Skip to main content

Hedgeweek® x Rate Your Cyber - Whitepaper - Ten Predictions

Page 1


Ten Predictions for Governance, Risk and Cybersecurity:

2026-2029

What Comes Next

The past five years reshaped the regulatory landscape for cybersecurity and operational resilience. Regulatory initiatives across the EU, UK and US more than doubled. Compliance cycle times compressed by nearly 70 percent. Fines rose at around 12 percent a year, and new enforcement mechanisms arrived on top of that trend.

That was the setup. What follows between now and 2029 will be more consequential.

The changes ahead are not simply more of the same. They are structural. The nature of regulation is shifting. The geography of leadership is changing. New disciplines are emerging that did not exist in most governance frameworks five years ago. And the burden of compliance is moving to places it has never reached before.

These are ten (although, subjective, based on trends we see) predictions for what regulated firms, fund managers and portfolio companies should expect.

More Prescriptive Regulation

1. Prescriptive regulation wins. Voluntary frameworks retreat.

The era of "here are some guidelines, do your best" is closing. What replaces it is specific, evidence-based and enforceable.

GDPR set the template. DORA extended it into operational resilience. The pattern is consistent: regulators define what is required, set deadlines, demand evidence, and impose meaningful penalties for non-compliance. Other jurisdictions are adopting the same approach because it works. Less ambiguity produces more security.

This matters for fund managers because it changes the nature of what portfolio companies must demonstrate. Narrative explanations no longer satisfy LP questionnaires. Voluntary alignment with a framework is no longer sufficient when regulators and counterparties expect documented, verifiable controls.

By 2029, voluntary-only compliance will be a liability, not a strategy.

2. Frameworks that do not adapt comprehensively will become obsolete.

Cyber Essentials is the clearest example. Its April 2026 update is minor: clearer definitions, mandatory multi-factor authentication, better cloud scoping. These are sensible adjustments. They are not a transformation.

Meanwhile, DORA requires documented ICT risk management frameworks, formal incident reporting processes and regular resilience testing. Saudi Arabia's National Cybersecurity Authority framework spans governance, asset management, risk management, people security and technology protection in a single mandatory structure. China's revised Cybersecurity Law, effective January 2026, incorporates AI governance at legislation level, extraterritorial enforcement and mandatory incident reporting within hours.

The gap is widening. Frameworks designed for a simpler threat landscape face a choice: evolve to match the actual regulatory and operational environment, or be overtaken by regulation that does the job properly. For regulated firms, the question is not whether a baseline framework is useful. It is whether it remains sufficient. For most, it already is not.

3. Freedom without structure is a liability.

Organisations given maximum flexibility in how they approach cybersecurity - choose your own framework, define your own risk appetite, self-assess - consistently underperform.

This is not a philosophical point. It is an observable pattern. The evidence from prescriptive regimes like GDPR and DORA suggests that structure, even when it feels burdensome, produces better security outcomes than voluntarism. Firms operating under clear, mandatory requirements tend to be better prepared, better documented and better able to demonstrate their posture to regulators, investors and counterparties.

The analogy is straightforward. A teenager given complete freedom without understanding that life is complex will almost certainly run into problems. Structure is not the enemy of efficiency. It is the condition for it.

The trend toward mandatory, evidence-based regulation is not bureaucracy. It is a correction.

4. Automated regulatory enforcement matures across the full cycle.

Over the 2026–2029 window, the progression is clear.

Regulators are already collecting compliance data automatically. The next stage is automated verification: cross-referencing submissions against external data, checking evidence for consistency, flagging gaps without human review. After that comes algorithmic enforcement and fines at scale, will probably become realistic for some jurisdictions, likely towards end of 2029 – going into 2030s

Once regulators learn they can enforce at scale, they do. This has been the pattern with every previous generation of financial regulation. Cybersecurity will not be different.

The window for getting by on self-reported questionnaires is closing. Firms that treat compliance checks as an annual exercise rather than a continuous process will find themselves exposed as verification becomes automated and persistent.

The Global Landscape Shifts

5. New jurisdictions leapfrog legacy frameworks.

The pattern is familiar from another sector entirely.

When fintech emerged across Eastern Europe, the traditional banking infrastructure was so outdated, and there was no established model worth copying, that entirely new systems were built from scratch. In many cases, what emerged was not just different but better: more coherent, more modern, more fit for purpose.

The same dynamic is playing out in cybersecurity governance.

Arabia's National Cybersecurity Authority produced an integrated framework covering governance, asset management, risk management, people security and technology protection - because it started from a blank page. The framework requires organisations to demonstrate implemented controls, regular audits and documented executive oversight. That is what DORA asks for, but the NCA built it natively rather than bolting it onto decades of legacy regulation.

China's comprehensively revised Cybersecurity Law took effect on 1 January 2026, the most significant update since the original was enacted in 2017. It incorporates AI governance into foundational legislation for the first time, expands extraterritorial enforcement to cover any overseas activity that endangers Chinese cybersecurity, tightens incident reporting to hours rather than days, and introduces supply chain security obligations with meaningful penalties. The revision took more than three years and multiple rounds of consultation. It is not a patch. It is a rebuild.

Hong Kong introduced its first comprehensive cybersecurity statute on the same date, covering eight essential service sectors with two-hour incident reporting for serious breaches.

These are not imitations of Western models. They are originals, built for the current threat landscape. For firms operating across borders or investing into these markets, understanding these frameworks is no longer optional. Yes, one may argue that putting in regulation in place does not mean that it will be properly enforced – but do you honestly believe this will not be a case, for example, with China?

6. Standards fragment and converge at the same time.

This sounds contradictory. It is not.

Principles are converging. Every major jurisdiction now expects resilience, accountability, incident reporting and evidence-based compliance. The direction of travel is the same everywhere.

Implementation is diverging. Different cryptographic standards. Different reporting timelines. Different data sovereignty rules. Different approaches to AI governance. China, the United States and Europe are each building distinct regulatory architectures around shared principles.

At the same time, efforts to harmonise are real. The EU's revised Cybersecurity Act focuses on structural harmonisation of technical security criteria. ENISA's 2026 International Strategy sets out how the agency will work with international partners to raise common cybersecurity levels. Cross-border frameworks like ISO 27001 and SOC 2 continue to provide shared reference points.

For firms operating across borders, the practical effect is that you cannot rely on a single framework, but nor can you ignore any of them. This favours approaches that map across multiple frameworks simultaneously rather than point-in-time certifications tied to one standard.

New Disciplines Emerge

7. Quantum compliance becomes a governance discipline.

The quantum threat to encryption is real, but it is not the immediate problem. The compliance obligation to prepare is (for now, in critical sectors)

By January 2027, new US National Security Systems must support post-quantum cryptography under CNSA 2.0. Financial services, healthcare and critical infrastructure sectors face emerging mandates for PQC migration roadmaps. The timeline that was once measured in decades is now measured in years.

For most organisations, the practical requirement is not to deploy quantum-resistant encryption tomorrow. It is to conduct a cryptographic inventory, understand where vulnerable algorithms sit across the estate, develop a migration roadmap and demonstrate crypto-agility to regulators, auditors and counterparties.

This is a governance and risk management exercise, not a technical one. It adds a new, permanent layer to every GRC programme. Organisations that begin now will manage an orderly transition. Those that wait will face compressed timelines, higher costs and regulatory pressure.

8. AI governance becomes a mandatory GRC domain.

Every major jurisdiction is building AI governance into its regulatory framework (read, restricts uncontrolled decision-making systems). China has written it into foundational

cybersecurity legislation. The EU AI Act is in force. The US Securities and Exchange Commission has made AI risk a 2026 examination priority.

The risks are not hypothetical. Shadow AI - employees adopting ungoverned AI tools to accelerate daily tasks - introduces data exposure, model misuse and compliance gaps that most existing security architectures do not account for. AI-generated content makes social engineering attacks harder to detect. AI-powered systems create new attack surfaces that traditional controls were not designed to address.

For fund managers, the implication is direct. Portfolio companies deploying AI, particularly in areas touching client data, investment decisions or regulatory reporting, need governance structures that address how AI is used, who authorises it, how outputs are validated and how risks are monitored. Any GRC framework that does not include an AI chapter by 2028 will be incomplete.

9. Risk identification, quantification and management become a systemic discipline.

The era of qualitative risk assessment is ending.

For years, cybersecurity risk was communicated through heat maps, colour-coded dashboards and subjective scoring. A risk was "high" or "medium" or "low." These assessments were better than nothing, but they could not answer the questions that boards and investors increasingly ask. How much could this cost us?

Quantitative risk analysis, led by methodologies such as FAIR, built the conceptual foundation for expressing cyber risk in financial terms. But traditional implementations were manual, resource-intensive and slow. By the time an assessment was complete, the landscape had often changed.

What changes between 2026 and 2029 is that requirement for continuous risk assessment and quantification makes this discipline operational and scalable. Automated data collection, real-time control monitoring and probabilistic modelling allow organisations to maintain a current, financially expressed view of their risk posture without the consulting overhead that made it impractical for all but the largest firms.

There is an interesting workforce implication here. As AI displaces data scientists from traditional modelling and analysis roles, those professionals - who already understand probability, scenario analysis, statistical methods and quantitative communicationbecome natural candidates for risk governance. The displacement creates the supply. The regulatory demand for quantitative risk management creates the demand. By 2029, the risk officer who cannot quantify will be as rare as the CFO who cannot read a balance sheet.

For SMEs, the shift is equally significant. They will not hire risk quantification teams. But they will need the discipline embedded in their processes, supported by platforms that do the heavy lifting. Risk governance - identification, quantification, mitigation,

reporting - will be built into operational procedures at every level. Not because organisations want it, but because their clients, investors, insurers and regulators will accept nothing less.

The Cascade Effect

10. Compliance becomes a condition of participation.

This prediction ties the others together.

Large enterprises, under pressure from regulators, investors and insurers, push compliance requirements onto their suppliers. The requirement is not unreasonable: if your security posture creates risk for my business, I need assurance that you are managing it. But the effect is structural.

More than half of large organisations now cite third-party and supply chain risk as their biggest cyber resilience challenge. The response, increasingly, is to make documented compliance a condition of doing business. Procurement processes incorporate security assessments. Contract renewals require evidence of governance. Insurance policies demand demonstrable controls.

For SMEs in regulated supply chains, the consequence is clear. Firms without documented, verifiable cyber governance lose access to contracts, partnerships and markets. The compliance burden that once applied only to regulated enterprises now reaches every firm in their ecosystem.

This is not malicious. It is structural. And by 2028–2029, it will be the norm across most sectors where regulated firms operate.

What This Means

The direction is set. Regulation will become more prescriptive, more automated and more consequential, as well as adaptive (and we see this in how fast regulatory changes occur) – and fast – in line with the changing threat landscape. New jurisdictions will produce frameworks that challenge assumptions about who leads in cybersecurity governance. And the compliance burden will cascade through supply chains to reach organisations that never expected to face it.

None of this requires panic. It does require clarity, structure and a willingness to take ownership rather than react to each new requirement as it arrives.

The organisations that will manage this well are not necessarily the largest or the best resourced. They are the ones that build cybersecurity into how they operate - with clear visibility, documented governance and the ability to demonstrate their posture in terms that regulators, investors and counterparties recognise.

The tools exist to do this at a rational cost. The question is whether leadership treats cybersecurity as a continuous discipline or an annual crisis. Between now and 2029, the distinction will become increasingly expensive to ignore.

About the author:

Andrey Darenberg, founder, RateYourCyber.com: Last 12 years in cybersecurity, with 10 years in governance consulting. Corporate strategy, investments and venture capital background, finance by training. PhD in Finance, MBA (London Business School), IT Systems Analysis and Design (Oxford), C-DORA-P, ISO 27001 Lead Auditor, C-DPO, CE auditor, IASME auditor.

Turn static files into dynamic content formats.

Create a flipbook
Hedgeweek® x Rate Your Cyber - Whitepaper - Ten Predictions by Global Fund Media - Issuu