Ten Predictions for Governance, Risk and Cybersecurity: 2026-2029 What Comes Next The past five years reshaped the regulatory landscape for cybersecurity and operational resilience. Regulatory initiatives across the EU, UK and US more than doubled. Compliance cycle times compressed by nearly 70 percent. Fines rose at around 12 percent a year, and new enforcement mechanisms arrived on top of that trend. That was the setup. What follows between now and 2029 will be more consequential. The changes ahead are not simply more of the same. They are structural. The nature of regulation is shifting. The geography of leadership is changing. New disciplines are emerging that did not exist in most governance frameworks five years ago. And the burden of compliance is moving to places it has never reached before. These are ten (although, subjective, based on trends we see) predictions for what regulated firms, fund managers and portfolio companies should expect.
More Prescriptive Regulation 1. Prescriptive regulation wins. Voluntary frameworks retreat. The era of "here are some guidelines, do your best" is closing. What replaces it is specific, evidence-based and enforceable. GDPR set the template. DORA extended it into operational resilience. The pattern is consistent: regulators define what is required, set deadlines, demand evidence, and impose meaningful penalties for non-compliance. Other jurisdictions are adopting the same approach because it works. Less ambiguity produces more security. This matters for fund managers because it changes the nature of what portfolio companies must demonstrate. Narrative explanations no longer satisfy LP questionnaires. Voluntary alignment with a framework is no longer sufficient when regulators and counterparties expect documented, verifiable controls. By 2029, voluntary-only compliance will be a liability, not a strategy. 2. Frameworks that do not adapt comprehensively will become obsolete. Cyber Essentials is the clearest example. Its April 2026 update is minor: clearer definitions, mandatory multi-factor authentication, better cloud scoping. These are sensible adjustments. They are not a transformation.