Cyber regulations are where politics meets business – where business becomes subject to political realities.

[...]

One hundred percent continuous global compliance is effectively impossible. “It is definitely getting more difficult for companies to manage compliance,” agrees Sharon Klein, partner and co-chair of privacy security & data protection at Blank Rome law firm. “Companies often take an 80/20 approach complying with the general principles of the various laws or by attempting to comply with the more protective law and using that as the gold standard,” she continues. “For data security purposes, we have also seen a push to comply with industry accepted information security standards, such as NIST CSF, or obtaining third-party certifications for standards such as SOC 2 Type 2, ISO 27001, 27002 or 27017.”

To read the full article, please click here.

"Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements," by Kevin Townsend was published in SecurityWeek on January 23, 2026.