European Union: Cybersecurity

Subscribe
Accounting law and audit law thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics such as FinTech, marketing, media, new technology, security.
Article
It’s LIVE: The Cyber Resilience Act Reporting Is Mandatory as of Today - 11 September 2026
Manufacturers of connected products must now comply with the EU Cyber Resilience Act's vulnerability and incident reporting obligations through ENISA's newly launched Single Reporting Platform. This comprehensive guide addresses the critical question every manufacturer faces: can your organization report a cybersecurity incident within 24 hours if one occurs tonight?
European Union Commercial
CM
Crowell & Moring LLP
Article
Cyber Resilience Act: New Vulnerability Reporting Requirements Now In Force
The EU Cyber Resilience Act introduces mandatory reporting obligations for manufacturers of digital products, requiring them to notify authorities within 24 hours of discovering actively exploited vulnerabilities or severe security incidents. This regulation establishes strict timelines for early warnings, detailed vulnerability notifications, and final reports, fundamentally changing how manufacturers must respond to cybersecurity threats.
Ireland Technology
BJ
Browne Jacobson
Article
The EU Cyber Resilience Act: Reporting Obligations Take Effect
The EU Cyber Resilience Act introduces mandatory vulnerability and incident reporting obligations for products with digital elements starting September 2026. Economic operators developing, importing, or distributing such products in the EU face strict compliance deadlines, substantial penalties for non-compliance, and must implement security-by-design principles throughout product lifecycles.
European Union Media & IT
M
Matheson
Article
The European Union Health Data Space: Unlocking The Value Of E- Health Data Through Responsible Governance
The European Union has spent the last decade reshaping the digital regulatory landscape through landmark legislation such as the General Data Protection Regulation (GDPR) and the AI Act. The European Health Data Space (EHDS) Regulation is the next significant step in that evolution. While often described as a healthcare initiative, the EHDS is at its core a data governance framework designed to unlock the value of electronic health data while safeguarding fundamental rights and promoting innovation.
Cyprus Healthcare
EN
Elias Neocleous & Co LLC
Article
Cybercrime & Compliance: Navigating Risks In A Digital World – A Conference Report
Herbert Smith Freehills Kramer's Frankfurt Corporate Crime & Investigations team hosted a conference examining cybercrime threats, AI-driven attacks, and the evolving responsibilities of corporate leadership in building cyber resilience. Senior representatives from law enforcement, industry leaders, and global legal partners explored prevention strategies, incident response protocols, and the complex liability landscape facing organizations in an increasingly digital threat environment.
Germany Technology
KL
Herbert Smith Freehills Kramer LLP
Article
Cyber Resilience Act: What Manufacturers Need To Know
The EU's Cyber Resilience Act introduces mandatory cybersecurity obligations for products with digital elements placed on the EU market. Understanding the five key manufacturer obligations—from secure-by-design requirements to incident reporting deadlines—is essential for compliance with this groundbreaking regulatory framework that elevates cybersecurity from best practice to legal requirement.
European Union Strategy
WF
William Fry
Article
ECB Requires Significant Institutions To Address AI-enabled Cybersecurity Threats
The European Central Bank has issued an urgent directive to major financial institutions requiring comprehensive action plans to counter rapidly evolving cybersecurity threats powered by frontier artificial intelligence models. With an October 2026 deadline looming, banks must demonstrate concrete measures across vulnerability management, monitoring capabilities, and third-party risk controls as AI-enabled attacks compress the timeline between threat discovery and exploitation. This supervisory escalation s
European Union Compliance
AO
A&O Shearman
See more