No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

5 Upcoming Trends in Compliance

Taking on Heightened Security and Privacy Concerns

by Adam Shnider
January 21, 2019
in Compliance, Featured
man in suit manipulating compliance technology on virtual screen

2018 demonstrated that cyber threats are far from being tackled. Coalfire’s Adam Shnider discusses how in 2019, we can expect compliance and governmental bodies to set the bar even higher to protect data.

While it may appear that enterprise security teams and compliance frameworks have stepped up their game to address cybersecurity risk, this past year evidenced the fact that cyber threats are as present as ever. We predict the following compliance trends will rise to the top in 2019:

1. Compliance in the Cloud

For years, companies have been diving deeper into the cloud, moving more critical functions over for the scalability, efficiency, effectiveness and usage-based pricing models it affords. Yet many enterprises have been hesitant to move functions requiring security compliance into cloud solutions. In 2018, we saw more companies get comfortable leveraging the tools, features and functions native to cloud service provider (CSP) offerings, moving more regulated functions to cloud-based services. Expect this trend to continue and escalate in 2019 as CSPs demonstrate their high level of security and compliance expertise in their native environments.

It will not stop at moving the functions, though: organizations that move to the cloud to really leverage the benefits will be re-engineering their technology stack to take advantage of the elasticity that the cloud provides, which requires a whole new skill set to deploy infrastructure as code, and doing this with security in mind will be an absolute necessity for protecting data and also meeting compliance requirements.

2. Privacy Gets Hotter, Merges with Security Efforts

Before companies mined and shared customer data for targeted marketing and other uses, security efforts addressed privacy concerns by building security controls to ensure the confidentiality of data (as a part of the Confidentiality, Integrity, and Availability [CIA triad] charter of cybersecurity). Once data sharing and big data analytics became a modus operandi and individuals’ desire to have their data deleted and “forgotten” was supported by regulations such GDPR, cybersecurity measures didn’t go far enough to address privacy.

Today, privacy continues to heat up globally with new regulations in Brazil and at the U.S. state level with regulations like the California Consumer Privacy Act and others likely on the horizon both at the state and federal level. The lines between security and privacy are blurring yet again; in meeting GDPR, companies must demonstrate adequate security measures to protect consumer data. In meeting compliance regulations, such as GDPR, many of our customers are taking the additional step of addressing all relevant privacy and security regulations simultaneously. Expect to see privacy regulations continue to expand in 2019 and security and privacy to continue to merge as these regulations not only focus on the confidentiality of the data, but also the right of the consumer to gain access to their data (availability) and ensure its accuracy (integrity), as well as the right to be forgotten.

3. Automation

Along with the move to the cloud and building infrastructure from code, companies will look to automate the validation process by embedding ways to gain visibility into the routine, repeatable and predictable parts of compliance into their architectures. This will allow companies to understand their security in these areas on an ongoing basis and also help streamline the validation process by reviewing dashboards and output from the environment rather than performing manually intensive sampling reviews that are becoming much less relevant and effective as environments are becoming more dynamic with newer technologies. By embedding automated dashboards into the enterprise security monitoring architecture, organizations can not only streamline their annual compliance efforts, but also have real-time visibility into their security status.

4. Simplification of Assessments

“Audit fatigue” isn’t just a catchy marketing phrase, it’s a reality for many enterprises. Many organizations today have to comply with multiple regulations and requirements, and as companies continue expanding into new regulated markets, they will be faced with new compliance frameworks — and it is likely to get even more complex (who would have thought 10 years ago that large retailers would be selling medical services and requiring HIPAA assessments?).

Conducting assessments and compliance cycles separately is not only time-consuming, it’s incredibly inefficient considering the many overlapping operational components that exist to manage the systems that support each set of data across the frameworks. In 2019, look for enterprises to align their assessment and compliance cycles, and expect a single assessment to be performed that can cover all of the requirements at one time for greater efficiency, cost savings and improved resource usage, allowing enterprises to focus the lion’s share of their year on other business drivers.

5. Emerging Tech Meets Compliance

As emerging technology goes mainstream, regulatory bodies begin to increase their interest in understanding the risk and determining changes to existing or new compliance requirements. We are at the cusp of seeing regulation around emerging tech, such as IoT, blockchain and artificial intelligence (AI). NIST recently released the draft report, “Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks,” to help federal agencies understand and manage device cyber risks. It is the first of a series of IoT documents; more will follow and become more specific on various aspects of IoT risk. We also closed out 2018 with the announcement of a new U.K.-based voluntary cybersecurity standard for the manufacturers of autonomous vehicles. We predict 2019 will see more orchestrated efforts to employ security standards on these technologies to ensure a baseline of controls is applied to their implementations in regulated environments.

Tags: Artificial Intelligence (AI)Big DataBlockchainCalifornia Consumer Privacy Act (CCPA)Cloud ComplianceData AnalyticsGDPRInternet of Things (IoT)
Previous Post

3 Key Compliance Trends for 2019

Next Post

A Cybersecurity Compliance Crystal Ball For 2019

Adam Shnider

Adam Shnider

Adam Shnider is the Executive Vice President of the Commercial Services at Coalfire. He has extensive experience in information security leadership, audit and assessment planning, enterprise risk management and helping clients meet compliance readiness requirements. He holds numerous industry certifications, including Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM).

Related Posts

rubiks cube

Put the General Counsel in Charge of AI Strategy

by Eric Dodson Greenberg
August 5, 2026

The conventional play for enterprise AI strategies is IT leads, committees advise, everyone weighs in. That produces strategies that live...

idea light bulb coming out of computer

The Line Between Offloading Work to AI & Surrendering Your Thinking

by Robert A. MacKenzie and David Reiss
August 4, 2026

A practical framework for responsible use of generative AI lays the foundation for managing hallucinations and overreliance

workday building sign

What the Workday Case Reveals About AI Hiring Records

by Rohan Sharma
August 4, 2026

A May discovery order can provide guidance for compliance professionals when it comes to retention of evidence with AI hiring...

computer and human arms at laptop

The Finance Team of 2030 Won’t Be Shaped Like Today’s

by Markus Hofbauer and Alissa Lugo
August 3, 2026

Forget the pyramid structure of your finance function; tomorrow’s is a diamond

Next Post
hands around glowing crystal ball

A Cybersecurity Compliance Crystal Ball For 2019

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights