Forgotten Dairies
Europe Just Criminalized Corporate Silence on Cybersecurity -By Fransiscus Nanga Roka
Preventing wealthy corporations from looking at fines the same way as operating expenses. Enforcement should focus on whether someone concealed details, how long they did so, if victims were exposed and when staff executives learned rather than just if a form arrived late.
For decades, security flaws were all somebody else’s problem for tech companies: consumers installed the updates, researchers found the bugs and governments paid the price tag. A radically new judgment on digital products comes from the European Union’s Cyber Resilience Act — if manufacturers profit off of them they need to be culpable for their weak points.
Under law on the Optional and Mandatory Reporting Regime, it has since the commencement of ENISA’s Single Reporting Platform (SRP) functioned.. Since September 11, 2026.[1] It is applicable to “manufacturers” that sell “products with digital elements” on the EU market, including connected hardware, software and firmware, Internet of Things devices and industrial systems. If open-source software topics are assigned to you, the stewards have even more required reports. Importers and distributors have distinct compliance responsibilities, but most of Article 14’s direct reporting duty is directed at manufacturers.
It covers who, what, where and when. That why is an indictment of regulatory failure: insecure products shipped possible around the world, a bungling of outcomes with the manufacturers cloaked vulnerabilities and delayed patches, externalizing costs to hospitals, businesses and governments. Studies in security seem almost like incidental or extreme sports; challenging new terrain that no one wished to pursue in their work.
The how is deliberately unforgiving. If a manufacturer is aware of a vulnerability that is actively being exploited, it has to submit an early warning within 24 hours as well as providing a wider notification on the vulnerability in the next 72 hour timeframe. And because the final vulnerability report must be released no later than 14 days after corrective or mitigating measures are available.
In the case of a serious security incident, the same 24-hour warning and a notification within 72 hours is given, after which a final report must be provided not later than one month after notification of the incident. Reports are pipelined to the relevant national CSIRT through the SRP and at the same time available to ENISA.
That distinction matters. And while summaries of what it means for a vulnerability to be “actively exploited” often cite a one-month deadline, this does not govern every exploited vulnerability. Europe has two different reporting tracks for the same reason; a discovered exploit and an actual serious product-security incident require unique final-reporting-triggers.
These penalties render corporate silence economically irrational. Fines for violations of Article 14 can be charged at an administrative level with fines of €15 million or 2.5% of the worldwide annual turnover, whichever is higher. Non-compliant products may also be restricted, withdrawn or recalled by the authorities. Regulators can also be fined for incorrect, misleading or partial information.
But perhaps the most powerful thing about the CRA may also be what makes it most susceptible to failure. An intelligence goldmine is a centralized platform filled with information about flaws being actively exploited. If hacked — or, worse, if information is spread too widely — the SRP could serve as a catalogue of targets to attack across Europe. And rapid reporting should not become rapid weaponization.
In conclusion, Europe needs to enforce need-to-know access, hardware-backed authentication, immutable audit trails, segregation keys encryption and red-team testing of the entire SRP. Notifications relative to unpatchable vulnerabilities should be sent to the authority for which it is operationally necessary, and every access must go back via identifiable official.
As for manufacturers, they will need product-security teams working 24/7; automated systems to escalate vulnerabilities as they are found; software bills of materials (SBOMs); and contracts forcing component suppliers to report any exploitation straight away. Real-time compliance dashboards should be shared with boards, and executives who keep reportable incidents from being reported should be held accountable in person.
Preventing wealthy corporations from looking at fines the same way as operating expenses. Enforcement should focus on whether someone concealed details, how long they did so, if victims were exposed and when staff executives learned rather than just if a form arrived late.
CRA boils down to a more straightforward moral precept, then globalizes it: companies can not become profit-oriented from software but socialize cyber insecurity. Now any manufacturer wanting access to Europe has to rethink not just its products but its culture.
Brussels has started the clock. No More Corporate Ignorance As A Defense—and Now Corporate Silence Could Cost Billions.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia
