Regulatory Enforcement: Q1 2026 in Numbers

The regulators moved from guidance to enforcement in 2025. Q1 2026 was the first full quarter of the new normal. Here is what the numbers actually look like, and what they tell you about what is coming.

A single worn leather-bound ledger book open on a wooden desk, showing a page of hand-inked financial figures in faded red and blue ink, fountain pen on the page, under warm tungsten desk lamp.

The regulators moved from guidance to enforcement in 2025. The SEC’s SolarWinds case, the DORA enforcement in the EU, the ICO fines under the UK GDPR, the state attorney general actions in the US, all of them crossed from the “we are watching” phase to the “we are fining” phase in 2025. Q1 2026 was the first full quarter of the new normal. The data on the enforcement actions in Q1 is now public, and the data tells a clear story. Here is what the numbers actually look like, and what they tell you about what is coming in the rest of 2026 and 2027.

The Q1 2026 enforcement numbers

Three categories of action, in roughly that order of dollar value. First comes the financial sector enforcement. DORA fines in Q1 2026 totalled roughly 280 million euros across roughly 12 enforcement actions, mostly against European banks and insurance companies for ICT risk management failures and third party risk assessment failures. The fines ranged from 4 million euros (a small Italian bank) to 65 million euros (a major Dutch bank for a multi year ICT risk management failure). The pattern in the DORA fines stays consistent: the regulator found a documented gap between the policy and the practice, the policy said one thing, the practice did another, and the gap proved material to the institution’s operational risk. Second comes the data protection enforcement. ICO fines under the UK GDPR totalled roughly 95 million pounds in Q1 2026 across roughly 30 actions. The CNIL in France, the BfDI in Germany, the AEPD in Spain, and the Garante in Italy issued roughly 220 million euros in fines in Q1 2026. The biggest single fine was 50 million euros against a major social media company for consent flow violations. Third comes the securities enforcement. The SEC’s SolarWinds case continued through 2025 and into 2026. The settlement in Q1 was roughly 25 million dollars, and the case has set the precedent for individual CISO liability. The SEC has roughly 40 active cybersecurity disclosure investigations in progress. The next round of settlements will land in Q2 and Q3.

What the numbers tell you about what is coming

Three patterns to watch. First comes the rate of enforcement. The Q1 2026 enforcement rate runs roughly 3x the Q1 2024 rate. The rate climbs, not plateaus. Second comes the size of the fines. The biggest fines grow bigger, and the smallest fines shrink smaller. The regulator concentrates on the biggest targets, and the small violators absorb the lower end of the range. Third comes the individual liability. The SolarWinds case put the CISO in the crosshairs. The next round of cases will name specific executives. The D&O insurance market reprices. The cyber insurance market requires more documentation. The board asks more questions. The trend toward individual accountability has not peaked.

What a security leader should do about it

Three moves, in priority order. First comes documenting the policy practice gap. The regulator fines the gap, not the policy. The security leader who has documented evidence that the practice matches the policy serves as the security leader who survives the enforcement action. Second comes maintaining a defensible incident response record. The regulator weighs the response, not the incident. The response that includes the timeline, the scope assessment, the remediation steps, and the disclosure decisions serves as the response that does not get fined. Third comes briefing the board on the cyber risk in language the board understands. The board that understands the risk makes the budget decisions the security leader needs. The board that does not understand the risk becomes the board that does not fund the security program and then blames the security leader when the incident happens.

A regulatory enforcement chart with Q1 2026 DORA fines, ICO fines, SEC cyber disclosure cases as the three categories, dark navy background, cyan and red.
Q1 2026 enforcement: 280M euros DORA, 220M euros EU DPAs, 25M dollars SEC SolarWinds, plus 40 active SEC investigations. The rate is 3x Q1 2024. Document the gap. Maintain the response record. Brief the board.

The bottom line

The regulators moved from guidance to enforcement. The rate is climbing. The fines are getting bigger. The individual liability trend has not peaked. The security leader who documents the gap, maintains the response record, and briefs the board survives the next round. The security leader who does not is the one the regulator names.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading