Regulation. There’s been a lot of it in recent years, particularly in the European Union (EU) concerning cybersecurity and digital resilience. The last few years saw the arrival of the EU Network and Information Systems Directive II (NIS2), then Digital Operational Resilience Act (DORA) for financial institutions, and the new EU Data Act. And there’s not much space to breathe with the Cyber Resilience Act gradually coming into force over the next year.

You might think that it’s all a bit too much. That regulation is getting in the way and slowing organizations down. But this is the wrong way to look at it. Resilience isn’t optional anymore, and regulation is only a waste of time if you view it as a box-ticking exercise. Organizations that approach it the right way stand to gain far more than just avoiding a fine.

Regulation frustration?

There’s no shying away from it; we’ve seen a lot of cybersecurity and resilience regulations over the last few years. Even the General Data Protection Regulation (GDPR) – the regulation that started it all – is only seven years old. Since then, we’ve seen NIS2 and DORA bring broad new responsibilities across digital risk management and incident reporting for essential and important industries (in the case of NIS2) and financial services (the focus for DORA).

It’s a lot for not just CISOs to worry about, but thanks to a new onus on corporate accountability in regulations like NIS2, the entire exec team as well. Beyond the potential fines for the company itself, execs found grossly negligent can face being dismissed, banned from senior positions, or even prosecuted.

When you put it like that, it sounds intimidating, even now when many companies fall outside the heavier regulations. And with the upcoming EU Cyber Resilience Act covering any companies that place digital products with software on the EU market, even more companies will soon find themselves newly under scope.

It pays to be resilient – in more ways than you think

I have great sympathy for stretched IT or general business leaders for whom regulation and compliance are one of several plates to spin. Many may even feel that keeping up with this growing regulation is holding them back.

But, if you look at these regulations beyond ticking boxes or simply avoiding fines, you can gain much more. Firstly, these regulations exist for a reason. Cyberattacks have plagued all digital organizations in recent years. Just in the last year, we’ve seen major cyberattacks cripple operations for Jaguar Land Rover and M&S.

Even if regulation didn’t exist, the threats they are trying to mitigate would, so you need to be paying attention and investing in cybersecurity resilience regardless. Treat regulations as the bar for the minimum standards you should be aiming for. If you find a regulation comes into play that forces you to start a new process or procedure, you’re already behind.

But it’s important to be clear: being compliant doesn’t always mean being secure and organizations should be aiming to clear the bar, not just meet it. New directives are so frequent because threats are evolving fast, making industry standards, to an extent, a snapshot in time. In other words, it's far more effective to be compliant through being a mature, digitally resilient organization than it is to try to be resilient through compliance alone.

What many organizations fail to realize is that having mature data resilience goes beyond just cybersecurity. It might have the biggest impact there, but it also affects the business as a whole, and often the more mature an organization is in its data resilience, the better performing it is. But why?

One step beyond

Regulation often focuses on the tactical, targeting the symptoms of problems and requiring organizations to deploy specific measures to mitigate risk or respond when things go wrong.

While this helps the industry make gradual improvements, this patchwork approach to resilience ultimately leaves organizations always one step behind. To achieve true data resilience maturity, companies need to be using a longer-term approach that addresses the root causes of digital risk rather than just papering over the issues as they crop up.

The age-old trifecta of “people, process, and technology” is still as valuable as ever, but strategy now also needs considering. With a cross-functional approach in place, IT, security, and compliance can all feed into one cohesive strategy that not only anticipates threats but enforces governance and keeps businesses one step ahead of compliance.

This is why organizations that are ahead in data resilience maturity are more profitable on average. Having a joined-up strategy not only protects the business but often smooths out operational inefficiencies and breaks down silos along the way, meaning the organization can work smarter and grow more freely.

But what about those trying to take that step that gets them from chasing regulatory compliance to leading it?

Thankfully, there are tools out there that can help. Data resilience maturity models are becoming more accessible, giving organizations frameworks to follow that can assess their existing resilience maturity, identify gaps and provide steps to implement targeted improvements. Turning data resilience into a continuous point of improvement that delivers benefits not just for compliance but also cost efficiency.

Organizations that use these models and follow this approach don’t view compliance as an inconvenience or a box-ticking exercise. For them, data is no longer a point of failure, but rather an enabler of growth. With new regulations like the EU Data Act and the upcoming Cyber Resilience Act, they’re likely 90% of the way there, and view regulation as a chance to test their resilience and flex their agility, staying ahead rather than just keeping up. In short, strategy has turned their resilience from a requirement into a real business advantage.