By Rob Pocock
The need to comply with constantly-evolving cyber security and resilience regulation can feel like a heavy burden for organizations if they focus purely on the avoidance of penalties and reprimands.
Headlines highlighting huge fines for big-name transgressors can skew the perceptions. This unnecessarily negative approach puts all the emphasis on doing the minimum to stay out of trouble and neglects the longer-term benefits.
Rather than dragging their heels about compliance, organizations are better served viewing regulatory compliance as the opportunity to adopt more advanced protective frameworks, which quite arguably, they should be doing already. Regulation shouldn’t be viewed as a pain, even if it often results from the authorities realising appropriate security measures are not already in place. These frameworks enhance overall security and resilience, improving risk management and customer relationships while streamlining the efficiency of many processes.
The torrent of acronyms can admittedly seem depressing, but cyber regulation must evolve to match the innovation of criminals and to meet legislators’ demands for heightened consumer protection. The list of regulations facing organizations in the UK and Europe is formidable and includes the Data Protection Act, GDPR, NIS2, DORA, EU Cybersecurity Act, Telecommunications Security Act, PCI DSS, and EU Artificial Intelligence Act. Businesses with US connections may also need to address NIST and SOX.
Too many companies fail to update their cyber security practices until the last minute (or sometimes later). This is not always by choice, but because all businesses face competing priorities.
Businesses must instead take the initiative on regulation. They should actively take steps to protect critical assets with a view to improving operational resilience, building stronger bonds of trust with partners and customers.
Admittedly, this is not straightforward without external help, given the complexity of much regulation. The urgency for businesses to focus on compliance has also now increased with the growth of AI use cases. As businesses increasingly adopt AI, the risks of inadvertently infringing regulation increase. But so too, do the risks of falling victim to an AI-powered cyber-attack.
Compliance is about more than avoiding fines
Up to 74% of companies view compliance as a burden rather than a helpful form of guidance and standardisation. The UK Government’s Cyber security breaches survey 2024 found that only 58% of medium-sized businesses have a formal cyber security strategy and only four-in-ten sought information or guidance on the topic in the previous year.
This procrastination leaves organizations vulnerable to attack as they may be operating with outdated security protocols and unpatched systems. The result is an increased risk of data breaches, resulting in financial loss and reputational damage. The longer companies wait, the more exposed they become.
As a vital component in ensuring organizations are safe, the cyber security industry must also change some of its rhetoric around cyber regulations – all too often companies are bombarded with negative messages about how much they would be fined if they are not compliant, but no real messaging about how their business would improve and be more resilient if they did adapt to meet the regulations.
Taking the initiative
Companies must shift from a bare-minimum mindset to a security-first approach. Proactive cyber security involves staying ahead of threats by continuously updating security protocols, conducting regular risk assessments, and investing in advanced security technologies.
Companies of all sizes can achieve this by adopting existing frameworks, such as the UK National Cyber Security Centre’s (NCSC) Cyber Essentials, which helps establish a solid foundation for cyber security practices.
True cyber security requires more than just a set of tools. The complexity of regulation calls for a level of expertise that most mid-tier organizations can only access from external providers. This demands evidence of deep industry knowledge, and the ability to provide tailored, proactive protection based on real-world experience of regulation.
Engaging external partners with knowledge of compliance is the most assured path to increased resilience.
Enhanced brand reputation and greater customer trust are all benefits that come from demonstrable, transparent compliance, easily reported on a continuing basis, taking care of the complexities for hard-pressed internal teams.
By following regulations and maintaining an adaptable and up-to-date security posture, organizations see beyond the time-consuming complications of compliance to deliver significant strategic advantage.
The author
Rob Pocock is Technology Director, Red Helix






