Cybersecurity is no longer governed only by internal policies and technical standards. Governments and regulators are increasingly establishing specific requirements for how organizations assess security risks, protect systems and information, respond to incidents, and demonstrate accountability.
The challenge is that information security laws do not follow a single global model. Requirements can differ significantly by industry, jurisdiction, and the type of information or services an organization handles. Financial institutions, healthcare organizations, public companies, and businesses operating critical infrastructure may all face different obligations.
As these requirements continue to evolve in 2026, organizations need to understand not only which laws apply to them, but also how overlapping requirements can be managed through a consistent security and compliance program. This guide covers the major information security laws and regulations organizations should know, how they differ from data privacy laws, and practical ways to build a compliance program across multiple requirements.
Key takeaways
- Information security laws set expectations for how organizations protect systems and information. Requirements can include access controls, encryption, risk assessments, incident response, and security governance.
- Requirements depend on your organization. Industry, geography, business activities, and the types of information you handle can determine which laws and regulations apply.
- US requirements are largely sector-specific. Organizations may need to consider frameworks such as GLBA, HIPAA, SEC cybersecurity requirements, and NY DFS regulations depending on their operations.
- EU requirements are becoming more comprehensive. NIS2 and DORA introduce broader cybersecurity, operational resilience, incident reporting, and management accountability requirements for organizations within their respective scopes.
- Information security and data privacy are related but different. Security requirements focus on protecting information and systems, while privacy requirements focus on how personal data is collected, used, and shared.
- ISO/IEC 27001 is a standard, not a law. Organizations can use it to establish a structured information security management system and support compliance with applicable regulatory requirements.
- Multiple requirements do not always require separate compliance programs. A common-controls approach can help organizations map shared security controls across different laws and frameworks while addressing each regulation’s specific requirements.
- Compliance should be treated as an ongoing program. Regulations, threats, technologies, and business operations change, so organizations need to regularly reassess their security and compliance posture.
What are information security laws?
Information security laws are laws and regulations that require organizations to protect their data, systems, and information from unauthorized access, misuse, loss, or other security threats. They establish expectations for the technical and organizational measures an organization should have in place, such as access controls, encryption, security monitoring, risk assessments, and incident response.
These requirements can vary depending on the organization’s industry, location, and the type of information or services it handles. For example, healthcare organizations may have specific security requirements for patient information, while financial institutions may face separate rules for protecting financial data and managing cybersecurity risks.
Information security laws are closely related to, but different from, data privacy laws. Security laws focus primarily on how information is protected, while privacy laws focus on how personal data is collected, used, shared, and retained. The 2 can apply to the same organization or incident, but they address different responsibilities.
US information security laws and rules organizations must know
The US does not have one comprehensive federal information security law covering every organization. Instead, security requirements are spread across industry-specific regulations, securities rules, state requirements, and industry standards. Which requirements apply depends largely on what an organization does, where it operates, and what type of information it handles.
The following are some of the most important requirements organizations should understand:
1. GLBA Safeguards Rule
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions under FTC jurisdiction to maintain a written information security program for protecting customer information. The program should be appropriate to the organization’s size, complexity, activities, and the sensitivity of the information it handles.
Organizations need to assess their security risks and implement appropriate administrative, technical, and physical safeguards. These include access controls, data inventory, encryption, and ongoing monitoring of the effectiveness of the security program. Covered institutions must also report certain security events involving the information of 500 or more consumers to the FTC within 30 days of discovery.
2. HIPAA Security Rule
The HIPAA Security Rule establishes security requirements for protecting electronic protected health information (ePHI). It applies to covered entities such as healthcare providers and health plans, as well as business associates that handle ePHI on their behalf.
The rule requires organizations to implement administrative, physical, and technical safeguards. These include access controls, authentication, audit controls, and transmission security. Some implementation specifications are classified as “required,” while others are “addressable,” meaning organizations must assess whether and how they should be implemented based on their circumstances.
Importantly, the existing Security Rule remains in effect in 2026. HHS has proposed significant changes to strengthen cybersecurity requirements, but those proposed changes should not be presented as current mandatory requirements until finalized.
3. SEC cybersecurity disclosure requirements
The SEC’s cybersecurity rules apply to public companies subject to its reporting requirements. They focus less on prescribing specific technical controls and more on how companies assess, govern, and disclose material cybersecurity risks and incidents.
When a company determines that a cybersecurity incident is material, it generally must file a Form 8-K under Item 1.05 within four business days of making that determination. The rules also require annual disclosures about cybersecurity risk management, strategy, and governance.
This makes cybersecurity a financial reporting and governance issue, not only an IT responsibility. Organizations need processes that allow security, legal, finance, and executive teams to assess the materiality of an incident and make accurate disclosures within the required timeframe.
4. New York DFS Part 500
New York’s 23 NYCRR Part 500 establishes cybersecurity requirements for organizations regulated by the New York Department of Financial Services. It applies to covered financial services organizations and requires them to maintain a cybersecurity program based on their specific risk profile.
The regulation includes requirements around risk assessment, cybersecurity governance, access controls, and multifactor authentication. Covered entities must also report certain cybersecurity events to NYDFS within 72 hours. The requirements make cybersecurity governance and ongoing risk management an important part of regulatory compliance for financial organizations operating in New York.
EU and global information security laws in 2026
Organizations operating in Europe may face broader cybersecurity requirements than those covered by traditional sector-specific rules. NIS2 and DORA establish legally binding requirements for different groups of organizations, while ISO/IEC 27001 provides a voluntary framework for building and managing an information security program.
1. NIS2 Directive
NIS2 is the EU’s updated cybersecurity directive, replacing the original NIS Directive and expanding the number and types of organizations covered. It applies to organizations in sectors such as energy, transport, healthcare, digital infrastructure, and certain digital services, with requirements determined by the organization’s sector and classification.
Covered organizations must establish appropriate cybersecurity risk-management measures, address supply-chain risks, and strengthen incident response. NIS2 also introduces specific reporting timelines for significant incidents: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
The directive also places greater responsibility on management bodies, making cybersecurity a governance issue rather than something handled solely by the IT or security team.
2. DORA
The Digital Operational Resilience Act (DORA) focuses specifically on the financial sector. It applies to a broad range of EU financial entities, including banks, investment firms, insurance companies, and other regulated financial organizations, as well as certain ICT third-party providers.
DORA requires financial organizations to establish a structured ICT risk-management program, manage ICT third-party risk, report major ICT-related incidents, and regularly test their digital operational resilience. It also requires financial entities to maintain a Register of Information covering their contractual arrangements with ICT service providers.
For financial organizations, DORA brings cybersecurity and operational resilience into a single regulatory framework, with requirements that extend beyond traditional information security controls.
3. ISO/IEC 27001
ISO/IEC 27001 is not a law or regulation. It is an international standard for establishing and maintaining an Information Security Management System (ISMS). Organizations can use it to create a structured approach to identifying security risks, implementing controls, and continuously improving their information security program.
Unlike NIS2 or DORA, certification is voluntary. However, ISO/IEC 27001 can provide a useful foundation for organizations that need to demonstrate that their security practices are formally managed and risk-based.
Key 2026 enforcement developments to know
Cybersecurity requirements are increasingly moving from policy expectations to active regulatory oversight. In 2026, organizations should pay attention not only to whether a regulation applies to them, but also to how regulators are assessing governance, incident reporting, and the effectiveness of security controls.
1. NIS2 is moving into active implementation
NIS2 is no longer simply a future compliance requirement. EU member states are implementing the directive through national legislation and supervisory processes, bringing covered organizations closer to active regulatory oversight.
For organizations within scope, the focus is on having appropriate cybersecurity risk management measures, incident reporting processes, supply chain controls, and management accountability in place. Organizations should therefore treat NIS2 as an operational requirement rather than a policy exercise.
2. DORA is now an operational requirement for financial organizations
DORA has applied to covered financial entities since January 17, 2025, making 2026 an important year for organizations to demonstrate that their ICT risk-management and operational resilience processes work in practice.
Financial organizations need to maintain appropriate ICT risk-management processes, manage third-party ICT risk, report major ICT-related incidents, conduct resilience testing, and maintain the required Register of Information for their ICT service arrangements. The emphasis is increasingly on evidence that these processes are operating effectively, not simply on having documentation.
3. The SEC continues to scrutinize cybersecurity governance and disclosures
For US public companies, cybersecurity remains both a governance and disclosure issue. The SEC’s Cyber and Emerging Technologies Unit, established in 2025, focuses in part on cybersecurity-related misconduct, including regulated entities’ compliance with cybersecurity requirements and public-company cybersecurity disclosures.
The SEC’s 2026 examination priorities also include cybersecurity policies and procedures, governance practices, access controls, data loss prevention, account management, and responses to cyber incidents. This reinforces the need for organizations to maintain accurate, well-documented processes for identifying, assessing, managing, and disclosing material cybersecurity risks and incidents.
Conclusion
Information security laws are becoming a core part of how organizations manage cybersecurity risk. The challenge is not simply knowing which laws apply, but translating different regulatory requirements into security practices that can be consistently implemented and maintained.
For organizations operating across industries or jurisdictions, a fragmented approach can create duplicated controls, inconsistent processes, and gaps in compliance. A common-controls strategy can provide a more practical foundation by establishing core security practices and then addressing the requirements unique to each applicable law or standard.
The most effective compliance programs therefore treat regulatory requirements as part of broader security and risk management—not as separate checklists. Organizations that build this foundation can respond more consistently to changing regulations while strengthening their overall security posture.
Need help building or strengthening your information security compliance program? Talk to Terralogic’s cybersecurity and GRC experts about mapping requirements, identifying control gaps, and building a practical compliance strategy.
Frequently Asked Questions (FAQs)
1. What’s the difference between an information security law and a data privacy law?
Information security laws focus on how organizations protect data and systems through measures such as access controls, encryption, risk management, and incident response. Data privacy laws govern how personal data may be collected, used, shared, and retained. An organization can meet its security obligations while still failing to meet privacy requirements, or vice versa.
2. What information security laws apply to US companies?
It depends on the organization’s industry, location, and activities. Financial institutions may be subject to the GLBA Safeguards Rule and, in New York, NYDFS cybersecurity requirements. Healthcare organizations handling electronic protected health information may fall under the HIPAA Security Rule. Public companies have cybersecurity disclosure obligations under SEC rules, while organizations handling payment card data may need to comply with PCI DSS.
3. Is ISO 27001 a legal requirement?
No. ISO/IEC 27001 is a voluntary, certifiable international standard for establishing and managing an information security management system. Certification can help organizations demonstrate a structured, risk-based security program, but it does not automatically make an organization compliant with laws such as NIS2 or DORA.
4. What happens if my organization is subject to multiple information security laws at once?
This is common for organizations operating across industries or jurisdictions. A practical approach is to establish a common control framework and map applicable laws and standards against it. Shared requirements such as access control, risk assessment, incident response, and security monitoring can be managed centrally, while requirements specific to each regulation—such as reporting timelines or sector-specific obligations—can be addressed separately.
