In Episode 113 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Mark Lambert, Chief Product Officer at ArmorCode, to unpack the European Union's Cyber Resilience Act (CRA) and why U.S. companies cannot treat it as someone else's problem. Dr. Chatterjee opens with a scenario that captures the stakes: a mid-sized U.S. software company discovers one of its products is being actively exploited, investigates, patches, and notifies its customers within three days — a response most frameworks would call fast, but one that violates the CRA, whose clock for reporting an actively exploited vulnerability starts at 24 hours, not three days.
Lambert, who works daily with organizations on vulnerability management, explains that the CRA functions like GDPR for security: any software that ships into Europe, or that relies on supporting infrastructure serving European users, falls under its scope, and non-compliance carries fines of up to 2.5% of global revenue or €15 million, whichever is higher. The conversation walks through the CRA's three distinct notification clocks — a 24-hour early warning, a 72-hour full notification, and a 14-day final report after a fix becomes available — and dispenses with the idea that lacking sophisticated detection capabilities is a viable defense; the law expects secure-by-design practices and detection capability to already be in place before an incident occurs.
Analyzed throughout the episode through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the discussion also covers what well-prepared organizations are already doing — operationalizing vulnerability management programs and building real-time asset inventories — and closes with a shared view that regulatory pressure, while unwelcome, ultimately pushes organizations toward the security discipline they should be practicing regardless of legal mandate.
To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-113-the-eu-cyber-resilience-act-countdown-why-u-s-companies-cant-afford-to-look-away/
Connect with Host Dr. Dave Chatterjee
LinkedIn: https://www.linkedin.com/in/dchatte/
Website: https://dchatte.com/
Books Published
The DeepFake Conspiracy
Cybersecurity Readiness: A Holistic and High-Performance Approach
Articles & Cases Published
Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026
Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026
Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.
Ramasastry, C. and Chatterjee, D. (2025). Trusona: Recruiting For The Hacker Mindset, Ivey Publishing, Oct 3, 2025.
Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.
Isik, O., Chatterjee, D., and Lourenco, D.A. (2024). “Getting Cybersecurity Right,” California Management Review — Insights, Accepted for Publication, July 8, 2024.
Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.
Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland
Chatterjee, D. (2022). “Making Cybersecurity Readiness Mainstream,” Executive Blog Post, NETSPI, March 1, 2022
Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020
Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.
Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.