This month's newsletter focuses on three shifts that are redefining how organisations must think about protection.
The language of cybersecurity is changing. The regulatory landscape for data is tightening. And the insurance many organisations rely on may not respond the way they expect.
The common thread is assumption.
Organisations are assuming that familiar terminology still applies. That data stored abroad is compliant. That a policy purchased provides cover. In each case, the gap between assumption and reality is where exposure lives.
2026 demands a more deliberate approach. Not more technology. More clarity about what you own, where your data sits, and what your obligations actually are.
The term cybersecurity has served its purpose.
For years it has been the organising concept for how organisations think about digital risk. But in 2026, it has become too broad to be actionable and too associated with technology investment to drive the behaviours that actually reduce risk.
Cyber hygiene is the more useful frame.
Where cybersecurity implies a programme, a budget, or a project, cyber hygiene implies a practice. It is the set of consistent, repeatable behaviours that keep an organisation clean. Patching systems on schedule. Managing access carefully. Training staff regularly. Monitoring continuously. Assuring continuously. Reviewing configurations as environments change.
None of these are new. What is new is the recognition that technology alone does not deliver them.
The majority of incidents investigated today are not caused by sophisticated attacks against well-defended organisations. They are caused by basic failures:
These are not technology failures. They are hygiene failures.
The shift in language matters because it shifts accountability. Cyber hygiene is not something the IT function owns on behalf of the organisation. It is something the organisation practises across every function, every team, and every individual with access to systems or data.
Leadership sets the standard. Operations maintain it. Governance validates it.
Organisations that have made this shift report a meaningful change in how risk conversations happen at board level. When the question moves from what have we invested in, to what are we actually doing every day, accountability becomes clearer and gaps become harder to ignore.
In practical terms, cyber hygiene means:
None of this requires a large budget. It requires discipline, ownership, and consistency.
The threat landscape in 2026 has not become less complex. But the organisations suffering the most significant incidents are not losing because attackers are more sophisticated. They are losing because the basics were not in place.
The organisations that will manage risk most effectively in 2026 are not those with the largest security budgets. They are those that have embedded consistent, disciplined practices into how they operate every day. Cybersecurity asks what you have invested. Cyber hygiene asks what you are actually doing. In 2026, the second question matters more.

The conflict in the Middle East has brought a quiet but critical issue into sharp focus.
During the disruption, data sovereignty became an operational emergency for organisations with data stored in the region. When data centres were destroyed data sovereignty law caused an operational issue. Normally, data cannot leave the UAE. In the UAE, regulators authorised a temporary exception to allow AWS to restore data to its Frankfurt infrastructure. It was an extraordinary measure taken under pressure, and it exposed something that most organisations have not adequately addressed.
If you do not know where your data lives, you cannot know what rules apply to it.
Data sovereignty is the legal principle that digital data is subject to the laws, regulations and governance frameworks of the specific country or jurisdiction in which it is collected, processed or physically stored. For most organisations, this has been a compliance consideration. The events of recent months have demonstrated that it is also an operational and resilience consideration.
Cloud platforms operate across global infrastructure. Data may be stored in one jurisdiction, processed in another, and replicated to a third. Without deliberate configuration and governance, organisations may be holding data in locations subject to:
This is not a theoretical risk. It is a practical one with direct consequences:
What is required is not complexity. It is clarity. Organisations need to know:
Data sovereignty is no longer a concern only for multinationals or regulated sectors. Any organisation using cloud platforms is making decisions about where data lives, whether deliberately or by default. The organisations that understand their data landscape will be able to respond, adapt, and recover. Those that do not will discover the gap under pressure.

The cyber insurance market has matured rapidly. Policies are more widely held than at any point previously, and awareness of cyber risk as an insurable exposure has grown significantly.
But a policy is not the same as cover.
Claims are being declined. Not because the incidents are not real, but because the controls that insurers expected to be in place were not. The gap between what organisations believe their policy provides and what it actually requires is one of the most significant and least discussed risks in the market today.
Insurers have responded to rising claims volumes by tightening requirements. Policies now routinely include conditions around:
These are not optional enhancements. They are conditions of cover.
If those controls are not in place at the time of an incident, the insurer has grounds to challenge or decline the claim.
This creates a specific and practical risk for organisations that purchase a policy without understanding what it demands of them. The policy is in place. The premium is paid. The assumption is that the management of the risk has been transferred. But if the underlying controls have not been maintained, the transfer has not occurred. The organisation carries the risk and believes it does not.
We have seen claims denied because the insured company had not disclosed that the operation of controls was by a third party, for example an IT support company or MSP (Managed Service Provider).
What is required is straightforward but often overlooked:
Cyber insurance is a valuable component of a resilience strategy. It is not a substitute for one. A policy that does not respond at the point of claim provides no protection. The organisations that will benefit from their cover are those that understand what it requires and maintain the controls to support it. Do not assume the risk is transferred until you have confirmed the conditions are met.

