started · updated
EU Cyber Resilience Act drives lower cyber‑attack losses, HDI study finds
The European Union’s Cyber Resilience Act (CRA) will, from 11 December 2027, require that any product with digital components sold in the EU meet strict cybersecurity standards. Manufacturers must conduct continuous risk assessments, maintain a complete Software Bill of Materials and report vulnerabilities within set time‑frames, shifting compliance from a reactive burden to a strategic advantage.
A separate HDI‑commissioned “Cyber Study 2026”, which analysed about 5,500 cyber‑loss cases from 95 countries between 2013 and 2026, reports that the average financial impact of cyber‑attacks has fallen sharply. The study notes that “the average damage dropped from at least €68,000 in previous years to roughly €25,000”. Companies that prioritise preventive measures see losses reduced by up to 33 % and experience shorter downtime—about two days versus five to six days for less‑protected firms. The report warns that complacency could reverse this trend, especially for small and medium‑sized enterprises with limited resources.
Together, the upcoming regulation and the study’s findings illustrate a European shift toward stronger cyber‑risk management and underline the growing economic benefits of proactive security practices.