European Smart Device Laws Fail to Address Ecosystem-Wide Cyber Risks, Scholar Warns
Legal researcher Mattis van 't Schip calls for regulatory reforms targeting software supply chains and cloud ecosystems rather than isolated smart hardware.

European regulatory frameworks governing connected technology remain fundamentally flawed due to a narrow focus on individual hardware products rather than broader digital ecosystems, according to research by legal scholar Mattis van 't Schip, as first reported by TechXplore. Ahead of his Ph.D. defense scheduled for Sept. 16 at Radboud University, van 't Schip is urging policymakers to overhaul technology legislation to address the complex networks of component suppliers, cloud services, and software layers that support modern internet-connected devices.
The deployment of connected hardware spans consumer items like internet-enabled vacuum cleaners and video doorbells to critical operational systems such as medical equipment in hospitals. Each physical device relies on microchips manufactured by multiple vendors, while its software architecture runs on stacked code produced by a wide variety of developers, ranging from multinational technology corporations to individual open-source contributors.
Existing legal standards fail to mitigate systemic digital risks because they treat products in isolation. "It still often focuses on individual products, but we need to tackle the entire ecosystem at once," van 't Schip noted, emphasizing that legislative oversight must encompass the broader environment of sensors, vendors, and cloud platforms. Drawing an environmental analogy, he explained that attempting to solve cybersecurity through isolated product rules is equivalent to managing a nature reserve's nitrogen levels by focusing strictly on individual trees.
Neglecting these broad interdependencies leaves organizational networks vulnerable to attacks through indirect entry points. Van 't Schip pointed out that compromising an institution like a university does not require attacking core servers directly; instead, threat actors can exploit software flaws on staff laptops, using those endpoints as modern-day Trojan horses to access internal networks. Consequently, digital defense across households, academic centers, and healthcare facilities remains bounded by its weakest operational link.
The research also highlights financial and structural vulnerabilities, such as when a smart video doorbell manufacturer goes bankrupt and its operations are acquired by an untrusted third party. These corporate transition risks are amplified by modern software architecture, where a single internet-connected product relies on dozens of software applications that, in turn, depend on hundreds of nested open-source packages.
While open-source components offer advantages—including strong transparency and contributions from global developer communities—the software chain presents distinct oversight challenges. Van 't Schip observed that regulators can learn from open-source transparency when tracking deep supply chains. However, history demonstrates that malicious actors have spent years building credibility within open-source projects specifically to install covert backdoors, though public transparency typically leads to their eventual discovery.
Empirical research conducted by van 't Schip and his colleagues reveals that end users consistently view original equipment manufacturers as responsible for managing cybersecurity risks. Consumers expect manufacturers to maintain clear communication during data security incidents, issue rapid vulnerability patches, and deliver technical support throughout a device's active operational lifespan.
To help consumers reduce their exposure to vendor instability and supply chain breaches, van 't Schip advocates for legal reforms that decrease dependency on single manufacturers. Because modern smart hardware is tightly tied to proprietary mobile applications, cloud services, and user accounts, he recommends regulatory measures that allow users to disconnect devices from mandatory external platforms and retain control over their immediate digital environments.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



