can Safety and Cyber Security Coexist in Modern Critical Infrastructures? Big Data & Society, 9(1):1–13

  38. [46]

    and Ranise, S

    Mollaeefar, M. and Ranise, S. (2023). Identifying and Quantify- ing Trade-Offs in Multi-Stakeholder Risk Evaluation With Appli- cations to the Data Protection Impact Assessment of the GDPR. Computers & Security, 129:103206

  39. [47]

    Onos´ e, C. (2020). Designing for Consumer Trust in a Data- Powered World. IEEE Consumer Electronics Magazine, 9(2):89– 93

  40. [48]

    Purnhagen, K. (2003). The Politics of Systemization in EU Product Safety Regulation: Market, States, Collectivity, and In- tegration. Springer, Dordrecht

  41. [49]

    K., Coyle, P., and Cohen, R

    Rabitti, G., Chokami, A. K., Coyle, P., and Cohen, R. D. (2024). A Taxonomy of Cyber Risk Taxonomies.Risk Analysis, 45(2):376– 386

  42. [50]

    Ralph, P. (2019). Toward Methodological Guidelines for Pro- cess Theories and Taxonomies in Software Engineering. IEEE Transactions on Software Engineering, 45(7):712–735

  43. [51]

    S., Calvo-Manzano, J., and Sanchez- Garcia, I

    Rea-Guaman, A., Feliu, T. S., Calvo-Manzano, J., and Sanchez- Garcia, I. (2017). Systematic Review: Cybersecurity Risk Taxon- omy. In Proceedings of the 6th International Conference on Soft- ware Process Improvement (CIMPS 2017), pages 137–146, Za- catecas. Springer

  44. [52]

    and Malgieri, G

    Rebrean, M.-L. and Malgieri, G. (2025). Vulnerability in the EU AI Act: Building an Interpretation. In Proceedings of the 2025 ACM Conference on Fairness, Accountability, and Transparency (F AccT 2025), pages 1985–1997, Athens. ACM

  45. [53]

    Ruan, K. (2017). Introducing Cybernomics: A Unifying Eco- nomic Framework for Measuring Cyber Risk. Computers & Secu- rity, 65:77–89

  46. [54]

    Ruohonen, J. (2022). A Review of Product Safety Regulations in the European Union. International Cybersecurity Law Review, 3:345–366

  47. [55]

    Ruohonen, J. (2025). (Forthcoming) An Empirical Analysis of Policy Consultations on the European Union’s Cyber Security Laws. In Amoretti, F., Busetti, S., Righettini, M. S., and Vecchi, G., editors, Cybersecurity Policy in the European Union. Palgrave Macmillan, Cham

  48. [56]

    Ruohonen, J., Hjerppe, K., and Kang, E.-Y. (2025a). A Map- ping Analysis of Requirements Between the CRA and the GDPR. In (Forthcoming) Proceedings of the IEEE 33rd International Re- quirements Engineering Conference Workshops (REW 2025), Va- lencia. IEEE

  49. [57]

    Ruohonen, J., Hjerppe, K., and von Zastrow, M. (2024). An Ex- ploratory Case Study on Data Breach Journalism. In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES 2024), pages 1–9, Vienna. ACM

  50. [58]

    Ruohonen, J., Kang, E.-Y., and Ramadan, Q. (2025b). An Alignment Between the CRA’s Essential Requirements and the ATT&CK®’s Mitigations. In (Forthcoming) Proceedings of the IEEE 33rd International Requirements Engineering Conference Workshops (REW 2025), Valencia. IEEE

  51. [59]

    and Mickelsson, S

    Ruohonen, J. and Mickelsson, S. (2023). Reflections on the Data Governance Act. Digital Society, 2:1–10

  52. [60]

    Ruohonen, J., Rindell, K., and Busetti, S. (2025c). From Cy- ber Security Incident Management to Cyber Security Crisis Man- agement in the European Union. Archived manuscript, available online: https://doi.org/10.48550/arXiv.2504.14220

  53. [61]

    and Timmers, P

    Ruohonen, J. and Timmers, P. (2025). Vulnerability Coordi- nation Under the Cyber Resilience Act. Archived manuscript, available online: https://doi.org/10.48550/arXiv.2412.06261

  54. [62]

    Ryan, I., Roedig, U., and Stol, K.-J. (2023). Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the Moon. In Proceedings of the IEEE/ACM 45th Interna- tional Conference on Software Engineering (ICSE 2023), pages 1622–1634, Melbourne. IEEE. 13

  55. [63]

    Sarmah, T., Ghosh, K., Chatterjee, R., and Shaw, R. (2024). History of Risk Management Approach. In Izumi, T., Abe, M., Fujita, K., and Shaw, R., editors,All-Hazards Approach: Towards Resilience Building, pages 29–41. Springer, Singapore

  56. [64]

    Shirey, R. W. (2007). Internet Security Glossary, Version

  57. [65]

    Request for Comments (RFC) 4949, the Internet Engineer- ing Task Force (IETF), available online in July 2025: https: //datatracker.ietf.org/doc/html/rfc4949

  58. [66]

    Sibony, A.-L. (2017). Returning to Risk Regulation After a Long Journey. European Journal of Risk Regulation, 8(1):112–114

  59. [67]

    and Kocarev, L

    Sokolovska, A. and Kocarev, L. (2018). Integrating Technical and Legal Concepts of Privacy. IEEE Access, 6:26543–26557

  60. [68]

    Solove, D. J. (2002). Conceptualizing Privacy. California Law Review, 90(4):1087–1155

  61. [69]

    Suslov, T. (2025). Rethinking Security: The Human Side of Risk Management. Palgrave Macmillan, Cham

  62. [70]

    Tatam, M., Shanmugam, B., Azam, S., and Kannoorpatti, K. (2021). A Review of Threat Modelling Approaches for APT-Style Attacks. Heliyon, 7(1):e05969

  63. [71]

    Usman, M., Britto, R., B¨ orstler, J., and Mendes, E. (2017). Tax- onomies in Software Engineering: A Systematic Mapping Study and a Revised Taxonomy Development Method. Information and Software Technology, 85:43–59

  64. [72]

    van der Heijden, J. (201). Risk as an Approach to Regulatory Governance: An Evidence Synthesis and Research Agenda. SAGE Open, 11(3):1–12

  65. [73]

    Vielberth, M., Siepmann, R., Glas, M., and Pernul, G. (2025). Securing the Road Ahead: Supporting Decision Making in Auto- motive Cybersecurity Risk Treatment. In Proceedings of the 20th International Conference on Availability, Reliability and Security (ARES 2025), pages 269–...

  66. [74]

    and Disparte, D

    Wagner, D. and Disparte, D. (2016). Global Risk Agility and Decision Making: Organizational Resilience in the Era of Man- Made Risk. Palgrave Macmillan, London

  67. [75]

    H., Fritsch, L., and Lindskog, S

    Wairmu, S., Iwaya, L. H., Fritsch, L., and Lindskog, S. (2024). On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review. IEEE Access, 12:19625–19650

  68. [76]

    Walley, P. (1991). Statistical Reasoning With Imprecise Proba- bilities. Chapman and Hall, London

  69. [77]

    Waqdan, M., Louafi, H., and Mouhoub, M. (2025). Security Risk Assessment in IoT Environments: A Taxonomy and Survey. Computers & Security, 154:10446

  70. [78]

    Woods, D. W. and B¨ ohme, R. (2016). SoK: Quantifying Cyber Risk. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), pages 211–228, San Francisco. IEEE. 14

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.