The regulatory environment is evolving rapidly as national and international regulatory bodies attempt to keep pace with changing business models, technology infrastructure and continuously escalating cyberthreats.
The past 18 months have seen a slew of new legislation and guidance come into effect across the globe as regulators aim to protect individuals, organisations and economies from the effects of disruption, data loss and theft.
There’s no doubt that new ways of doing business, managing financial and corporate systems and recording individuals’ personal information require new governance principles, but the volume and complexity of regulations is creating significant challenges for the businesses that must comply. The issue is further complicated by the fact that new regulations have been designed with today’s interconnected digital ecosystems in mind; businesses are not just responsible for their own security and risk management, but that of their partners and suppliers as well.
And the clock is ticking. As the first penalties for infringements of the GDPR are proposed by the Information Commissioner’s Office (ICO) - at levels showing the regulator’s willingness to exercise its full powers - businesses can have no illusions that compliance risk management has to be top of the board agenda.
Common drivers and themes for regulation – accountability and control
The latest raft of regulations and guidelines are, understandably, driven by some of the mass breaches and disruptions that have taken place over recent years. Incidents such as the SingHealth breach in the Asia Pacific region, which saw hackers steal personal data of 1.5 million patients, and the Landmark White case in Australia, where the third party property valuation service used by several major banks was compromised, have directly resulted in regulators issuing recommendations to try and prevent a recurrence.
At the same time the financial sector, in particular, has identified the risks introduced when financial market institutions outsource critical infrastructure to third parties, such as cloud service providers. The European Banking Authority (EBA) outsourcing guidelines apply from 30th September 2019 and will require that financial institutions achieve robust assurance that third parties are compliant with security objectives. Their aim is to allow financial institutions to benefit from the advantages of outsourcing, while maintaining control of risk.
This brings us to the two common themes of the vast majority of regulations that have recently been enacted which, taken together, allow companies around the world, and in whatever industry, to get a workable perspective on the landscape.