Regulatory compliance is a foundational driver of security design, requiring IT professionals to align their implementations with applicable laws based on industry, geography, and data handling practices. Understanding these obligations is essential for protecting consumer data and meeting organizational security standards.
Regulations & Compliance
One of our big drivers for the requirements of anything that we're designing, and security that we're implementing, is the laws and regulations and compliance.
Small and medium-sized businesses have a bit of a problem, in that a lot of times they have tight budgets and they're trying to make ends meet to make their company profitable. What are they trying to do? They're trying to increase the revenue, so they have increased revenue. They're trying to decrease costs and expenses so they can increase their profit.
And then we as security professionals come along and tell them all these things that they need to do, all this money that they need to spend in order to increase security. This is problematic for that company. They don't want to do it because it costs a lot of money.
This is problematic because we are the customers that are going to these businesses and utilizing these services, handing over our data, handing over our credit cards, handing over information to them. We are entrusting them with this, and they're not willing to spend money on security. This has been a big problem with certain companies, that they won't spend it, yet they are housing our information and our data. And this becomes problematic.
What's happened is that the amount of attacks has gone up. In response to that, government agencies and different credit card processing companies and different things have been put into place that said to these companies, no, you've got to do something different. You've got to put in laws and regulations.
So that's what's happened. We see more laws and regulations that are out there helping protect the consumer and making sure businesses are putting in the proper time and attention into security to make things happen. So now there's more and more laws and regulations that are being put into place to help protect us as consumers, but us as IT professionals have to now implement that into the organizations that we work for. We need to make sure that they're secure.
There's more and more laws and regulations that we have to comply with, based off of maybe where we're doing business. For instance, I'm in the United States, so then I have to make sure that I'm complying to those laws. If I'm selling to people, for instance, over in the European Union, I have to follow GDPR. So I don't just follow my laws and regulations where I live, but wherever my data is being stored at, wherever my customers are at, I have to follow all of that as well.
There's also sector specific regulations that I have to follow. If I'm in some sort of health care, or maybe I'm in finance, or maybe I'm in education, then there are laws and regulations that I have to follow in accordance to those as well.
So there are different laws and regulations that I need to make sure are incorporated into my security architecture and how I roll things out.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →