Regulators across the 50 states are applying a higher and more elaborate standard for “reasonable cybersecurity” than in prior years. Certain issues remain key enforcement priorities while state AGs and sectoral regulators are also scrutinizing routine practices such as logging, alert monitoring and vulnerability patching more closely. This final article in a three-part series published in collaboration with IAPP shares leading defense practitioners’ advice on how companies can address the investigators’ sharper probes of foundational cybersecurity measures. It also illuminates the emerging impact of AI issues on enforcers’ interrogation of companies. Part one, authored by the managing director of IAPP’s Cybersecurity Law Center, examined breakthrough state legislative developments gaining force in 2026. Part two presented recommended steps companies can take to prepare for regulators’ initial post-incident questions. See “For the First Time, Verizon Data Breach Investigations Report Finds Exploitation of Vulnerabilities a Top Threat” (Jul. 29, 2026).