Cyber-security

What Cyber-Security Laws and Regulations Apply to Me?

USD 49 single Risk Briefing|Delivered within 4 hours|Reference material, not advice
Configure your report

What this risk is, and why it matters

Cyber-security is now a body of hard law, not best practice, and the obligations vary sharply by jurisdiction and sector. The risk for a senior executive is failing to map which regimes apply before an incident forces the question. A firm operating across borders may face EU, US federal, US state and sector-specific rules at once, each with its own security duties, reporting deadlines and penalties. Getting the map wrong creates exposure on several fronts, and ignorance of an applicable regime is not a defence.

Legal and regulatory framework

The landscape includes the EU's NIS2 and GDPR, the SEC's cyber-disclosure rules for listed companies, sector regimes such as HIPAA, the Gramm-Leach-Bliley safeguards and PCI DSS, financial-sector rules including DORA, and a patchwork of national and US state laws. Deadlines differ, from NIS2's 24-hour initial notice to the SEC's four business days for material incidents. Penalties reach tens of millions or a percentage of global turnover, with individual accountability rising.

Typical scenarios and impact

Enforcement has produced multi-million penalties for security and disclosure failures, mandated programme rebuilds, and increasingly personal consequences for officers who misrepresented posture. Because regimes overlap, one incident can trigger parallel investigations, each with its own timeline and disclosure duty, multiplying legal cost and management distraction. The reputational effect of a regulatory finding often exceeds the fine, particularly where it signals systemic weakness to customers and counterparties.

Mitigation framework and when to engage an expert

Build a jurisdiction-and-sector map of the regimes that apply, the security duties each imposes, and the exact reporting deadlines, and keep it current as the business and the law change. Assign clear ownership, and rehearse the multi-regime notification decision so the clocks are met under pressure. Engage regulatory and privacy counsel to validate the map, and align the security baseline to the strictest applicable standard rather than managing each regime separately.

Read the report. Talk to an expert.

This research is a starting point, not a verdict.

A Risk Briefing in the Cyber-security Domain tells you what the risk looks like, what the law says, and what indicators to watch. It does not replace a senior adviser who knows your jurisdiction, your industry, and your specific exposure. Senior advisors who have published on this exact question for your country appear at the bottom of this page once you have configured for a country. Download a Report for free; contact details live inside each PDF.

Configure for your country and industry

Pick a jurisdiction and an industry. Receive the report within 4 hours.

Country, optional state or region, and optional industry. Single Risk Briefing USD 49. Or buy the entire Domain Bundle (12 Risk Briefings) for USD 412 Save USD 176 (30%).

For Expert-Partners

Publish on this exact question

Buyers researching this risk in their country see your Report on this page. A Single Seat is USD 495 a year, up to five firms per page, and a Pro Seat is USD 1,485 for the larger card at the top. All 12 Cyber questions in one country cost USD 4,158/yr (save usd 1,782 (30%)). Registration is free and shows which of them are open before you choose.

Reference material for informed readers, not professional advice. Reports are produced against current, verifiable sources; material claims are referenced. Always consult a qualified adviser before acting on the contents of a report. Browse all Intelligence Reports.