ssdftrade-pressNewsThe Broadside2 min read

Zabierek pushes state software liability for secure-by-design rules

The federal strategy keeps naming manufacturers, but the legal pressure may arrive first from state product and privacy law.


TL;DR

Former CISA secure-by-design co-lead Lauren Zabierek told Inside Cybersecurity that states should explore software liability rules, using privacy and product-liability frameworks to push manufacturers toward secure-by-default development. The argument lands on state procurement offices, legislatures and software vendors, especially around critical infrastructure. Her uncomfortable point is capacity: the Trump resiliency order puts more security and resilience on states she says do not yet have the resources.

Inside Cybersecurity reports that Lauren Zabierek, a former CISA official who co-led the agency’s secure-by-design initiative, sees state governments as the nearer path for software liability rules. That matters because the Biden-era national cyber strategy put the conceptual burden on software manufacturers, while federal legislation and a safe harbor remain the hard, slow route. Zabierek’s claim is that states can move through procurement standards, privacy law and product-liability concepts before Congress finishes the grand architecture.

The state-law angle is the useful part. Zabierek pointed to uneven treatment across states, with New York using data privacy rules and Michigan and Louisiana approaching software through the definition of a “product” subject to product-liability claims. That is not the tidy national framework industry would prefer, and it is not the uniform operating model compliance teams would enjoy. But it is a plausible pressure point for changing who pays when insecure software ships.

Her sharper critique is aimed at the standard defense that software is too fast, too complex and too innovation-sensitive for product safety accountability. Zabierek told the outlet that treating software as uniquely exempt is a political position, not a technical finding. That is the secure-by-design argument stripped of its nicer brochure language: if manufacturers can define the defect out of the legal system, customers keep absorbing the security cost.

The practical problem is that the same states being asked to drive liability and critical-infrastructure resilience may not have the money, staff or institutions to do it cleanly. Zabierek said President Trump’s 2025 resiliency order puts more responsibility on state and local governments “without capacity and resources,” while praising CISA’s CI Fortify as an example of federal support. So the Monday-morning issue is not whether secure-by-design has rhetorical momentum. It does. The issue is whether states can turn that into enforceable procurement and liability standards without building fifty incompatible compliance regimes.


Published ·Deep Fathom

Zabierek pushes state software liability for secure-by-design rules — The Broadside