Cyber resilience requires urgent response from in-house lawyers
Forthcoming legislation in both the EU and the UK will introduce new cyber resilience requirements for businesses. In-House Perspective explores the impact on in-house counsel, who are set to take on an increasingly strategic role in cybersecurity.
Cyber resilience is a key concept found in forthcoming EU and UK regulation, one that in-scope companies can’t ignore. There are two key upcoming dates for in-house lawyers in this regard. From 11 September 2026, manufacturers of products with digital elements must comply with vulnerability and incident reporting as part of the EU Cyber Resilience Act (CRA). Meanwhile, the UK Cyber Security and Resilience Bill is expected to have been finalised by the end of 2026.
The message is clear for in-house counsel. ‘The cyber realm now entails a regulated area of business risk and increasingly requires board-level legal accountability,’ says Derya Durlu Gürzumar, a Member of the IBA Alternative and New Law Business Structures Committee Advisory Board. Durlu Gürzumar, counsel at Turkish law firm Kolcuoğlu Demirkan Koçaklı Attorneys at Law, believes the CRA’s new reporting timelines ‘fundamentally alter legal work.’
Lukas Bühlmann, a Member of the IBA Technology Law Committee Advisory Board, says there’s been ‘a fundamental shift in regulatory thinking’ so that cybersecurity is ‘no longer treated purely as a technical issue’. Regulators, he says, ‘increasingly view cyber resilience as a product, governance and accountability issue.’ This is evident from the rules imposed by the CRA, which embed cybersecurity requirements directly into the product lifecycle.
But there are challenges for in-house lawyers grappling with this regulation. For instance, an understanding of what’s required can vary across businesses. Stefan Weidert, also a Member of the IBA Technology Law Committee Advisory Board, describes how his firm has seen many companies struggle to grasp the full breadth of the CRA’s scope.
The regulation covers all software and hardware products and their remote data processing solutions, provided their intended use includes a data connection. The breadth of this requirement can ‘lead to a rude awakening’, says Weidert, Head of the IP/Tech Practice Group at Gleiss Lutz in Berlin.
Sönke Lund, Chair of the IBA SPPI Working Group on AI, agrees. With regulatory obligations on their way, the most difficult question is often the first one asked, and that’s to consider whether an organisation is even in scope, he says. He believes that determining whether a given product qualifies as a ‘product with digital elements,’ and which risk tier it falls into, is a ‘genuinely difficult scoping exercise.’ This is particularly true for companies that don’t think of themselves as ‘product companies’ but embed connected functionality into their offerings, he says. At the same time, the obligation isn’t limited to new product launches. ‘It reaches back into the company’s existing portfolio,’ says Lund.
Geography is irrelevant. ‘Market access is what matters,’ says Lund, a partner at Iberian firm ECIJA. ‘The CRA applies regardless of where a manufacturer is headquartered, or where production occurs. The trigger is simply whether the product is made available on the EU market.’ For UK-based companies, this means any business exporting connected products or software into the EU, or participating in supply chains in the bloc, will need to comply as though they were an EU manufacturer.
More broadly, the primary impact of the UK and EU regulation for in-house lawyers is that ‘cybersecurity is moving much closer to the legal function’, says Bühlmann, Chair of the ICT Practice Group at Swiss law firm MLL Legal. He believes the greatest challenge will be managing the interaction between overlapping regulatory regimes. For example, he highlights that the CRA doesn’t operate in isolation. ‘It interacts with the second EU Network and Information Systems Directive, the Digital and Operational Resilience Act, data protection law, product liability rules, sector-specific requirements and national frameworks such as the evolving UK regime,’ he explains.
For international businesses, particularly Swiss and UK companies operating across borders, the practical challenge will be to coordinate requirements imposed by London, Bern, the EU and sometimes US requirements within a ‘coherent governance and compliance framework’, says Bühlmann.
At the same time, supply chain risk will become increasingly important. Organisations will need better visibility over software components, third-party providers, contractual responsibilities and incident-reporting obligations. ‘This is particularly challenging in complex digital ecosystems involving multiple vendors and open-source components,’ Bühlmann says.
In practice, many organisations already have a reasonable understanding of what good cybersecurity looks like. But going forward, the more difficult question is ‘who owns the relevant decisions, who carries responsibility and how those responsibilities are documented and evidenced’, says Bühlmann. ‘Often, the hardest part is not implementing a technical security measure, but demonstrating how decisions were made, who approved them and how accountability was allocated throughout the organisation.’
He believes the CRA’s documentation requirements could therefore prove challenging. ‘Organisations will increasingly need to evidence not only that cyber resilience measures exist, but also how they were designed, approved, monitored and maintained over time,’ he says.
Companies that continue to treat cybersecurity as a purely technical function risk missing the point of the new regulatory landscape
Lukas Bühlmann
Member, IBA Technology Law Committee Advisory Board
Regulation is shifting the paradigm in multiple ways, and the CRA’s September compliance deadline is one significant change of many. But preparation is key. Given the breadth of products the CRA covers, experts believe that a scoping exercise is a good place to start. The first step is to identify which products, services, legal entities, suppliers and contractual relationships may fall within the relevant regulatory framework, says Bühlmann. Organisations should then assess whether responsibilities are ‘clearly allocated between legal, compliance, security, procurement, product teams and senior management’, he says.
In parallel, companies should review supplier contracts, vulnerability disclosure processes, incident escalation procedures and governance structures to ensure they support future compliance requirements, Bühlmann adds. ‘Particular attention should be given to how cyber-related decisions are documented and how evidence is retained,’ he says.
The legislation at EU and UK level signals a regulatory shift that in-house counsel will need to adjust to. Yet the core message is simple, says Bühlmann. ‘Companies that continue to treat cybersecurity as a purely technical function risk missing the point of the new regulatory landscape,’ he explains. ‘Cyber resilience is becoming a question of governance, accountability and product responsibility. That is why in-house lawyers will play a much more strategic role than many organisations currently anticipate.’
Kate O'Flaherty is a freelance cybersecurity and privacy journalist and can be contacted at Kate.oflaherty@techjournalist.co.uk