Lisa Rooij

PhD Researcher Regulation and Governance of Security Patching

Tilburg University

Lisa Rooij has recently submitted her PhD research on the regulation and governance of patching (‘security updates’). She conducted her research at the Tilburg Institute for Law, Technology and Society (TILT), working alongside Lokke Moerel. Her research analyses EU cybersecurity laws, such as the NIS2 Directive and CRA, to identify trends and gaps in the regulation of vulnerability management and security patching. As part of her research, Lisa combines her legal background with expert insights from practice. She has conducted interviews with 30 CISOs of large Dutch organisations to identify challenges to timely patching and the effective implementation of security patching policies and EU rules. Part of this research was featured in a video presented during a keynote at the 2025 ONE Conference. Lisa collaborates with a multidisciplinary consortium of researchers and stakeholders as part of the NWO-funded THESEUS project, with the aim of delivering concrete recommendations to incentivise timely patching for lawmakers and practitioners.

Sessions with Lisa Rooij

Lisa_Rooij