Keegan Crage is the owner of TechBrain, an ISO 27001-certified technology, cybersecurity & AI governance partner operating across Australia.
A law firm calls to ask about a recently enacted compliance rule. Then an equipment distributor, same quarter different industry, midway through absorbing the last rule when the next one landed. Running an IT and security practice for mid-market companies, you see it clearly: Compliance is no longer the sole domain of the lawyers.
And then there is the surprising bit: Most people want the additional rules. A World Economic Forum survey of business and security leaders found that 78% believe cyber regulation reduces risk. However, the same survey also found 69% believe the rules have become too complex or too numerous to keep up with. The rate of new obligations has simply exceeded the ability of businesses to absorb them.
Let’s take a look at upcoming cyber regulation in the back half of 2026.
The European rules for high-risk AI came into force in August. The American incident reporting rules for critical infrastructure are still making their way through the regulatory process, yet the government’s own analysis has already priced them: $1.4 billion in first-year costs across 316,244 covered entities.
The Pentagon’s supplier certification program recently suspended independent assessments due to start in November, covering 220,000 companies, mostly small to mid-sized subcontractors in the defense space. Each rule is reasonable on its own, so nobody is in charge of the sum. The compliance burden has become heavier in Australia too. The financial crime regulator here recently went from supervising around 19,000 businesses to close to 100,000: law firms, accountants and real estate agents, most of them never regulated this way before.
Those professions sit among the five most reported sectors for breaches in official statistics, and now they carry financial crime obligations too. A financial services business in Australia can face two separate 72-hour incident clocks, owed to two different regulators and triggered by two different events. And the newest critical infrastructure rules went from exposure draft to binding law in 11 weeks.
We had a client asking for Essential Eight Level 1 compliance based on the recommendation of their existing provider. Once we sat down to discuss their business objectives, it became clear that there were a number of compliance hurdles they needed to clear across various frameworks, including the Privacy Act, ASX requirements, notifiable data breaches and Corporations Act, along with third-party business relationship obligations.
Essential Eight compliance would fall short, and tackling each requirement as a separate project was not practical, so our recommendation was to establish a set of core controls and map them out to their specific requirements.
In my experience, organizations tend to launch a project for each rule and end up building out duplicate auditors, spreadsheets and meeting cadence. All of these projects can collectively overburden a business with compliance debt. In the U.S., the Business Roundtable told the White House’s harmonization review that duplicative and conflicting rules are focused on driving technical compliance but fail to incrementally move the needle on security value.
Security chiefs at financial companies say 30% to 50% of their time goes to regulatory compliance that could be better spent dealing with the real threats. Relief may come one day through more streamlined regulation, but waiting for that day is not a strategy.
I’ve seen mid-market companies managing to cope with the cascade by establishing a set of core controls, then translating those into whatever format is required by each relevant regulator. The rules for critical infrastructure in Australia allow five different security frameworks to implement a single set of obligations, including the NIST framework and ISO 27001.
Recently in Brussels, there have been proposals to allow companies that have gone through an audit by a third party to rely on that audit instead of having to go through the same audit by every regulator. And a government commissioned review of the architecture for critical infrastructure in Australia concluded that an architecture of resilience is required, not an architecture of compliance.
For a mid-market business already running a solid control baseline, such as ISO 27001, when a new regulation drops, more often than not the organization can introduce the new requirement through mapping to the existing control framework. The cyber ransomware reporting requirement is a good example. Some changes, however, such as the new Anti-Money Laundering regulation, will require genuinely new work.
And there are more rules coming in 2027. Health security rules in the U.S. will be revised, product security rules will be introduced in Europe and a new round of privacy rules is already flagged in Australia.
Buy compliance one regime at a time, and you’ll pay for the same control five times over. Treat the overlap as the asset, and you’ll walk into next year’s rules with most of the groundwork already done.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







