Cybersecurity 2026

UK Trends and Developments Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

Conclusion Cybersecurity threats pose a serious and growing range of operational, financial, regulatory and reputa - tional risks for organisations operating in the UK, and continue to be a material risk for almost all organi - sations according to DSIT. In its Governance COP, DSIT emphasises that building and maintaining cyber resilience remains crucial to protect an organisation’s financial viability. Through appropriate cyber resilience measures, DSIT further comments that organisations can leverage digital technologies, such as AI, to drive their business strategy and improve performance. Therefore, organisations should continue to closely monitor the development of new laws and guidance, while proactively implementing appropriate standards to mitigate cyber risks in 2026.

An indication of the ICO’s enforcement priorities can be gleaned from the foreword to its 2025 annual report. The actions highlighted illustrate the ICO’s readiness to impose significant penalties, especially where sen - sitive data is compromised. The ICO notes (amongst other things) enforcement actions taken against a pro - vider of healthcare software and against a company offering genetic testing. These actions resulted in fines of GBP3.07 million and GBP2.31 million, respectively. In both cases, the fines were issued following cyber- attacks, prior to which the data controllers had failed to implement appropriate security measures. Accord - ing to the Information Commissioner, a consistent theme in the ICO’s 2025 activities is the challenge of maintaining high standards and safeguards for indi - viduals’ rights while also fostering an environment that encourages organisations to innovate in a responsible and secure manner.

460 CHAMBERS.COM

Powered by