top of page

News & Views


CRA reaches critical milestone says NETSCOUT 
 
The EU’s Cyber Resilience Act (CRA) is putting a 24-hour clock on cyber incident reporting.  From 11 September 2026, manufacturers, distributors and importers of digital products must report actively exploited vulnerabilities and security incidents within 24 hours of becoming aware of them.  We speak to Darren Anstee, Chief Technology Officer for Security at NETSCOUT, about what the deadline means for organizations and how they can turn regulatory compliance into stronger cyber resilience.
“These reporting obligations, and the availability of the Single Reporting Platform, mark a shift in how digital product manufacturers must report on exploited vulnerabilities and security incidents affecting their products.  Having a single place to report, which will then automatically propagate information across the region, will help to ensure relevant information is quickly disseminated.
 
“The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt.  Better, more rapid sharing of information helps organizations put defences and mitigating controls in place when they know there is heightened risk.”
 
“Organizations must accept that preventative controls can fail.  Maintaining cyber resilience means ensuring that you have consistent, detailed visibility across your digital infrastructure.  Being able to quickly isolate anomalous behaviours and identify the scope of any security is key.  Equipping operations teams with the tools they need is crucial to retaining trust with customers and stakeholders.”
 
“The follow-up phases of the SRP, where organizations will be able to voluntarily notify around vulnerabilities and risk changes in advance of an active exploit or incident are also important.  These subsequent phases will hopefully ensure information sharing which allows organisations to get ahead of potential issues, rather than waiting for there to be a patient zero before a notification is made.”

 
bottom of page