< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief

437 articles

TikTok to Pay $400M in U.S. Child Privacy Settlement

📰 The U.S. Department of Justice announced that ByteDance-owned TikTok agreed to pay $400 million to resolve a 2024 lawsuit alleging violations of child privacy laws. The settlement includes $300 million payable immediately and $100 million contingent on vacating a prior consent decree tied to Musical.ly. The complaint, filed with the FTC, accused TikTok of enabling under-13 accounts and improperly collecting data in "Kids Mode," claims the company has disputed as largely tied to past practices. The DoJ called the recovery among the largest under COPPA and noted TikTok has since strengthened age controls and parental oversight.
read more →

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

NCSC urges stricter controls for agentic AI systems

🛡️ The UK NCSC has issued interim advice urging organizations deploying autonomous AI agents to use sandboxing, human oversight and tightly controlled access to limit unintended or malicious activity. It recommends assessing required autonomy, threat-modeling prompts, tools and networks, and avoiding sole reliance on model-level safeguards. For higher-risk deployments the agency advises robust sandboxes, deny-by-default network controls, separate execution and inference infrastructure, and short-lived, minimal credentials. Organizations should assign distinct identities to agents, maintain named human oversight with real-time monitoring, log agent activity, and ensure the ability to halt autonomous operations immediately. The guidance is interim and will be superseded by formal guidance under development.
read more →

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

ICO urges police to tighten facial recognition governance

🔎 The UK Information Commissioner’s Office (ICO) has called on police forces using live facial recognition (LFR) to strengthen data governance and align practice with legal requirements. Emily Keaney, deputy commissioner for regulatory policy, highlighted audits showing inconsistent compliance across five forces and urged improvements in oversight, record-keeping, training and accuracy checks. The ICO noted forces are engaging with the findings and stressed robust protections are essential to maintain public trust.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

UK Legal Regulator Issues AI Safety Warning

🛡️ The Solicitors Regulation Authority (SRA) has issued a warning to solicitors and law firms about using AI responsibly after spotting hallucinations and data leaks. The notice emphasizes that regulated individuals remain accountable for AI outputs and must maintain appropriate human oversight, governance and secure handling of client data. The SRA highlighted risks including false case citations, potential contempt of court and breaches of client confidentiality when information is entered into public AI tools.
read more →

ETSI Proposes 17 Standards for EU Cyber Resilience Act

🛡️ The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 draft cybersecurity standards to align products with the EU Cyber Resilience Act (CRA). The drafts, published on 13 August, define minimum security features—such as modern cryptography, secure-by-default settings, SBOMs and update capabilities—across network, edge, IoT and security product categories. Submissions from 41 member bodies are under public enquiry, with stakeholder comments invited through mid-September to mid-November 2026 and final standards expected by December 2026 ahead of CRA enforcement in December 2027.
read more →

White House memo expands private cyber offensive role

📝A White House memorandum signed by President Donald Trump directs the National Coordination Center (NCC) to create a program enabling vetted U.S. private companies to conduct cyber surveillance and cyber effects operations against foreign Transnational Criminal Organizations (TCOs). The NCC must implement the program within 60 days and impose oversight, minimization, and reporting requirements to prevent operations from targeting U.S. persons or systems. The move broadens private sector involvement in offensive cyber actions, while raising legal and security concerns given existing prohibitions on private actors conducting cyber attacks without court authorization.
read more →

White House Authorizes Private Hack-Back Program

📝 The White House issued a National Security Presidential Memorandum directing the National Coordination Center to establish a program allowing vetted private security firms to apply for authorization to conduct cyber operations against foreign transnational criminal organizations. The program, overseen by executive directors from the Justice and Homeland Security departments, requires companies to post a $1 million bond, adhere to strict legal and constitutional safeguards, and immediately halt activities that exceed approved limits, such as accidentally targeting U.S. systems or citizens. It targets disruption of ransomware, phishing, financial fraud, sextortion, and impersonation schemes and aims to leverage private sector capabilities under government control.
read more →

US Authorizes Private Help in Offensive Cyber Operations

🔒 The White House has approved a memorandum allowing federal law enforcement to collaborate with private companies on limited offensive cyber operations against foreign actors targeting the US. The National Security Presidential Memorandum (NSPM) signed on August 12 builds on earlier executive actions and tasks the Homeland Security Task Force’s National Coordination Center to oversee the program. Rigorous procedures and legal safeguards are promised, while experts warn about attribution difficulties and escalation risks.
read more →

Administration Clears Path for Supervised Private Cyber Operations

🛡️ A presidential memorandum directs the National Coordination Center to establish a program allowing vetted US companies to conduct government-supervised cyber surveillance and cyber effects operations against foreign groups targeting US interests. Participating firms must contract with the DOJ or DHS, undergo vetting, and obtain written approval for each operation, with officials given 60 days to set procedures. The plan raises concerns about collateral damage, attribution errors, corporate liability, and privacy implications for threat intelligence sharing.
read more →

NIST Seeks Input to Modernize NVD for AI Era

🛡️ NIST has issued a request for information to modernize the National Vulnerability Database (NVD) to better address AI-driven challenges and incorporate automation. The RFI, published on August 12, asks stakeholders for forward-looking perspectives and practical recommendations to improve the NVD’s scalability, interoperability, transparency and utility. NIST noted that traditional periodic scanning and manual remediation are becoming inadequate as AI-enabled tools and faster technology cycles increase vulnerability volumes. Responses are invited through October 13, with the aim of creating a more continuous, contextual and automated vulnerability management system.
read more →

Cybersecurity needs a new operating model for AI era

🔒 The article argues that AI has compressed the timeline between exposure and exploitation, undermining a longstanding security operating model built for human-speed attackers. The ECB’s July 7, 2026 supervisory letter requires major banks to submit AI-focused cybersecurity action plans by Oct. 31, 2026, signaling that AI-driven threats are a long-term, operational reality. Regulators and agencies now emphasize risk-based prioritization, evidence-based decisions, and accelerated remediation to maintain resilience.
read more →

Prosecution Over Phone Wipe Raises Border Search Questions

🔐 The prosecution of an American who provided a code that wiped his GrapheneOS-powered Pixel phone highlights tensions at the U.S. border. The feature in GrapheneOS deliberately erases device contents when a specific passcode is entered, and the defendant’s phone ran this OS. The case probes constitutional protections at the border and the government’s stance that border zones are not subject to the same rights until entry is authorized. GrapheneOS maintains the feature is legal and constitutionally protected.
read more →

FCC Blocks New Foreign-Produced Robots and Inverters

🔒 The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally blocking new models from receiving US equipment authorization for import, marketing, or sale. Previously authorized units and existing owners are unaffected, and federal purchases remain permitted. A waiver allows security and compatibility software updates through at least January 1, 2029, while manufacturers may seek Conditional Approval by January 1, 2028.
read more →

CISA's Six-Step Blueprint for Infrastructure Isolation

🔒 The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

Guidance for isolating critical infrastructure OT

🔒 New joint guidance from U.S. and Australian cybersecurity agencies, including CISA and the ACSC, advises critical infrastructure operators to prepare to isolate vital operational technology systems during cyber incidents. The document defines concepts like vital systems, isolation points, and graduated versus physical isolation, and stresses planning, documentation, and regular testing. It highlights trade-offs, operational impacts, and the need to maintain manual operations and secure offline plans.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →