< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 12 of 24

CISA directs removal of unsupported federal edge devices

🔒 CISA has ordered Federal Civilian Executive Branch agencies to inventory, update where possible, and remove all end-of-support edge devices—firewalls, routers, VPN gateways, load balancers, and other network security appliances—within an 18-month timeline. Agencies must report inventories within three months and begin removals within 12 months. CISA warned unsupported devices represent a substantial and constant threat and urged private sector adoption of similar measures.
read more →

CISA Orders Federal Agencies to Replace EOL Edge Devices

⚠️ CISA has issued BOD 26-02 requiring U.S. federal agencies to identify and remove end-of-life (EOL) network edge devices such as routers, firewalls, and switches that no longer receive security updates. Agencies must inventory devices on CISA's end-of-support list within three months, decommission pre-directive EOL devices within 12 months, and replace all identified EOL edge equipment within 18 months. The directive also requires agencies to implement continuous discovery processes within 24 months and encourages non-federal organizations to follow CISA's guidance to mitigate exploitation risks.
read more →

Meeting Cybersecurity Regulations: Practical Compliance Steps

🔒 Cybersecurity regulatory obligations vary by company size, industry and geography, and meeting them is increasingly a business prerequisite. Leaders should treat compliance frameworks such as NIS-2, ISO and NIST as structured methodologies — not end goals — while recognizing that compliance is not the same as security. CISOs must partner with legal, privacy and audit teams, prioritize risk-based decisions, and use tools like GRC, SIEM and continuous monitoring to demonstrate and maintain compliance.
read more →

Reducing Attack Surface from End-of-Support Edge Devices

🔒 This fact sheet from CISA, the FBI, and the U.K. NCSC urges organizations to mitigate risks posed by end-of-support (EOS) edge devices such as firewalls, routers, load balancers, and VPN gateways. It highlights BOD 26-02 for U.S. federal agencies and recommends maintaining asset inventories, replacing EOS hardware, and applying timely updates and patches to reduce exposure to nation-state threat actors.
read more →

CISA Directs Agencies to Secure End-of-Support Edge Devices

🔒 CISA issued Binding Operational Directive 26-02, requiring Federal Civilian Executive Branch agencies to mitigate risks from unsupported edge devices. Agencies must inventory devices, update vendor-supported software, remove end-of-support hardware and software, and implement mature lifecycle management within specified timeframes. CISA will monitor compliance, assess progress, and encourage non-federal organizations to adopt similar measures to reduce technical debt and strengthen cyber resilience.
read more →

US Declassifies Details of JUMPSEAT Reconnaissance Satellites

🛰️The US National Reconnaissance Office has declassified details about the JUMPSEAT fleet, a series of spy satellites that operated from 1971 to 2006. The release is notable because much of the material was declassified roughly two decades after these systems were retired. The disclosure provides historians, analysts, and policymakers with new primary-source material to reassess historical intelligence programs.
read more →

UK ICO Investigates X Over AI-Generated Sexual Images

🛡️ The UK Information Commissioner’s Office has opened a formal investigation into X and its AI assistant Grok after reports the system generated non-consensual sexual images using people’s personal data. The inquiry will assess whether such data were processed lawfully, fairly and transparently and whether appropriate safeguards were integrated into Grok’s design and deployment to prevent harmful image manipulation. The ICO has requested urgent information from X and warned the reports raise risks of significant harm, particularly to children.
read more →

UK ICO Probes X's Grok Over AI-Generated Sexual Images

🔍 The UK Information Commissioner's Office has opened a formal investigation into X and its Irish subsidiary after reports that the AI assistant Grok generated nonconsensual sexually explicit images using individuals' personal data. The ICO said it contacted X and xAI on January 7 to request urgent information and will assess whether X Internet Unlimited Company and X.AI LLC processed data lawfully and had adequate safeguards. The regulator warned that loss of control over intimate personal data can cause immediate and significant harm, especially where children are involved.
read more →

French Prosecutors Raid X Over Grok Sexual Deepfakes

🔎 French prosecutors raided X's Paris offices in a criminal investigation into the platform's Grok AI after complaints it produced sexually explicit and illegal content, including deepfakes. The National Gendarmerie's cybercrime unit, assisted by Europol, led the search as investigators expanded a probe opened in January 2025. Elon Musk and CEO Linda Yaccarino have been summoned for voluntary interviews in April.
read more →

NSA Publishes Phased Zero Trust Implementation Guidelines

🔐 The NSA has released new Zero Trust Implementation Guidelines (ZIGs) introducing Phase One and Phase Two to help organisations progress from Discovery to target-level zero trust maturity. Phase One establishes a secure baseline with 36 activities supporting 30 capabilities, while Phase Two adds 41 activities to enable 34 additional capabilities and integrate solutions across component environments. The guidance emphasises continuous authentication and post-login evaluation, aligns with NIST SP 800-207 and other federal frameworks, and is designed as a modular, tailorable approach for skilled practitioners.
read more →

Germany and Israel Conduct Joint Cyberattack Defense Drill

🛡️ Germany and Israel jointly conducted a first-ever exercise, called “Blue Horizon,” to practice defending against a major cyberattack as part of a recent bilateral cyber and security pact. The drill aims to familiarize experts and advance the planned construction of a German “Cyberdome”, modeled on Israeli systems that consolidate data and use AI to detect network vulnerabilities and warn organizations. The pact also foresees closer cooperation on cybercrime, artificial intelligence and drone defense.
read more →

Google's AI crawler policy and publisher control debate

⚖️ Cloudflare welcomes the UK CMA’s consultation on proposed conduct requirements for Google but argues the measures do not go far enough to protect publishers and competition. Cloudflare’s analysis shows Googlebot accesses substantially more unique pages than other AI crawlers, giving Google an entrenched advantage that can undercut publisher revenue. The company urges mandatory crawler separation so sites can permit search indexing while blocking use of content for generative AI, restoring publisher choice and enabling fairer market competition.
read more →

NIS2 Elevates Supply Chain Security to Leadership Task

🔒 NIS2 pushes organizations to treat supply-chain risk as central to cybersecurity, making external dependencies part of security architecture and leadership responsibility. It requires systematic inventories, contractual security obligations, and continuous monitoring of both direct providers and downstream subcontractors. For the CISO, the role shifts from technical stewardship to cross-functional risk management and enforcement. Common failures—poor prioritization, unenforced controls and organizational silos—must be addressed with scalable, evidence-based controls.
read more →

FBI Launches Winter SHIELD to Strengthen Cyber Defenses

🔐 The FBI has launched Operation Winter SHIELD, a ten-week campaign outlining ten concrete actions organisations should adopt to improve cyber resilience across IT and OT environments. Developed with domestic and international partners and informed by recent investigations, the initiative connects observed adversary behaviour to practical defenses such as phish-resistant authentication, immutable offline backups, vulnerability management and reduced administrator privileges. Aligned with the US National Cyber Strategy and the FBI Cyber Strategy, the effort aims to harden critical infrastructure and reduce the attack surface.
read more →

CISA Issues New Guidance on Insider Threat Risk Management

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) has released an infographic to help critical infrastructure operators and SLTT governments prevent, detect and respond to insider threats. It advocates treating insider risk as an essential capability and recommends scalable, multidisciplinary teams that are embedded in existing structures. The guidance outlines a four-stage model—plan, organize, execute, maintain—and emphasizes confidentiality, legal compliance and coordination with external partners.
read more →

GDPR Violation Reports Surge to Highest Daily Rate

📈 A new DLA Piper report finds that notifications of GDPR violations across the EU averaged 443 reports per day in 2025, a 22% increase over 2024. The firm cautions that the dataset does not definitively explain the rise but highlights likely drivers such as geopolitical tensions, new attacker technologies, and expanded mandatory reporting laws. Annual fines remained near €1.2 billion while cumulative penalties total about €7.1 billion since 2018.
read more →

Criticism of Kritis Umbrella Law Raises Patchwork Concerns

⚠️ The German Association of Cities warns the coalition's proposed Kritis umbrella law, due for a Bundestag vote, is insufficient because its 500,000‑inhabitant threshold excludes many essential facilities and weakens crisis preparedness. The draft tightens obligations for classified operators — including reporting duties and fines — but the Städtetag urges lowering the cutoff to 150,000 to cover medium-sized municipalities. The association also warns that allowing federal states to designate additional facilities risks creating a fragmented patchwork. In response to a January power-supply arson in Berlin, the amendment asks the government to review and remove publicly available infrastructure data to limit attacker intelligence, a shift Chancellor Friedrich Merz framed as moving from broad transparency toward greater resilience.
read more →

NIST Tightens AI Cybersecurity Guidance for Enterprises

🛡️ NIST is moving from high-level AI risk principles toward operational cybersecurity expectations, focusing especially on AI agent systems that take autonomous actions. The agency’s CAISI center has issued a formal RFI on secure practices for AI agents and is adapting the Cybersecurity Framework into a Cyber AI Profile. NIST’s work—spanning the AI RMF, Dioptra testing, an adversarial ML taxonomy, and SSDF guidance for generative models—signals that CISOs must treat AI as a near-term security priority rather than “just software.”
read more →

CISA Urges Critical Infrastructure to Combat Insider Threats

🛡️ CISA is urging critical infrastructure organizations and SLTT governments to take decisive action against insider threats and has published an infographic titled Assembling a Multi-Disciplinary Insider Threat Management Team to guide prevention, detection, and mitigation. The agency highlights that insider threats include both deliberate malicious acts and unintentional errors that can undermine systems and trust. The resource offers actionable steps to build cross-functional teams, foster accountability, and strengthen organizational resilience.
read more →

Data Protection Day 2026: From Compliance to Resilience

🛡️ On Data Protection Day 2026, CrowdStrike urges organizations to move beyond checkbox compliance toward operational resilience against modern data risks. The post details how adversaries exploit stolen credentials, identity abuse, SaaS sprawl and AI-driven workflows to access and exfiltrate data, often without crossing conventional boundaries. It calls for controls across identity, endpoints, browsers and the AI interaction layer, and highlights Falcon AIDR as a runtime capability to detect prompt injection, model manipulation and unauthorized tool execution while preserving legitimate workflows.
read more →