Cybersecurity 2026

INTRODUCTION  Contributed by: Christian Schröder, Orrick, Herrington & Sutcliffe LLP

Introduction to the Cybersecurity Guide Cybersecurity has shifted from a niche technical con - cern to a management board priority and, increas - ingly, to an enforcement reality. Lawmakers and regu - lators in many jurisdictions are moving from principles to practice, demanding that organisations not only implement robust controls but also adhere to certifi - cation schemes or otherwise prove their compliance. The result is a maturing patchwork of cybersecurity rules that pose new challenges to many organisations. In the European Union (EU), the NIS2 Directive, the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA), the Cyber Solidarity Act, and a pending revision of the Cybersecurity Act are con - verging into a more integrated regime that reaches products, services, operations and supply chains. The US, Middle East and Asia-Pacific are simultaneously tightening rules, creating a patchwork of laws that management boards, legal departments and counsel must navigate cautiously. The recent wave of cybersecurity regulations reflects a global recognition of the critical importance of safe - guarding digital assets. These regulations underscore the necessity for comprehensive risk management strategies, accountability at the highest levels of man - agement, and the implementation of rigorous secu - rity measures across all sectors. One of the primary implications of these regulations is the heightened accountability placed on organisational leadership. This shift in responsibility requires a cultural change within organisations, where cybersecurity is integrated into the core business strategy rather than treated as a peripheral IT issue. Furthermore, the emphasis on incident reporting and transparency has profound implications for how organisations handle data breaches and cyber inci - dents. Timely reporting to regulatory authorities and affected parties is not only a legal obligation but also a critical component of maintaining trust and credibility. Cybersecurity laws around the world The rapid pace of technological advances and the growing significance of cyber-related systems for critical infrastructure are prompting lawmakers world - wide to introduce new legislation to address emerging

cybersecurity challenges. One of the key challenges for international businesses in implementing cyberse - curity regulations is the harmonisation of standards across jurisdictions. Differences in legal systems, regulatory approaches and levels of technological development can hinder efforts to establish common standards. For international businesses, it is crucial to react promptly to legislative amendments and imple - ment the relevant cybersecurity obligations within their internal structure. Consequently, it is essential to consistently monitor legislative processes and gen - eral trends. The EU continues to set the tone. Even as the transpo - sition of NIS2 remains uneven across member states, management bodies already face explicit governance duties and potential liability, and supervisory expecta - tions are sharpening. The CRA has been in force since December 2024 and pushes secure‑by‑design devel - opment, vulnerability handling and incident reporting across products with digital elements, including soft - ware‑only offerings. Its reporting obligations begin in September 2026, with many core duties taking effect in December 2027. In early 2025, a targeted update to the EU Cybersecurity Act strengthened the certifi - cation framework and empowered ENISA to develop new schemes, reinforcing trust in cloud and informa - tion security products and services. DORA has applied to financial entities since 17 Janu - ary 2025, with regulatory technical standards already in place for incident classification, reporting content and timelines, and the critical third-party provider (CTPP) oversight regime. The European Supervisory Authorities have already designated the CTPPs and launched oversight engagement. Financial entities should expect assertive supervision of ICT risk man - agement, testing, third-party chains and reporting. The United States is also consolidating incident reporting and governance obligations. The Cyber - security and Infrastructure Agency’s rule under the Cyber Incident Reporting and Critical Infrastruc - ture Act is planned for 2026. For the use of artificial intelligence, the National Institute of Standards and Technology is planning a Cybersecurity Framework, with the focus on securing AI system components, conducting AI-enabled cyber defence, and thwart -

6 CHAMBERS.COM

Powered by