< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles

UK regulator secures AI firms' data protection pledges

🔐 Ten major AI firms including Amazon, Google, Microsoft and OpenAI have committed to strengthen UK data protection measures after guidance from the Information Commissioner’s Office (ICO). The ICO’s report on agentic AI urges clearer transparency, lawful bases for processing, stronger rights mechanisms and robust safeguards. The regulator has launched a six-week call for evidence and warned it will intervene where organizations expose people to avoidable harm.
read more →

Agencies Warn to Accelerate Post‑Quantum Migration

🔒 Europe’s Europol and the US GAO have issued reports urging rapid action on post‑quantum cryptography (PQC) due to the impending risk from cryptographically relevant quantum computers. The US GAO found agencies lack inventories, funding plans and testing for PQC, while Europol highlighted risks from harvest‑now decrypt‑later attacks and threats to cryptocurrency wallets. Both recommend upgrading protocols, adopting hybrid PQC approaches and prioritizing inventory and testing.
read more →

OT Coalition Urges CISA to Mandate Federal OT Security

🔐 The Operational Technology Cybersecurity Coalition (OTCC) urged CISA to issue a binding operational directive requiring mandatory OT security across federal civilian agencies, citing lack of minimum practices and limited visibility into risks. The report highlights OT in over 8,000 GSA-managed facilities and follows a GAO finding that most agencies missed OMB inventory requirements. The proposed directive would set baselines for asset inventory, segmentation, remote access, configuration, incident preparedness and recovery.
read more →

Italy fines IQVIA €7M for inadequate data anonymization

🔒 Italy's Data Protection Authority fined IQVIA €7 million over insufficient anonymization and data-processing practices affecting about one million patient records. The GPDP found that pseudonymous codes plus detailed health and location data could enable re-identification, and that some records included full personal identifiers. Authorities also cited lack of legal basis, failure to inform patients, and missing retention policies, ordering compliance within 120 days.
read more →

MI5 warns UK academics aided Chinese MSS research

🛡️ MI5 has warned that over 100 academics linked to U.K. institutions have contributed to research projects funded by the China General Technology Research Institute (CGTRI), which the agency assesses as a front for the Chinese Ministry of State Security (MSS). The alert cautions that CGTRI-backed research in AI, cybersecurity, covert communications, and steganography directly enhances MSS espionage capabilities. U.K. universities are urged to review collaborations and funding sources immediately, with potential prosecution under the National Security Act 2023 for continuing material assistance.
read more →

EU Cyber Resilience Act reshapes vendor security baseline

🔒 The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, creating an EU-wide product-security law that applies even to non-EU companies. Experts warn the requirement effectively ends manual vulnerability triage, forcing vendors to automate linkage between SIEMs, SBOMs, KEV alerts, asset inventories, and other telemetry. The regulation is expected to elevate secure-by-design practices, test operational resilience, and reshape global technology markets much like GDPR did for data protection.
read more →

Preparing Governments for Interconnected Cyber Risk

🔒 The Microsoft Digital Defense Report finds government agencies were the most impacted sector for cyber threats between July 2025 and June 2026, with 27% of observed activity. The post highlights rising dwell time, increased phishing-driven intrusions, and the expanded risk from compromised credentials. It recommends five priorities for governments, including cross-sector coordination, secure-by-design AI practices, and robust information sharing to strengthen resilience.
read more →

White House secures voluntary AI safety accord

📄 The White House has obtained a voluntary safety commitment from six leading AI firms, who agreed to internal controls, independent audits and board-level oversight for frontier models. President Trump and the executives signed the White House Accord on Super Intelligence on September 29. Signatories include leaders from Google, Anthropic, Meta, OpenAI, xAI and NVIDIA. The accord outlines four layers of controls and calls for regular meetings to develop standards and best practices.
read more →

CISA publishes election security plan ahead of 2026

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) released an Election Infrastructure Security Plan on September 24, 2026, to guide federal, state, and local bodies in mitigating cyber and physical threats ahead of the November 3 midterm elections. The plan outlines risks to physical assets and ICT systems—including voter registration databases and voting machines—and recommends measures such as harmonized patch management, paper ballots, MFA, continuous monitoring, and insider-risk mitigations. CISA also detailed no-cost services like tabletop exercises, penetration testing, vulnerability scanning, and regional coordination to help election stakeholders strengthen defenses.
read more →

UK shifts to service-led cybersecurity governance

🔒 The UK government is moving from top-down mandates to centrally built, user-focused cybersecurity services for its federated civil service. Breandán Knowlton-Hung, Deputy CISO, described how a 2025 NAO report revealed weak implementation of the 2022 strategy and capacity shortfalls, prompting a pivot to polycentric governance. The approach prioritizes useful central services, cheaper adoption, and reserved central authority for systemic risks.
read more →

EU auditors flag fault lines in bloc cyber resilience

🔍 The EU Court of Auditors has identified significant shortcomings in the bloc’s cyber incident detection and response, citing insufficient information exchange and unclear roles between national CSIRTs and EU-CyCLONe. The report also highlights delays in NIS2 transposition, procurement holdups for the European Cybersecurity Alert System hubs, and duplication between the Commission's cyber-situation centre and ENISA. Auditors warned that recipients of EU cybersecurity funds were not consistently vetted, risking exposure to non-EU influence.
read more →

Sweden fines Miljödata over municipal data breach

🔒 IMY, Sweden’s data protection authority, fined IT provider Miljödata SEK 1.8 million ($183,000) after an August 2025 cyberattack exposed personal data of 2.2 million people across municipal systems. The regulator found the company failed to perform adequate checks on newly installed software and lacked automated real-time monitoring to detect intrusions, violating GDPR Article 32(1). The attack disrupted services in over 200 regions and saw stolen data published by the threat actor “Datacarry.”
read more →

EU fines Google €403M for mishandling location data

📌 The Irish Data Protection Commission fined Google €403 million for GDPR breaches in how three features handled location data between May 2018 and February 2020. The DPC found issues with Web & App Activity, Location History and the Location Accuracy feature, citing failures in lawful processing, transparency and accountability, and excessive data retention. Google says the case concerns historical policies and notes it has updated practices, including introducing auto-delete controls and changing defaults since 2019.
read more →

DPC fines Google €403M for location data breaches

📌 Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches tied to processing users’ location data. The investigation, opened in February 2020, reviewed three features — Web & App Activity, Location History, and Location Accuracy — active during May 25, 2018 to February 4, 2020. The DPC found failures in transparency, lawful processing, and retention practices, and ordered compliance within six months. Google says it has since updated policies and added user controls for location data.
read more →

Irish DPC Fines Google €403M Over Location Data

📍The Irish Data Protection Commission has fined Google €403m for GDPR breaches related to its handling of users' location data across features such as Web & App Activity, Location History and Location Accuracy. The inquiry, covering May 25, 2018 to February 4, 2020, found failures in lawfulness, transparency, accountability and retention practices. The DPC said Google must rectify its processing within six months, while Google contends policies have since changed and tools improved.
read more →

Cyber Essentials Sees Record Uptake but SME Coverage Lags

🔒 The UK’s Cyber Essentials scheme recorded a 20% rise to 61,430 certificates between July 2025 and June 2026, split between 46,245 self-assessed CE and 15,185 CE+ audited certifications. Nearly three-quarters were recertifications rather than new sign-ups, leaving adoption low relative to about 5.7 million UK SMEs. The increase coincides with findings that 49% of SMEs experienced a cyber incident in the past year, highlighting a gap between risk and basic cyber hygiene.
read more →

LinkedIn Pushes Limits on Secrecy in Government Subpoenas

🛡️ Microsoft’s chief legal officer argued that secrecy orders accompanying government subpoenas should be the exception, not the rule. LinkedIn, owned by Microsoft, is challenging broad government demands that bar notifying customers when their data is sought, urging courts to impose meaningful limits and oversight. The company acknowledged law enforcement needs while asserting providers and users deserve adversarial review and notice. Legislative reforms in the House aim to constrain secrecy orders and strengthen notice protections.
read more →

Radaris Loses Domains After New Jersey Privacy Case

📰 A New Jersey judge ordered radaris.com and more than a dozen related domains transferred to plaintiffs after finding the data broker repeatedly ignored removal requests under Daniel’s Law. Atlas Data Privacy Corp sued Radaris in 2024, alleging the company published personal data for state law enforcement and other officials and employed evasive shell-company tactics. The transfer follows extensive litigation, investigative reporting and documentary evidence tying multiple sites to a common operator.
read more →

CISA and NIST Issue Final Cloud Token Guidance

🔐 The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) published Interagency Report 8587 on September 15 to protect cloud identity tokens and assertions used in SSO, identity federation and API access. The guidance, which is voluntary, warns that adversaries are increasingly targeting tokens to move laterally and access sensitive data. It prescribes short token lifetimes, scoped key usage, hardware-backed key storage for moderate impact and above, and strict logging and audience validation rules.
read more →

Private offensive cyber program shifts risk to vendors

🔍 The White House memorandum creates a vetted program permitting private firms to conduct covert access and disruptive cyber operations under DOJ and DHS oversight, but it leaves significant legal, insurance, and commercial exposure with participating companies and their customers. The document relies on an untested reading of the CFAA for criminal protection, offers no civil safe harbor or indemnification, and may increase attribution risk internationally. Non-participating organizations can still inherit risk through shared infrastructure, vendor silence, insurance exclusions, and supply-chain telemetry.
read more →