July 24, 2026
July 24, 2026
Dale Peterson argues that Europe has taken the lead over the United States in OT security regulation through the Cyber Resilience Act and the NIS2 Directive. He says these rules will affect vendors, integrators and asset owners active in the EU, but cautions that the field is still new, evolving and unevenly interpreted across countries. Because requirements and compliance expectations are still developing, Peterson says only specialists deeply engaged with CRA and NIS2 should give detailed compliance advice.
The article compares the current European situation with the early years of NERC CIP in North America. Peterson’s main warning is that regulatory risk can overtake actual OT cyber risk: organisations may abandon sensible security plans and spend only on what is required for compliance, even if other measures would reduce risk more effectively. He notes that NERC CIP did raise the cybersecurity floor for lagging utilities, but in an inefficient way that slowed broader progress, and he hopes Europe’s CRA and NIS2 experience will avoid repeating that pattern.
Source: Dale Peterson