IAPP Global Summit 2026: Privacy | AI governance | Cybersecurity law

WASHINGTON, DC

30 March-2 April

Back to conference agenda

Cybersecurity Compliance in Europe: Lessons Learned from the First Year

Tuesday, 31 March

09:00 - 10:00 EDT

Intermediate level

BREAKOUT SESSIONCYBERSECURITY LAWDATA SECURITYFRAMEWORKS AND STANDARDSLAW AND REGULATIONREGULATORY GUIDANCESTRATEGY AND GOVERNANCE

European lawmakers have adopted a wave of new cybersecurity regulations that have created a complex compliance landscape. The Network and Information Systems Directive, Cyber Resilience Act, Critical Entities Resilience Directive and other regulatory measures impose stringent security obligations on a wide range of entities operating in the EU. With implementation deadlines already effective and still others looming, multinational companies must act swiftly to ensure compliance. This session will provide practical, real-world insights into the evolving cybersecurity compliance landscape in the EU, drawing from the panelists’ experience managing operational implementation of large-scale compliance projects.

What you will learn: 

  • Understand critical compliance obligations under NIS2, CRA, CER, and country-level requirements. 
  • Gain practical insights into operationalizing these requirements.
  • Explore legal considerations and strategic approaches for global companies to efficiently navigate the evolving cybersecurity framework.

Moderator and speakers

headshot of Jim Dempsey

Jim Dempsey

Lecturer, UC Berkeley Law; Managing Director, Cybersecurity Law Center

IAPP

headshot of Corey Dennis

Corey Dennis

CIPP/E, CIPP/US

Chief Privacy Officer and Assistant General Counsel

Legend Biotech

generic profile silhouette

Natallia Karniyevich

Partner, Cybersecurity

McDermott Will & Schulte