I suspect that this will come up legislatively over time - everyone is watching Russia’s electronic warfare against Ukrainian infrastructure – and it’s a good time to write to your representatives about what you think policy responses should be. For example, I’d like to see it be harder for companies to deploy the “nation state-level attack” excuses without some barrier to entry greater than “we’d been slacking on patches for 18 months”.
Perhaps private industry and state governments should be more open to secure standards and rights to repair (looking at my ISP enforced routers).
It is.
1. PDF https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA...