Cybersecurity rules written for Europe’s biggest institutions in recent years are exerting pressure on thousands of smaller firms to tighten up their own digital defenses.
As new regulations like NIS2 and DORA ripple through industries, even modest suppliers must step up in order to keep contracts and customers, driving a kind of “trickle-down security,” where compliance pressure at the top strengthens resilience across the entire economy.
That’s what cybersecurity experts and industry analysts say they’re observing across the EU and the UK, a region that—despite its own internal rivalries and bureaucratic rankling—has managed to pass a variety of international rules and frameworks in recent years in an effort to level-set cybersecurity protocols across borders.
While each new act or standard may have its flaws and fair share of detractors—two-thirds of cyber professionals cite the growing volume and complexity of regulations as a major obstacle to compliance, says the World Economic Forum—this legislation stands in stark contrast to the more muted efforts coming from the (by and large) regulation-averse U.S. And as this new trickle-down trend reveals, enterprises that look beyond the complexity and prioritize IT compliance reap dividends down the line.
Cybersecurity observers point to regulations aimed at critical sectors and enacted in recent years, such as…
- NIS2—With its focus on securing essential services and critical infrastructure across EU member states, this update of the Network and Information Security (NIS) Directive was adopted in 2023 and transposed into law in 2024.
- DORA—The Digital Operations Resilience Act, designed to bolster resilience of financial institutions, launched in 2023.
- The EU’s AI Act—The world’s first law governing artificial intelligence was adopted in 2024.
- GDPR—The General Data Protection Regulation, touted as the world’s toughest data privacy legislation, launched in 2018.
- UK Cyber Security and Resilience Bill—A framework set to modernize support for critical national infrastructure and strengthen oversight of supply chain risk, currently winding its way through Britain’s Parliament and anticipated to pass into law sometime in 2026.
…which have all begun to exact a subtle (and sometimes not-so-subtle) effect across the entire cyber supply chain.
The impact is reaching critical mass and extends well beyond Europe: U.S. and other non-EU enterprises are likewise required to consider these regulations when operating in the European market.
“It’s not just top-down; it’s cascading through the entire supply chain,” says Marc Vael, president of the Belgian chapter of the European Cyber Security Organisation (ECSO) CISO Community, the largest independent public-private federation for chief information security officers in Europe. “Not just third parties,” he adds, “but fourth and fifth parties, too.”
Pressure points: when cyber regulations get rigorous
Each of the new regulations brings its own brand of pressure.
“It’s not just top-down; it’s cascading through the entire supply chain. Not just third parties, but fourth and fifth parties, too.”Marc Vael, President, Belgian chapter of the European Cyber Security Organisation (ECSO) CISO Community
NIS2 expands on the original directive to cover a wider array of essential and important entities. DORA adds rigorous incident reporting, governance, and third-party risk requirements to the financial services sector. The AI Act and GDPR go further still, layering on demands for transparency and accountability. Failure to comply isn’t just a matter of fines. In many cases, board members can be held personally liable, and organizations risk real reputational damage or lost business.
“In practice, many companies start by asking: Do we meet the minimum to be compliant?” says Edwin van den Heuvel, director ServiceNow solution architect at Tanium, a leading global cybersecurity solutions provider (and publisher of this magazine). “They get a paper-based audit from a big advisor, and then realize they’re still flying blind about what critical assets they even have.” Cyber resilience, it turns out, starts with 100% visibility of connected devices on your network. Once you know what you’re running, you can begin to protect it.
Once companies see the gaps, they begin mapping what’s connected, what’s critical, and what’s at risk, van den Heuvel notes.
Cyber regulations and the chain reaction of accountability
But regulations do more than motivate internal audits—they reshape external relationships.
“The real question is: How do suppliers manage their own subcontractors? Cybersecurity isn’t just about your own house; it’s about the keys you hand to everyone else.”Sven Hutse, CISO and CIO advisor, Birkin&Barre
Regulated companies, under pressure themselves, increasingly demand more from their suppliers. They send questionnaires—sometimes short, sometimes containing hundreds of items—to business-partner inboxes across the economy. In a given year, the CISO of a midsize company may have to answer questionnaires from over 160 customers, totaling more than 8,000 individual queries, Vael estimates. “It’s overwhelming,” he says. “You either answer one-off, or you proactively publish certifications, audits, or trust center documents on your site.”
Observers like Vael are seeing that kind of proactive disclosure of cyber safeguards more often, as the pressure from above nudges partners toward tighter defenses and greater transparency.
Suppliers who can’t keep up may find themselves dropped. And the expectations don’t stop there.
“The real question is: How do those suppliers manage their own subcontractors?” says Sven Hutse, CISO and CIO advisor at consultancy Birkin&Barre. “Cybersecurity isn’t just about your own house; it’s about the keys you hand to everyone else.”
Van den Heuvel confirms that dynamic: “The moment you don’t meet the requirements as a supplier, they simply say we’re not renewing your contract.” That commercial pressure ensures that even small vendors start meeting standards originally meant for critical sectors.
This push for accountability creates a new kind of digital ecosystem, one where compliance is contagious. As major firms impose higher security standards downstream, their vendors (and their vendors’ vendors) start to adapt. The effect resembles what epidemiologists might call digital herd immunity.
“Throughout Europe, you see fewer and fewer companies where the front door is wide open,” says Vael. “Five years ago, you’d always find something wrong. Now, it’s the exception.” He encourages organizations to use open-source intelligence to check the honesty of subcontractors in filling out the questionnaires mentioned earlier.
Supplier scrutiny, from SolarWinds to supermarkets
Incidents like the 2020 cyberattack on software supplier SolarWinds, a breach that compromised security at 18,000 organizations, forced regulators and major enterprises to expand supply chain scrutiny, making smaller firms strengthen their own defenses. Each breach and its consequences tighten the web of expectations.
“The moment you don’t meet the requirements as a supplier, they simply say we’re not renewing your contract.”Edwin van den Heuvel, Director, ServiceNow Solution Architect, Tanium
And it's not just tech firms that are vulnerable when it comes to their supply chains. Van den Heuvel, who is based in Amsterdam, recalls a ransomware incident at a Dutch transport company that halted cheese deliveries to supermarkets and disrupted the Netherlands’ food logistics network.
“Having no cheese on the shelves, in the Netherlands, is practically a national emergency,” Van den Heuvel jokes. But the lesson, he adds, is serious: Resilience now depends as much on your suppliers’ cybersecurity as on your own.
The cheese caper isn’t a one-off—a wave of cyberattacks hit “cold chain” deliveries of perishables in the EU and UK this year, and analysts anticipate they may soon strike the U.S. These kinds of incidents underscore the fragility of interconnected systems. “Companies want to be secure, but they rely on others for so much,” says Vael. “The trust has to go both ways, upstream and downstream.”
Maintaining that trust is expensive and resource-intensive. Smaller businesses risk being excluded not because they don’t care about security, but because the cost of proving it is too high. Hutse acknowledges the challenge: “Not every SME [small to midsize enterprise] has the means to get an ISO 27001 certification,” says Hutse, referring to a leading international standard for information security management systems. “That’s why classification is important—different levels of scrutiny based on the type of data or access involved.”
In other words, without proportionality, regulation could become self-defeating. The EU’s AI Act, for one, addresses this idea with its risk-based framework governing the development, deployment, and use of AI systems in Europe. (The rules, which take effect in stages, roll out through 2026.) “If you’ve got an AI system that is going to touch Europe in any way, you need to be thinking about the EU AI Act,” said Gretchen Scott, a technology partner at Goodwin Law, in an interview with Focal Point last year, when the law was adopted by the European Parliament. Scott, who is based in London, and other attorneys encourage enterprises to assess their AI system’s risk level based on the four levels in the regulation.
[Read also: Need to comply with the EU’s AI Act—or aren’t sure? Start with your risk level]
Security leaders can take the same approach when they look down their supply chain. Classifying suppliers by risk, as Hutse advises, keeps the ecosystem both secure and inclusive.
Ultimately, companies are balancing between two pressures: the cost of implementing cybersecurity and the cost of not being trusted. “You either spend now, or you lose business later,” says Vael.
Cyber regulations and the role of tools
Cybersecurity advances like autonomous endpoint management, which fuses automation with endpoint management tools, can help companies keep control of the expanding attack surface. “You don’t just need an inventory,” says van den Heuvel, “you need a living inventory, something continuously updated.”
“You don’t just need an inventory, you need a living inventory, something continuously updated.”van den Heuvel
But even the best tools can’t prevent the oldest vulnerability in the book: human behavior. Experts urge companies to provide ongoing awareness training and education, yet many businesses fall short. “Fewer than half of companies have structured training programs for cybersecurity,” says Hutse. “And over 90% of successful attacks involve human error. We know this, and yet we still underinvest in people.”
Van den Heuvel argues that DORA’s incident-reporting requirements could change that mindset by forcing organizations to practice, not just promise, collaboration: “Companies need to have a process that says: There’s an incident, we assess the impact, and we report it externally. That makes it possible to warn other players.” That cooperative reflex, now embedded in DORA, may be one of the regulation’s quietest but most powerful ripple effects.
[Read also: Solution brief—unpacking DORA and ensuring digital operational resilience]
That awareness needs to stretch all the way to the top. Boards are beginning to pay attention, not just because of regulations, but because their own liability is now on the line. Still, some execs see compliance as a checklist rather than a strategic approach to risk management. “The real goal isn't just to tick boxes,” says van den Heuvel. “It’s to be operationally resilient. If something goes wrong, how fast can you detect, contain, and recover?”
And how fast can you inform others? DORA, in particular, emphasizes the need for quick reporting to regulators, but also to industry peers. “If you get hit, the others in your ecosystem deserve a warning,” van den Heuvel adds.
Toward a more secure digital economy
As with sustainability, where large companies have driven greener practices across their networks, cybersecurity is entering a phase where responsibility radiates outward. Many businesses aren’t waiting for laws to tell them what to do. They're acting out of market pressure, reputational risk, and, yes, common sense.
“Perfect security doesn’t exist. But regulations, audits, and peer pressure all make you think... And thinking is half the battle.”Vael
“Many companies are already taking action on their own,” says van den Heuvel. “You don’t need laws or regulations for that.” Hutse draws the same comparison to sustainability—many firms began improving their environmental footprint long before regulation forced them to. The same cultural shift, they argue, is now happening with cybersecurity.
“Perfect security doesn’t exist,” Vael admits. “But regulations, audits, and peer pressure all make you think. About backups, onboarding, training, third-party risk, business continuity. And thinking is half the battle.”
[Read also: Employee security training is way overdue for a shake-up—here’s the fix]
In this new landscape, it’s not just about compliance; it’s about trust. Trust that your suppliers won’t expose you. Trust that your tools are up-to-date. Trust that your people won’t plug a compromised device into the cash register. Cybersecurity may start at the top, but it doesn’t stop there. It trickles down, through forms, audits, contracts, and conversations, until even the smallest firm in the chain starts asking: what do I need to protect, and how?
In the end, the cheese must be delivered. And in the digital economy, that means everyone plays a part in keeping the supply chain secure.
