Skip to content
Clumio

The data-first CISO, for a new era of data compliance

Let’s be honest, most of us in this industry have been asking for change for a long time. Many of us have argued for digital privacy as a right, and now it’s starting to come to fruition. We see month over month more legislation being introduced.


This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

Maßnahmen im Zusammenhang mit US-Datenschutzvorschriften: CCPA, NYDFS und SEC aktualisieren ihre Anforderungen

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great tracker.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • Hier geht es um mehr als nur ein Datenschutzgesetz – es geht auch um die Widerstandsfähigkeit von Unternehmen und einen sicheren Betrieb.

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at „Data Protection Report.

Warum Führungskräfte Cybersicherheits-Know-how priorisieren müssen

Angesichts dieser starken gesetzgeberischen Bestrebungen sind nun konkrete Haftungsrisiken zu erwarten. Führungskräfte können die Empfehlungen der Sicherheitsteams nicht länger ignorieren. Die Realität sieht so aus, dass die meisten Unternehmen noch nicht darauf vorbereitet sind. Ein kurzer Auszug aus Forbes veranschaulicht dies perfekt:

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

Kurz gesagt: CISOs müssen in jede strategische Diskussion auf Vorstandsebene einbezogen werden. Ein aktiver CISO kann sogar einen Wettbewerbsvorteil darstellen. Diese aktiven Führungskräfte verstehen die Geschäftsdaten, wissen, wie man sie für Marktvorteile nutzt, und meistern neue regulatorische Herausforderungen. Unternehmen, die den sich wandelnden regulatorischen Rahmenbedingungen immer einen Schritt voraus sind, werden höhere Erträge erzielen. Unternehmen, die Compliance lediglich als eine Aufgabe betrachten, die abgehakt werden muss, werden ins Hintertreffen geraten.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Tabletop-Exercise-2026

SaaS Matters – Enterprise Support Made Possible by Clumio

Read more about SaaS Matters – Enterprise Support Made Possible by Clumio
Thumbnail_Blog-QTFY-Advisory-2026

The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.

Read more about The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.
Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio