The cybersecurity wave hitting life sciences and healthcare companies: what you need to know
Life sciences and healthcare companies - from pharmaceutical manufacturers and medical device makers to hospitals, care providers and digital health platforms - face a rapidly evolving cyber regulatory landscape across the EU and UK.
The life sciences and healthcare sector is an increasingly high-value target for cyber attackers. Sensitive patient data, valuable IP, complex supply chains and growing reliance on connected devices and digital platforms all increase cyber risk. With the potential for operational disruption in this sector to directly affect patient safety, implementing appropriate cyber security measures is more important than ever.
Regulators have responded. Four major EU and UK cyber laws now impose - or are about to impose - significant new cyber security obligations on in-scope organisations, with substantial penalties for non-compliance.
Our attached briefing sets out what you need to know about:
EU Cyber Resilience Act;
EU NIS2 Directive;
UK Product Security and Telecommunications Infrastructure Act; and
UK Cyber Security and Resilience (Network and Information Systems) Bill, which is expected to receive Royal Assent before the end of 2026.
Click here to read more.
Share Article
Related Expertise
Contributors
Joanne Elieli
Partner
London
Sarah O'Brien
Partner
London
Alison Llewellyn
Senior Knowledge Lawyer
London
Alexandra Pygall
Partner - Head of Intellectual Property, London & Head of Life Sciences & Healthcare sector
London
Dan Holland
Partner - Global Head of Intellectual Property, Technology & Data
London
Naomi Leach
Partner
London