What Deregulation Means for Data Protection and Cybersecurity
Skip to content

What Deregulation Means for Data Protection and Cybersecurity

Regulations are crucial for information security strategies in an increasingly interconnected and interdependent digital world. Data and cybersecurity regulations establish baseline security requirements, promote accountability, and guide stakeholders in safeguarding sensitive information. But what happens when cybersecurity requirements are rolled back or relaxed?

Deregulation, while often aimed at reducing overhead for small businesses and startups, can significantly impact how federal agencies, financial institutions, and the private sector approach cyber risk management and cybersecurity practices.

This article explores the implications of deregulation for cybersecurity, the potential risks, and how organizations can stay resilient in a less regulated ecosystem.

Why deregulation typically happens

Deregulation is often pursued to:

  • Streamline compliance processes and reduce operational costs.
  • Encourage innovation in fields like artificial intelligence and information systems.
  • Enhance competitiveness across healthcare, financial services, and other critical infrastructure sectors.

While these goals can have economic benefits, deregulation may inadvertently weaken cybersecurity safeguards if organizations consider mandates and directives as their primary motivation for security measures.

The cybersecurity risks of deregulation

When cybersecurity regulations are loosened or eliminated, several risks can arise:

1. Decreased security baselines

Some service providers may reduce their investment in information security without mandatory cybersecurity requirements. This creates a potentially inconsistent cybersecurity landscape across industries, leaving gaps that can be exploited by cyber attackers.

2. Increased supply chain risks

Many regulatory frameworks require vetting third-party providers for cybersecurity safeguards. Deregulation may lead to less oversight, increasing the risk of supply chain vulnerabilities and cyber incidents affecting critical infrastructure.

3. Compliance vs. security mindset

Organizations that rely heavily on regulatory compliance frameworks may deprioritize cyber risk mitigation once cybersecurity regulations are relaxed, exposing themselves to threats like ransomware and unauthorized access.

4. Data privacy concerns

Looser privacy laws and amendments can undermine data privacy, exposing sensitive information to breaches and cybersecurity incidents.

Cybersecurity under different administrations

Deregulation trends have varied under different U.S. administrations:

  • Second Trump administration: Executive orders sought to reduce federal cybersecurity requirements for specific sectors. Donald Trump emphasized cutting bureaucratic red tape but faced criticism over potential risks to national security.
  • Biden administration: Focused on strengthening cybersecurity practices with directives targeting federal agencies, financial institutions, and the private sector. Recent efforts include collaboration with CISA, law enforcement, and the Department of Homeland Security to address cyber threats.
  • First Trump administration: Took a mixed approach—initially emphasizing deregulation, but later issued the 2017 Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. This required federal agencies to adopt the NIST cybersecurity framework and improve cyber resilience.
  • Obama administration: Treated cybersecurity as a national security priority. Introduced the Cybersecurity National Action Plan (CNAP), expanded public-private partnerships and elevated the role of the Department of Homeland Security in national cyber coordination.
  • State-level action: States like New York have enacted stricter cybersecurity regulations for financial services, emphasizing robust risk management, third-party oversight, and timely cyber incident reporting.

Why cybersecurity should go beyond compliance

Compliance does not always result in robust cybersecurity safeguards. While regulatory frameworks provide a baseline, effective risk management requires proactive measures beyond meeting the minimum regulatory requirements. Organizations with a security-first mindset will always be better prepared to address known and unknown cyber threats.

Strategies for staying secure amid deregulation

Even in a deregulated environment, maintaining strong cybersecurity practices is essential:

1. Conduct regular risk assessments

Identify vulnerabilities in information systems and prioritize mitigation strategies to address cyber risk effectively.

2. Prioritize third-party and supply chain risk management

Implement thorough vetting for providers and stakeholders to prevent cyber incidents affecting your suppliers and critical infrastructure.

3. Adopt industry best practices

Align with frameworks like NIST and adhere to CISA recommendations to uphold robust cybersecurity safeguards.

4. Foster a security-first culture

Educate employees on cyber risk, information security, and the importance of safeguarding against cyberattacks and unauthorized access.

5. Leverage advanced security solutions

Utilize solutions such as data loss prevention (DLP), enterprise digital rights management (EDRM), quantum-resistant encryption, and automated risk management tools to protect against cyber threats.

How Seclore can help

Deregulation doesn’t have to mean diminished cybersecurity. Seclore provides comprehensive data-centric security solutions that enable organizations to persistently protect sensitive data across information systems and throughout their supply chains.

With robust cyber risk solutions and data privacy controls, Seclore helps organizations maintain security amid changing regulatory frameworks.

Conclusion

While deregulation may promote operational flexibility, it should never come at the cost of data and cybersecurity at your organization, including data shared with third parties. Organizations must remain vigilant, leveraging risk management strategies, adhering to best practices, and collaborating with federal agencies, law enforcement, and CISA to mitigate evolving cyber threats.

With the right approach, businesses can protect their sensitive and private data and maintain operational resilience in any regulatory environment.