.st0{fill:#FFFFFF;}

The Broken Link In Cybersecurity Nobody Wants To Fix – Is It What You Think? 

 July 19, 2026

By  Jane Frankland

There’s a problem in cybersecurity I haven’t been able to let go of these past few weeks. I’ve been returning to it and looking at it from different angles. To begin, I asked whether we’re solving the wrong problem in cybersecurity. Then, I looked at how we’ve handed software the equivalent of anti-lock brakes, and whether that’s actually made us safer. Then, the crash-test problem, and why safer software won’t come from goodwill, and what happens when you don’t own the brakes – when the off switch sits in someone else’s capital.

Here’s the thread running through all of it, if I pull it tight. Cars didn’t become safe by accident, and they didn’t become safe because manufacturers suddenly wanted them to be.

They became safe because, over decades, every part of a system was made to work together. Independent crash-testing bodies that rated cars and published the results. Regulation that mandated seatbelts, then airbags, then structural standards. Liability that made cutting corners expensive. Insurance that priced in risk. And, the part I want to discuss today – enforcement with real consequences, when a maker fell short. Take any single link out of that chain and the whole thing stops delivering safety. Goodwill was never the mechanism. The working system was.

Which brings me to a question I can’t stop thinking about. In cybersecurity, we’ve been busy building the links. We have standards. We have frameworks. We even have the beginnings of crash-test-style ratings. But there’s one link I’ve come to believe is quietly, badly broken, and a chain is only as strong as that.

Enforcement.

So let me ask my question plainly, the way I’d ask about a car that passed its test but had no working brakes. In cybersecurity, is enforcement actually working? Not the announcements. Not the eye-watering maximum fines in the press release. The enforcement itself. Because I’ve been looking at the evidence worldwide, and I don’t think it is. And I don’t think this is bad luck. I think it’s dysfunction. And it’s the same dysfunction I keep seeing everywhere.

First, the pattern isn’t unique to cyber

I noticed it first somewhere completely unexpected. I’d been watching the coverage of Britain’s waterways where rivers and coastlines are quietly filling with sewage. And what struck me wasn’t the pollution. It was the gap between the rules on paper and what happens in the water. Discharge after discharge, and almost nothing at the other end. No consequence. No cost. No one made to stop.

I mentioned it to one of my sons, who works for a council as a town and country planner. I expected sympathy; I got a wry smile and a knowing laugh. Because in his world it’s the same story in a different hat. Someone builds without permission or ignores their conditions, and more often than not, nothing. The council may act. It usually doesn’t. Enforcement is discretionary, lengthy, risky, expensive. Departments are stripped bare, and a determined developer simply waits out the clock. In England, planning enforcement notices have fallen to their lowest level since records began, with dozens of councils in a single year issuing not one.

That’s when it clicked. This isn’t a cyber problem, or a water problem, or a planning problem. It’s a system problem. We’ve become brilliant at writing rules and announcing penalties, and hopeless at the unglamorous final step of actually making them bite. It’s the crash-test problem all over again. You can rate the car, but if nobody enforces the standard, the rating is decoration.

And once you see that pattern, you cannot unsee it in cybersecurity.

The EU can’t even get its own members to turn up

Let’s start with NIS2, the European Union’s flagship cybersecurity law, which is meant to harden critical infrastructure across the continent. Serious work, serious penalties, with essential entities facing fines up to €10 million or 2% of global turnover.

But here’s the problem. Member states had to write NIS2 into national law by 17 October 2024. When the deadline passed, the European Commission had to open infringement proceedings against 23 of the 27 member states for failing to do it. By May 2025, seven months late, 19 were still non-compliant and had to be sent formal reasoned opinions. A year on, only around half had fully transposed it. Germany, France, Spain, Ireland, some of Europe’s largest economies, still not done.

Think about that for a moment. This isn’t companies dodging the rules. It’s the governments, the very bodies meant to enforce cybersecurity law, failing to enact it. In car terms, it’s as if the regulator wrote a magnificent crash-test standard and then most of the testing centres never opened. When the enforcers can’t meet their own deadline, what’s the deterrent worth to a company weighing up whether to bother?

America named a CISO, then did a U-turn

Now let’s cross the Atlantic, because the US gave us the most dramatic cyber enforcement story we’ve ever had, and then took it back.

In 2023 the Securities and Exchange Commission did something unprecedented. It charged SolarWinds, the company at the centre of the devastating Sunburst supply-chain attack, and named its CISO, Tim Brown, personally. The industry reacted with something close to panic. This, everyone agreed, was the moment accountability got real.

Then, on 20 November 2025, the SEC quietly dismissed the whole thing. With prejudice. No settlement, no penalty, no trial. The courts had already gutted most of the claims in 2024, and after a change in leadership the regulator simply walked away. Cyber related enforcement actions that year fell to their lowest level in over a decade. The rules still technically exist, and companies must report material incidents within four business days, but the most serious attempt to enforce them collapsed, and every boardroom drew the obvious conclusion.

The fines that look enormous, and don’t always stick

“But Jane,” you might say, “what about the GDPR? Those fines are gigantic.” True. Cumulative, the GDPR fines across Europe reached €7.1 billion between 2018 and January 2026, with roughly €1.2 billion in 2025 alone. Real money, real headlines.

But look closer. First, the concentration. Ireland’s regulator alone accounts for around €4 billion of that, about 57% of the total, overwhelmingly a handful of penalties against Big Tech. Strip those out and the picture thins fast. Second, the fragility. In March 2026 alone, Amazon’s €746 million fine and a €15 million penalty against OpenAI were annulled on appeal. And here in the UK, freedom-of-information analysis found the ICO had collected only about a quarter of the value of fines it issued in 2020 to 2021, with roughly 42% of all fines since 2015 still unpaid. A fine issued is not a consequence delivered.

Now, the honest counter-argument

Here’s where I have to be fair, because the strongest case for my view has to face the strongest case against it. And the other side is not stupid.

The ICO changed its approach for defensible reasons. It now issues fewer but far bigger fines against serious breaches. The average has jumped from around £150,000 in 2024 to roughly £1.6 million in 2025, and climbed higher again in 2026, while a single 2025 settlement with Capita hit £14 million. It collects more as a result, because large, solvent firms pay.

But its shift to reprimands rather than fines for the public sector rests on a genuinely hard point. Fining a hospital or a council just recycles taxpayers’ money while cutting the very frontline services those taxpayers rely on. The SEC’s retreat has its defenders too. Many argued that prosecuting a CISO personally would chill the candid internal risk assessment good cybersecurity depends on. And discretion itself exists for real reasons, including proportionality, thin resources, and the need to chase systemic failures rather than one-off accidents.

Every one of those defences is reasonable. I mean that. But here’s why they still don’t add up to a working system.

Deterrence doesn’t run on the intentions of regulators. It runs on the expectations of the regulated. And when you stand back and take in the whole landscape at once, a European law its own governments couldn’t implement on time, a landmark US case dropped after a leadership change, headline fines that are concentrated and frequently overturned, a national regulator that fines less and forgives more, each defensible choice adds up to a deterrent a rational actor can reasonably discount. The individual decisions may be sound but the aggregate signal is that the rules are optional.

Why the gap matters everywhere, including cyber

I want to be careful here, because it would be easy to argue that cyber matters more than the rest. It doesn’t, and the evidence won’t support it. Sewage pollution is not a slow, abstract harm. Heather Preen was eight years old when she died in 1999, two weeks after contracting E. coli on a Devon beach. Surfers Against Sewage has logged more than seven and a half thousand sickness reports in the last five years alone. A friend of mine needed open heart surgery. Unenforced rules have a body count, and it’s not a metaphorical one.

So the point isn’t that cyber is worse. The point is that in every one of these cases the cost of not enforcing lands on someone other than the organisation that broke the rule. What cyber adds is speed and spread. A failure can move through supply chains, customers and shared critical services in hours, which means the people who pay are usually the ones with the least say in whether the rule was followed. That’s precisely the domain where deterrence needs to be most credible. Instead, it may be where the gap between rule and reality is widest.

That’s what makes the car comparison so uncomfortable. The motor industry proves an entire sector genuinely can be made safer, but only when every link holds. Cyber has copied the parts of that system that generate press releases and skipped the part that generates consequences.

The UK’s moment of choice

As I write, the UK’s own Cyber Security and Resilience Bill is moving through Parliament. On paper it’s muscular, with fines up to £17 million or 4% of global turnover, and daily penalties of £100,000 for continuing non-compliance. But the provision I’d actually watch is the least glamorous, a cost-recovery mechanism letting regulators fund their own oversight. Headline maximums are easy. They’ve never been the constraint. Whether regulators are resourced, empowered and willing to collect is the only question that decides whether behaviour changes. “May enforce” has a habit of becoming “won’t enforce” when budgets are thin.

What this means for you

This pattern doesn’t only live in statute books. It lives in organisations, in yours. You can write the policy, run the training, publish the guidelines. But if there’s never a visible, credible consequence when someone ignores them, you haven’t built a control. You’ve built a suggestion. People calibrate to what happens, not to the poster on the wall.

So decide in advance what happens when a rule is broken, and then make sure something actually does. Bound your discretion, so inaction is the thing that has to be justified rather than the default. Give whoever owns the policy the time and the authority to follow up, because a rule nobody has the standing to enforce is just a document. And make consequences visible, because deterrence is a story people tell themselves about what happens if they’re caught, and your only job is to make sure it’s true.

And if you’re reading this thinking you can’t fix any of that from where you sit, you may well be right. Most of us can’t resource a function or rewrite the consequences on our own. But you can name the gap, and you can put it in front of the people who can. Saying out loud that a control is really a suggestion is uncomfortable, and it is also the first thing that has to happen before anything changes.

So, is cyber enforcement working?

No. Not yet. Not in any way a rational actor on the receiving end would recognise. We’ve never been better at writing cyber rules, and rarely worse at meaning them. The car industry showed us it doesn’t have to be this way. Safety has risen because every link in the chain was made to hold. The broken link in ours isn’t mysterious to fix. It’s just unglamorous, which is exactly why it keeps getting skipped.

Now I want to hear from you

I started this run of blogs with cars, and I’m ending it in the same garage, because the lesson is the same. A safety system only works when every part of it works, and right now our enforcement link is hanging loose.

So here’s my question for you. In your world, your organisation, your sector, your regulator, where have you watched a cyber rule that exists on paper but is never truly enforced? And what did that absence of consequence do to how people actually behaved?

Tell me in the comments over on LinkedIn. I read every reply.

Did you enjoy this blog? Search for more blogs that you want to read!

Jane frankland

 

Jane Frankland MBE is an author, board advisor, and cybersecurity thought leader, working with top brands and governments. A trailblazer in the field, she founded a global hacking firm in the 90s and served as Managing Director at Accenture. Jane's contributions over two decades have been pivotal in launching key security initiatives such as CREST, Cyber Essentials and Women4Cyber. Renowned for her commitment to gender diversity, she authored the bestselling book "IN Security" and has provided $800,000 in scholarships to hundreds of women. Through her company KnewStart, and other initiatives she leads, she is committed to making the world safer, happier, and more prosperous.

Follow me

related posts:

Leave a Reply:

Your email address will not be published. Required fields are marked

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}

Get in touch