The compliance shift puts governance, supplier oversight, incident response, and sanctions at the center of how companies are expected to manage cyber risk.