ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

"Assume compromise" as industries face compliance challenges

Linked InXFacebook

Andy Norton at Armis explores how changing regulations are affecting the way that organisations must address their security

 

The clock is ticking. Attacks are looming. And almost no one is ready.

 

With less than a year to go before the enforcement of the EU’s Network and Information Security Directive 2 (NIS2), compliance is imperative. This urgency is rooted in the essence of NIS2, an upgraded directive designed to align with the evolving digital landscape and combat the surge in cyber-threats. 

 

Yet, a mere third of impacted organisations in the UK, France and Germany are adequately prepared for it. Notably three-quarters of UK organisations that operate within the EU are finding themselves lagging the most.

 

What industries are failing to realise, however, is that these new directives – not just NIS2 – are a different beast from previous regulations. Put simply, these regulations carry substantial consequences. Individuals at the top can be held accountable, with penalties for non-compliance on businesses and their senior board members. 

 

For example, companies like SolarWinds and its CISO are being charged by the SEC for not previously disclosing cyber-security vulnerabilities; or the construction company Interserve being fined £4,400,000 by the ICO for ignoring critical measures and using outdated software systems and protocols.

 

In addition, investigations into the UK Electoral Commission continue after it failed its Cyber-Essentials audit, despite a massive data breach last year. 

 

The landscape has shifted. And time is running out to comply. 

 

So, where does an organisation start?

 

The growing regulation challenge

The aim of any cyber-security regulation is to bolster the security of networks and information systems. NIS2, for example, casts a wider net far beyond its predecessor, including public entities and private organisations in critical sectors such as healthcare, transport, digital infrastructure, finance and manufacturing; the latter, in many cases, has not previously encountered such regulatory frameworks. 

 

However, the directive shifts the focus from where fines were once imposed reactively after a breach to enforcing proactive and robust cyber-security standards first. NIS2 emphasises a risk-oriented approach, demanding organisations to identify, assess and manage potential vulnerabilities continuously. Therefore, organisations must grapple with the imperative to fortify their cyber-defences, all under the assumption that compromise is not a possibility but a certainty.

 

Put simply, the attack surface continues to grow, and so does the opportunity for attackers to find a vulnerability and exploit it. On an average business day, UK organisations have approximately 45,000 connected assets, each carrying significant risk. Concerningly, over a third of IT and security decision-makers lack complete visibility, and, according to our research, 42% report a lack of control over these assets.

 

These threats and vulnerabilities are not going away. Compliance is a necessity. And yet, the clock continues to tick.

 

However, it’s not just NIS2 that’s shaking up the legislation landscape in the coming months. The UK’s consumer connectable product security regime will enforce minimum security requirements for manufacturers, aligning with the UK’s Code of Practice for consumer IoT security and global standards. This regime, like NIS2, aims to secure consumer products and mandates collaboration across supply chains.

 

Then there’s the Digital Operational Resilience Act (DORA) which will build a safer EU financial system from ICT incidents and operational vulnerabilities.

 

That’s a lot to contend with. Understanding and managing these regulations is no small task for any organisation. Combined with the likes of the Data Protection Act 2018, the UK-GDPR, the Online Safety Act, PECR and even NIST leading to overlaps with cyber-security mandates, it’s no wonder that in our research we have found that 39% of organisations admit to feeling challenged by the increasingly complicated regulations and governance requirements.

 

Thankfully, the solution to compliance is simple.

 

Building cyber-resilience the right way

The UK’s legal framework is, for now, spread across multiple different laws. But there’s three simple steps that organisations can take to ensure they meet the new demands. First, get the right technology in place. 

 

Navigating the complexities of compliance starts with investment in the right tech. Organisations must prioritise solutions that offer visibility of the entire attack surface, allowing for early detection, rapid response and the mitigation of potential high-risk vulnerabilities. By investing in a proactive stance, companies can not only ensure future proofing with compliance of changing regulations but can also fortify their defences against evolving cyber-threats.

 

The next step is all about the processes. 

 

The impact of NIS2 and other legislation will compel organisations to undergo a comprehensive risk management transformation. This includes implementing cyber-security risk measures, specifically addressing supply chain security, including risk assessments for suppliers and service providers.  

 

Furthermore, if an organisation is unsure whether it needs to comply with a certain regulation, it’s crucial to reach out to its industry’s relevant authorities. Engaging with regulatory bodies such as Ofcom, FCA, HSE or other industry-specific governing bodies is crucial. Establishing communication channels ensures organisations stay informed about whether they must comply, while offering opportunities to share threat intelligence and actively contribute to the overall cyber-security ecosystem.

 

The final step includes a cultural change. From the employee level to the boardroom, adopting a cyber-security-conscious culture is paramount. Particularly when according to our research, 67% of employees unknowingly introduce risks by downloading apps and software without IT or security team knowledge.

 

Therefore, educating the workforce through regular training and awareness programmes ensures that employees become the first line of defence against potential threats.

 

Together, these steps form the foundation to building compliant cyber-resilience. 

 

Safeguarding the future

Whether it’s NIS2, DORA or any other legislation, the countdown to compliance in the digital landscape is on. Organisations must recognise that this ticking clock is not merely about meeting regulatory deadlines, it’s a commitment to securing the future. Adequate cyber-security now demands constant vigilance.

 

While the ticking clock rings out, the necessity to assume you’ve been compromised echoes even louder. Yet, with the right technology, processes and training in place, organisations can stay safe and in line with regulations, no matter the industry. 

 


 

Andy Norton is European Cyber Risk Officer at Armis

 

Main image courtesy of iStockPhoto.com

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543