The Compliance Treadmill: Regulated Firms Deserve Better The Problem Across financial services, regulators have quietly closed the perimeter. There are eight core areas that matter in cybersecurity, and regulators now cover all eight. Not lightly, not vaguely, but comprehensively. Some areas are still evolving, but the gaps are gone. They have also discovered something new: they can collect information automatically and issue fines using algorithms. Once regulators learn they can enforce at scale, they do. Fines in financial services have been rising at around 12 percent a year. New cyber rules are landing on top of this trend. If your organisation is still operating on a firewall, antivirus and hope model, the next regulatory cycle will be painful. The regulatory volume itself is escalating: • • •
EU: 45 active initiatives US: 32 UK: 22
These numbers used to be far lower. In 2020 the EU had 12. The UK had 8. The US had 18. Growth has been fast and continuous.
Timelines are tightening too:
• • • •
DORA: effective January 2025 NIS2: intended for October 2024 transposition, but only around half of EU states met it UK Cyber Security and Resilience Bill: introduced in late 2025 CIRCIA: from May 2026, 72-hour reporting for more than 300,000 US entities
If your company works across borders, you face different definitions of incidents, different reporting deadlines and different regulators asking for the same information in different formats.
What Makes It Worse Regulation is one thing. Reality is another. Financial firms are targeted constantly. Criminals want client data, transaction data, payment capabilities and leverage. Internal misuse, both deliberate and accidental, adds another layer of risk. AI has lowered the cost of causing trouble. A lone attacker can now impersonate a voice, craft personalised messages and stitch together data from multiple sources in minutes. What once required a coordinated team can be achieved by one person with a laptop. For regulated companies, this creates a difficult combination: real threats, increasingly capable attackers and regulators who expect you to keep up.
Why Current Approaches Struggle The industry's default reaction is to spend more. Cyber budgets grew from 8.6 percent of IT spend in 2020 to 13.2 percent today. However, MSP and outsourced IT budgets are shrinking. Companies are trying to do more with fewer people while facing heavier regulation. So where does the money actually go? Consultants. Gap analyses, mappings and health checks often cost between £50,000 and £80,000. Then come annual reviews and additional work whenever a new regulation appears. Consultants help, but you begin to rely on them. Enterprise tools. The logic is simple: buy a platform and things will improve. In reality, the platform needs a full-time operator. Licences range from £12,000 to £34,000 a year. The person to run it costs between £60,000 and £100,000. Even with both, someone still needs to translate what the results mean for your business. Questionnaires. You receive them from clients. You send them to suppliers. Dozens of pages on
continuity, privacy, access and resilience. Most of them get skimmed rather than analysed. Not because people do not care, but because there simply is not enough time. Cyber remains a cost line. Insurance premiums rise every year. Investors ask for documentation. Large clients demand evidence. And the internal feeling grows: we are spending more, but it is not getting easier.
The Cycle No One Intended Some organisations look to Cyber Essentials or similar baseline frameworks. These are sensible for small businesses. They are not designed for regulated firms holding financial records, client data and fiduciary responsibility. Even completing these baselines properly often requires external help. Then the cycle repeats the next year.
The pattern becomes familiar: 1. A new regulation appears. 2. Urgency spikes. 3. Consultants are hired. 4. Tools are purchased. 5. Everyone promises clarity. 6. Another regulation appears. You never quite take ownership. You only react to the next requirement.
Breaking the Cycle There is another way: take ownership, but do it thoughtfully, with clarity and with confidence. You do not need to become a cybersecurity specialist. No one expects a CFO, COO or Head of Compliance to learn thousands of technical terms. What you do need is a clear understanding of where you stand in language that makes sense for your business. That is the purpose of RateYourCyber. It is built for companies with regulatory responsibilities but without a dedicated security department. Typically, these are organisations with 10 to 500 staff who need clarity rather than complexity. •
•
•
•
One assessment, 40 to 50 minutes. Written in straightforward language with a technical toggle if you want it. Any senior leader can complete it. All eight domains covered at once. Your current gaps mapped to DORA, NIS2, GDPR, ISO 27001, SOC 2, SEC rules and guidelines at the same time. Outputs you can rely on. A clear report. A structured roadmap with 90-day, 6 month and 3-year priorities. Benchmarks. Policies created from your actual answers rather than generic templates. A rational cost model. Instead of £145,000 consulting cycles or enterprise tools and the staff to run them, this is a simple annual cost in the low thousands.
Tools do not replace leadership. They do not eliminate responsibility. But they can give you visibility, structure and a common language so cybersecurity becomes part of running the business rather than a crisis or a dependency. Regulators have raised expectations. Attackers are improving. Insurance, investors and clients are all asking tougher questions. The answer is not to panic or to outsource everything. It is to take control, calmly and clearly, with the right support. We believe that is the way forward: thoughtful ownership, supported by tools, guided by understanding rather than fear.
About the author: Andrey Darenberg, founder, RateYourCyber.com: Last 12 years in cybersecurity, with 10 years in governance consulting. Corporate
strategy, investments and venture capital background, finance by training. PhD in Finance, MBA (London Business School), IT Systems Analysis and Design (Oxford), C-DORA-P, ISO 27001 Lead Auditor, C-DPO, CE auditor, IASME auditor.