TL;DR: Security regulations are increasingly being used to drive resilience, trust and budget decisions, according to Semgrep’s comparison of US, EU and UK regulatory models and security frameworks. The real test is whether rules change operational controls and security culture, not whether they simply add paperwork.
NHIMG editorial — based on content published by Semgrep: Comparing security regulations, frameworks and standards for real security outcomes
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should security teams turn regulatory requirements into actual controls?
A: Start by mapping each requirement to a specific control owner, evidence source and operating cadence.
Q: Why do regulations often expose weaknesses in identity governance?
A: Because many requirements depend on accurate identity inventory, accountable access decisions and reliable audit trails.
Q: What do organisations get wrong about breach defence and cybersecurity frameworks?
A: Many teams assume framework alignment is a paperwork exercise completed after an incident.
Practitioner guidance
- Map every rule to a control owner Build a regulatory inventory that maps each applicable obligation to a named owner, the control it depends on, and the evidence required to prove it.
- Translate regulatory language into entitlement rules Convert broad obligations such as MFA, least privilege and audit logging into concrete access policies for human identities, privileged accounts and machine credentials.
- Treat NHI inventory as compliance evidence Document service accounts, API keys, tokens and certificates with owners, purpose, rotation expectations and expiry dates.
What's in the full article
Semgrep's full article covers the regulatory comparisons and framework details this post intentionally leaves at the strategic level:
- How the FTC Safeguards Rule, NYDFS, SEC disclosure and HIPAA differ in operational burden and scope.
- Why GDPR, NIS2 and DORA drive stronger evidence requirements than many patchwork regimes.
- What ISO 27001 and NIST offer teams trying to turn compliance into maturity.
- How UK resilience and consumer-security laws change implementation priorities for regulated firms.
👉 Read Semgrep's comparison of security regulations, frameworks and standards →
Security regulations and frameworks: which ones actually drive maturity?
Explore further
Compliance becomes security only when it changes entitlement behaviour. The article’s central argument is that regulation has value when it forces organisations to implement controls they would otherwise delay, particularly in access, logging and accountability. That is especially relevant to IAM and PAM, where policy language often exists without lifecycle enforcement. The practical conclusion is simple: if a regulation does not alter access decisions, it is unlikely to change risk.
A question worth separating out:
Q: Who is accountable when compliance requirements are missed?
A: Accountability should sit with the business and technical owners of the control, not only with GRC. If a requirement depends on identity governance, then the owners of access policy, privileged access and machine identity lifecycle need clear responsibility for evidence and remediation. Shared accountability without named ownership usually fails under audit pressure.
👉 Read our full editorial: Security regulations are becoming a governance lever, not just a burden