Law changes faster than evergreen security principles
The principles are stable. The legal detail around them is not.
Least privilege and defence in depth have held for decades. Which regulation applies, what the deadline is and what must be reported have changed repeatedly in the last five years and will again. Anything written down that mixes the two ages at the speed of the faster half, which is why they are worth keeping separate.
More on Regulation and law
- Regulatory scope is a security architecture questionThe rope follows the wire
- Incident reporting deadlines change response prioritiesThe clock starts with the incident
- DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entitiesThe work moves, the answering stays
- Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties applyThree flaps, one outcome
- Breach notification and incident notification are different testsTwo holes, two different shapes
- Legal privilege does not make incident facts disappearIt seals the advice, not the facts
