IO has found that only 35% of cybersecurity managers in UK organisations believe their existing compliance model is fully prepared to scale as information security, privacy, resilience, and artificial intelligence requirements expand.
Although 85% of organisations describe themselves as ready for upcoming regulation, 50% of respondents said their model was only mostly prepared and would require adjustment, while 15% expected notable changes to be necessary.
The results distinguish between meeting a known requirement and maintaining a governance system capable of absorbing several overlapping obligations. Cybersecurity, operational resilience, personal data, and artificial intelligence regulations increasingly affect the same systems, suppliers, and decision-making processes.
Human interpretation remains central, with one third of respondents saying oversight is required when complex regulatory requirements are applied to real operating conditions. Automation can collect evidence, monitor controls, and support reporting, but ambiguity and conflicting obligations still require experienced judgement.
Clear executive accountability ranked as the second strongest indicator of genuine compliance resilience, selected by 26% of respondents, while a further 22% identified experienced employee oversight as an important measure.
Chris Newton-Smith, chief executive of IO, said organisations should develop governance and compliance capabilities capable of supporting several frameworks rather than treating each new requirement as an isolated project.
“Automation speeds that up; it doesn’t replace it,” he said. “The organisations that build the human capability, alongside the tools, are the ones ready to scale.”
Industrial compliance crosses operational boundaries
Manufacturers and infrastructure operators face particular difficulty because regulatory obligations extend into production equipment, connected sensors, remote maintenance systems, cloud platforms, product data, and supplier access.
The separation between information technology and operational technology complicates implementation further. IT teams may control corporate networks and business applications, while engineering teams remain responsible for systems designed around availability, safety, and equipment lifecycles measured in decades.
Controls that are routine in an office environment can be disruptive on a production line. Frequent patching may interrupt validated processes, older equipment may lack modern authentication, and shutting down a control system for testing can carry significant operational cost.
Regulatory requirements must therefore be translated into controls appropriate to the site, bringing cybersecurity specialists, engineers, legal teams, quality managers, procurement, and operational leadership into the same governance process.
Supplier relationships add further complexity because manufacturers increasingly depend on software providers, equipment builders, integrators, logistics businesses, and remote service teams. Every connection can create access routes and data dependencies that require assessment and monitoring.
Recent collaboration between e2e-assure and A&O Corsaire has combined operational security with evidence-ready compliance for regulated and critical sectors, reflecting wider demand for systems that can demonstrate control performance rather than simply document policies.
ISO 27001 can provide a common management structure, while related standards extend into privacy, business continuity, and AI governance through ISO 27701, ISO 22301, and ISO 42001.
Alignment can reduce duplicated risk assessments, policies, and evidence requests, although certification does not automatically satisfy every regulation. DORA, NIS2, GDPR, sector rules, customer contracts, and emerging AI legislation retain different scopes, reporting duties, and enforcement mechanisms.
Automation can map controls across several frameworks, collect evidence from technical systems, and identify missing reviews or overdue actions. Human oversight remains essential where obligations are ambiguous, operational consequences must be judged, or several control requirements conflict.
Executive accountability becomes decisive when compliance requires capital investment or production changes. A cybersecurity manager may identify that an unsupported control system creates unacceptable risk, but replacement can involve shutdown planning, recertification, procurement, and approval from equipment suppliers.
Scalable compliance depends on whether those decisions follow an established route. Organisations that rebuild their response for every audit, regulation, or customer assurance request repeatedly consume specialist time and often produce inconsistent evidence.
A more durable model maintains a common control library, clear ownership, reliable records, and a process for assessing new obligations against existing arrangements. Additional requirements can then be absorbed through controlled change rather than emergency remediation.
The research shows that general confidence remains considerably higher than confidence in scalability. As regulation accumulates, organisations able to connect technical controls, operational risk, evidence, and executive decisions will adapt with less disruption than those relying on periodic compliance exercises.




