This Practice Note offers a concise overview of cybersecurity challenges for life sciences companies, providing practical advice for EU-based organisations. It covers the regulatory landscape regarding cybersecurity in the EU, including NIS 2 Directive, Medical Devices Regulations (MDR and IVDR), EU AI Act, EU Cyber Solidarity Act, EU Cyber Resilience Act, European Health Data Space Regulation or EHDS, among others, and their compliance obligations and their sanctions or enforcement consequences in the event of non-compliance. It also highlights key regulatory authorities and industry bodies, concluding with insights into cybersecurity legislation trends and future outlooks. The cybersecurity landscape in the life sciences sector The life sciences sector, covering research and development (R&D) of pharmaceuticals, medical devices, and biotechnology; clinical trials; and healthcare services, increasingly integrates digital technologies like telemedicine, health apps, and artificial intelligence (AI) to boost operations and innovation. This digital adoption, however, introduces cybersecurity risks. For the purpose of the current Practice Note, cybersecurity refers to the protection of data and systems from unauthorised or malicious