< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 11 of 24

Is AI Good for Democracy? Arms Races, Power, Policy

⚖️ Bruce Schneier contends that AI is reshaping democratic engagement by creating widespread, domain-specific arms races—from academic publishing and courts to media, hiring, and public comment systems. These dynamics advantage well-resourced corporate actors while pressuring governments to adopt automated tools to manage scale. Schneier urges both tactical citizen use of AI and stronger regulatory responses to prevent concentrated power and preserve civic voice.
read more →

NIST AI Agent Standards Initiative Aims for US Leadership

🧭 NIST has launched the AI Agent Standards Initiative via the Center for AI Standards and Innovation (CAISI) to create a roadmap for developing interoperable, trustworthy autonomous AI agents. The effort will gather public input through an RFI (responses due March 9) and sector-specific listening sessions in April, and emphasizes industry-led standards, open-source work, and international engagement. Critics caution the process may be too slow to keep pace with agentic AI adoption and emerging threats.
read more →

Texas Sues TP-Link Over Alleged Chinese Hacking Risks

🔒 Texas Attorney General Ken Paxton has sued TP-Link, alleging the company deceptively marketed routers as secure while obscuring Chinese supply-chain ties and labeling devices Made in Vietnam. The complaint cites firmware vulnerabilities exploited by Chinese state-backed actors and a large credential-theft botnet built from compromised routers. Paxton seeks monetary penalties and injunctions forcing disclosure of Chinese origins and limits on data collection; TP-Link denies the allegations and says U.S. user data is stored on domestic AWS servers.
read more →

Spain Court Orders NordVPN, ProtonVPN to Block Piracy

⚖️ A Spanish court has ordered NordVPN and ProtonVPN to block 16 websites and a dynamic set of IP addresses in Spain that facilitate illegal streaming of LaLiga matches. The measures were issued inaudita parte, meaning the providers were not called to a hearing and will have no opportunity to appeal. Rights holders argue VPNs fall under the EU Digital Services Regulation; the vendors say they were not notified and question the efficacy and legality of the order.
read more →

Ireland launches GDPR probe into X's Grok for sexual images

🔎 Ireland's Data Protection Commission has opened a formal probe into X over the use of its Grok AI to generate non‑consensual sexual images of real people, including children. The inquiry will assess whether X Internet Unlimited Company complied with core GDPR duties such as lawful processing, data protection by design, and required impact assessments. The DPC said it has been engaging with XIUC since media reports emerged and has commenced a large‑scale inquiry. As X's EU lead regulator, the DPC's findings could trigger cross‑border enforcement and significant penalties.
read more →

NCSC Urges SMEs to Use Cyber Essentials as Threats Rise

🔐 The NCSC's CEO Richard Horne has warned that small and medium-sized enterprises (SMEs) wrongly assume they are not attractive to cybercriminals and are failing to take basic protective measures. He stressed that attackers seek opportunity and weaknesses rather than high-profile brands, and urged businesses to adopt Cyber Essentials. The scheme focuses on five core controls — secure configuration, user access control, malware protection, security update management and firewalls — to reduce the risk of common attacks. Horne warned that leaving these protections undone is comparable to operating without physical security or insurance and called on SMEs to act immediately as the NCSC reports rising incidents and risks to critical infrastructure.
read more →

Passwords to Passkeys: ISO 27001 Compliance Practical Guide

🔐 Password-based authentication is increasingly replaced by passkeys—FIDO2/WebAuthn-backed credentials that store private keys on devices and typically meet AAL2/AAL3 assurance per NIST SP 800-63B. This article explains how organizations can adopt passkeys while remaining compliant with ISO/IEC 27001, mapping changes to Annex A controls (Access Control, Authentication Information, Secure Authentication) and documenting risk treatment. It highlights benefits, common risks such as device loss and downgrade attacks, and practical migration steps for enterprise deployment.
read more →

PIPC Fines Three Luxury Brands KRW36B for SaaS Failures

🔒 South Korea’s Personal Information Protection Commission (PIPC) fined the local subsidiaries of Louis Vuitton, Christian Dior Couture and Tiffany a combined KRW 36.033 billion plus KRW 10.8 million in additional penalties for failures securing customer data processed via a SaaS platform. The regulator found critical lapses — absent IP‑based access restrictions, weak or missing strong authentication, inadequate controls over bulk exports and insufficient log review — that allowed credential theft and social‑engineering attacks to expose personal information. The PIPC stressed that SaaS environments qualify as personal information processing systems under Korean law, placing responsibility squarely on data controllers, and ordered the firms to publicly disclose the enforcement actions.
read more →

BSI Sets Deadlines to Phase Out Classical Encryption

🔒 The Federal Office for Information Security (BSI) has updated its technical guideline TR-02102, establishing concrete deadlines to end the sole use of classical asymmetric encryption: from 2031 generally and for high-security systems from the end of 2030. The guideline mandates hybrid configurations that combine traditional algorithms with post-quantum cryptography and schedules deprecation of conventional signature algorithms for sole use by 2035. TR-02102 is divided into parts addressing algorithm/key guidance, TLS, IPsec/IKEv2, and SSH, and is a reference for developers and mandatory for certain classified-product deployments.
read more →

OpenEoX and BOD 26-02: Standardizing EOS Management

🔒 CISA warns that unsupported edge hardware and software pose systemic risks and highlights Binding Operational Directive BOD 26-02 as a federal step to identify, replace, and patch end-of-support (EOS) devices. The article introduces OpenEoX, an OASIS OPEN, machine-readable JSON standard that standardizes product lifecycle information and integrates with SBOMs and CSAF. By enabling producers to publish EOS milestones and consumers to automate lifecycle tracking, OpenEoX aims to reduce exposure and streamline vulnerability management. The piece urges rapid, communitywide adoption to close doors on threat actors exploiting outdated products.
read more →

CISA Hosts Town Halls to Seek Input on CIRCIA Rulemaking

📣 CISA will host a series of virtual town hall meetings beginning March 9 to collect stakeholder input on the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) rulemaking. The sessions will solicit feedback on the Notice of Proposed Rulemaking and implementation details; schedule information is published in the Federal Register and updates will be posted to CISA’s CIRCIA webpage. CIRCIA would require covered entities to report certain cyber incidents within 72 hours and ransom payments within 24 hours. CISA emphasized the need to balance improved national cybersecurity outcomes with minimizing unnecessary burden on critical infrastructure sectors.
read more →

Russia Moves to Block WhatsApp and Telegram Access

🔒 Russia is escalating efforts to block WhatsApp and Telegram after Roskomnadzor excluded whatsapp.com and web.whatsapp.com from the national DNS and began throttling services. Authorities previously limited voice and video calls and attempted to block new registrations, while Meta has been labeled as extremist in Russia. The Kremlin is promoting the state-aligned MAX messenger as an endorsed alternative, and users currently rely on VPNs and external resolvers to maintain access amid mounting restrictions.
read more →

New York Proposal Would Add Surveillance to 3D Printers

⚠️ New York’s 2026–2027 executive budget bill proposes a blocking technology requirement for all 3D printers sold or delivered in the state. The provision would require firmware or software to scan every print file with a firearms blueprint detection algorithm and refuse prints flagged as potential firearms or components. While intended to curb illicit weapon production, critics say it resembles DRM, will be technically ineffective, and would impose significant burdens on makers, educators, and small manufacturers.
read more →

CISA Guidance: Barriers to Secure OT Communication

🔒 CISA released guidance that examines why legacy industrial protocols are often insecure-by-design and why available protections are not widely adopted. Developed with OT equipment manufacturers and standards bodies, the document reports findings from interviews with asset owners and operators about motivations to secure communication and barriers they face. The guidance identifies practical, operational, and technical obstacles and offers recommendations for owners and operators and manufacturers to drive more usable, sustainable security capabilities.
read more →

NCSC Warns CNI Operators of Severe Cyber-Attacks Now

⚠️ The NCSC has issued an urgent alert to critical national infrastructure (CNI) providers after December's coordinated malware attacks against Poland's energy sector, urging operators to act now to defend UK assets. Director Jonathan Ellison stressed the need to follow recent NCSC guidance on monitoring, situational awareness and hardening network defences. Recommended measures include patching, access controls and MFA, secure-by-design management and robust resilience and recovery plans.
read more →

CISA Orders Federal Agencies to Remove EOS Edge Devices

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 26-02 requiring federal civil executive branch agencies to decommission end-of-support (EOS) edge devices within specified timelines. Agencies must identify and remediate vulnerabilities within three months and remove EOS devices from external-facing network edges within 18 months, replacing them with vendor-supported hardware. The directive also mandates continuous discovery and inventory processes to prevent future exposure.
read more →

NIS2 Reframes Supply Chain Risk as Core Security Duty

🔒 NIS2 forces organizations to treat supply chains as an integral part of cybersecurity rather than an afterthought. The directive shifts emphasis from perimeter defenses to the risks posed by external service providers and subcontractors, requiring firms to identify dependencies, set proportionate contractual security obligations, and implement continuous monitoring. It also elevates the CISO's remit to enforce cross-functional risk management.
read more →

Preparing for the Quantum Era: A Call to Secure PQC

🔐 Google issues a call to action to protect digital systems against quantum threats, outlining its post-quantum cryptography (PQC) work and policy recommendations. The company warns that large-scale quantum computers could break current public-key cryptography and cautions about 'store now, decrypt later' harvesting of encrypted data. Google commits to research transparency, completing PQC migrations within NIST guidelines, and strengthening crypto agility, critical shared infrastructure, and ecosystem readiness.
read more →

EU Says TikTok Faces Fine Over Addictive Design in EU

⚖️ The European Commission says TikTok may face a substantial penalty under the Digital Services Act after preliminary findings concluded that core design elements — infinite scroll, autoplay, push notifications and personalized recommendation systems — promote compulsive use and can harm minors and vulnerable adults. Regulators say TikTok failed to adequately assess and mitigate risks, pointing to nighttime usage and frequent app openings as ignored indicators of harm. If confirmed, the violations could trigger a fine of up to 6% of global turnover and the Commission has demanded screen-time breaks, adapted recommendation systems and the disabling of key addictive features; existing parental controls were judged insufficient.
read more →

CISA Orders Removal of Unsupported Edge Devices Nationwide

🔒 CISA ordered federal agencies to remove edge devices that no longer receive vendor security updates and to strengthen lifecycle management within 12–18 months. Directive 26-02 requires agencies to catalog devices, update supported software immediately, report end-of-support items in three months, and decommission listed devices in 12 months and others in 18 months. CISA published an end-of-support edge device list and highlighted routers, firewalls, load balancers, wireless access points and IoT edge gear as high-risk targets for exploitation.
read more →