Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

AI Transformation Is An Organization Redesign Project

September 4, 2026

Tesla shares slump after feds launch probe into new Cybercabs

September 4, 2026

Welcome To The Cyber Compliance Cascade

September 4, 2026

New In-N-Out in Irvine opens at massive Great Park development

September 4, 2026

You’re AI-Ready, But Is Your Security Posture?

September 4, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Welcome To The Cyber Compliance Cascade

Welcome To The Cyber Compliance Cascade

By News RoomSeptember 4, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Keegan Crage is the owner of TechBrain, an ISO 27001-certified technology, cybersecurity & AI governance partner operating across Australia.

​A law firm calls to ask about a recently enacted compliance rule. Then an equipment distributor, same quarter different industry, midway through absorbing the last rule when the next one landed. Running an IT and security practice for mid-market companies, you see it clearly: Compliance is no longer the sole domain of the lawyers.

And then there is the surprising bit: Most people want the additional rules. A World Economic Forum survey of business and security leaders found that 78% believe cyber regulation reduces risk. However, the same survey also found 69% believe the rules have become too complex or too numerous to keep up with. The rate of new obligations has simply exceeded the ability of businesses to absorb them.

Let’s take a look at upcoming cyber regulation in the back half of 2026.

The European rules for high-risk AI came into force in August. The American incident reporting rules for critical infrastructure are still making their way through the regulatory process, yet the government’s own analysis has already priced them: $1.4 billion in first-year costs across 316,244 covered entities.

The Pentagon’s supplier certification program recently suspended independent assessments due to start in November, covering 220,000 companies, mostly small to mid-sized subcontractors in the defense space. Each rule is reasonable on its own, so nobody is in charge of the sum.​ The compliance burden has become heavier in Australia too. The financial crime regulator here recently went from supervising around 19,000 businesses to close to 100,000: law firms, accountants and real estate agents, most of them never regulated this way before.

Those professions sit among the five most reported sectors for breaches in official statistics, and now they carry financial crime obligations too. A financial services business in Australia can face two separate 72-hour incident clocks, owed to two different regulators and triggered by two different events. And the newest critical infrastructure rules went from exposure draft to binding law in 11 weeks.

We had a client asking for Essential Eight Level 1 compliance based on the recommendation of their existing provider. Once we sat down to discuss their business objectives, it became clear that there were a number of compliance hurdles they needed to clear across various frameworks, including the Privacy Act, ASX requirements, notifiable data breaches and Corporations Act, along with third-party business relationship obligations.

Essential Eight compliance would fall short, and tackling each requirement as a separate project was not practical, so our recommendation was to establish a set of core controls and map them out to their specific requirements.​

In my experience, organizations tend to launch a project for each rule and end up building out duplicate auditors, spreadsheets and meeting cadence. All of these projects can collectively overburden a business with compliance debt. In the U.S., the Business Roundtable told the White House’s harmonization review that duplicative and conflicting rules are focused on driving technical compliance but fail to incrementally move the needle on security value.

Security chiefs at financial companies say 30% to 50% of their time goes to regulatory compliance that could be better spent dealing with the real threats. Relief may come one day through more streamlined regulation, but waiting for that day is not a strategy.

I’ve seen mid-market companies managing to cope with the cascade by establishing a set of core controls, then translating those into whatever format is required by each relevant regulator. The rules for critical infrastructure in Australia allow five different security frameworks to implement a single set of obligations, including the NIST framework and ISO 27001.

Recently in Brussels, there have been proposals to allow companies that have gone through an audit by a third party to rely on that audit instead of having to go through the same audit by every regulator. And a government commissioned review of the architecture for critical infrastructure in Australia concluded that an architecture of resilience is required, not an architecture of compliance.

For a mid-market business already running a solid control baseline, such as ISO 27001, when a new regulation drops, more often than not the organization can introduce the new requirement through mapping to the existing control framework. The cyber ransomware reporting requirement is a good example. Some changes, however, such as the new Anti-Money Laundering regulation, will require genuinely new work.

And there are more rules coming in 2027. Health security rules in the U.S. will be revised, product security rules will be introduced in Europe and a new round of privacy rules is already flagged in Australia.

Buy compliance one regime at a time, and you’ll pay for the same control five times over. Treat the overlap as the asset, and you’ll walk into next year’s rules with most of the groundwork already done.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Keegan Crage
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

AI Transformation Is An Organization Redesign Project

September 4, 2026

You’re AI-Ready, But Is Your Security Posture?

September 4, 2026

Where The Shopper Meets The Shelf

September 4, 2026

How Gen-Z, Millennials, Gen-X And Boomers Really Use AI

September 4, 2026

The Best Culture Is Full Of Curious Beginners

September 4, 2026

Architecting Zero-Downtime Database Refactoring For Enterprise Systems

September 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Tesla shares slump after feds launch probe into new Cybercabs

Business September 4, 2026

The National Highway Traffic Safety Administration on Friday opened an investigation into whether 1,000 Tesla Cybercab vehicles were properly certified. Tesla shares fell…

Welcome To The Cyber Compliance Cascade

September 4, 2026

New In-N-Out in Irvine opens at massive Great Park development

September 4, 2026

You’re AI-Ready, But Is Your Security Posture?

September 4, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

How I stumbled into a major trend that’s slamming beer sales nationwide

September 4, 2026

Where The Shopper Meets The Shelf

September 4, 2026

US employers add 162K jobs in August — surprisingly strong pace

September 4, 2026

How Gen-Z, Millennials, Gen-X And Boomers Really Use AI

September 4, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.