Cybersecurity 2026

INTRODUCTION  Contributed by: Christian Schröder, Orrick, Herrington & Sutcliffe LLP

ing AI-enabled cyber-attacks. In addition, a range of state-level cybersecurity laws are already in place, with further legislation anticipated. Beyond the EU and the US, cybersecurity momentum is also recognisable. • On 12 November 2025, the UK introduced the Cyber Security and Resilience (Network and Infor - mation Systems) Bill to modernise its NIS regime, tighten reporting and transparency, and raise sanc - tions, largely aligning with the EU’s NIS2 Directive and easing cross‑channel co-ordination for multi - nationals. • In China, the first major overhaul of the Cyberse - curity Law since 2017 took effect on 1 January 2026, increasing penalties, strengthening adminis - trative enforcement, and extending extraterritorial reach. It also introduces a new article addressing artificial intelligence, signalling that AI governance and cybersecurity will increasingly be treated as integrated policy concerns. • Across the MENA region, Saudi Arabia’s National Cybersecurity Authority has entrenched mandatory baselines through Essential Cybersecurity Controls and sectoral extensions (including cloud), backed since 2024 by inspection and enforcement powers. • The UAE and Qatar are likewise elevating baseline controls and clarifying notification expectations. Challenges Rising geopolitical tensions are one reason for stricter cybersecurity regulations worldwide. State-backed and state-aligned activity has grown more sophisti - cated, and sectors intertwined with public mandates (such as defence, infrastructure and water) face heightened exposure. Consequently, cybersecurity standards for the public sector have increased sig - nificantly worldwide. The regulatory challenge now is less about intent and more about coherence of cybersecurity regulation. While the EU has made strides in creating a unified cybersecurity framework, achieving global consensus remains a complex task. Differences in legal systems,

regulatory approaches and levels of technological development can hinder efforts to establish common standards. However, international co-operation and dialogue are essential to overcoming these barriers and creating a cohesive global cybersecurity strategy. Another challenge lies in the integration of emerging technologies, such as artificial intelligence (AI) and the Internet of Things (IoT), into existing cybersecu - rity frameworks. These technologies offer tremendous potential for innovation but also introduce new vulner - abilities that must be addressed. The EU’s AI Act, for example, sets standards for the design and operation of AI systems to ensure they are resilient to errors and secure against unauthorised alterations. As technol - ogy continues to evolve, legal frameworks must be adaptable to accommodate new developments and address emerging threats. In addition, the cost of non-compliance with cyber - security laws is rising. Non-compliance can trigger substantial penalties under the EU’s NIS2 Directive of up to EUR10 million or 2% of worldwide turnover, alongside civil litigation and reputational harm. In the EU, a key driver is the personal liability of manage - ment introduced by NIS2. Conclusion: integrated legal approaches are needed Cybersecurity law can no longer be thought of as something separate and isolated but should be treat - ed as an integral part of a larger, interconnected land - scape, where a broad range of stakeholders must be integrated and where different laws are relevant, such as data protection law, consumer protection law and corporate governance. Technical aspects are also deeply connected with legal matters. For legal professionals, navigating the complexities of cybersecurity law requires a deep understanding of both the regulatory landscape and the technical aspects of cybersecurity. The path forward involves balancing innovation with regulation, ensuring that legal frameworks are both comprehensive and adapt - able to emerging threats.

7 CHAMBERS.COM

Powered by