< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 13 of 24

CISA publishes PQC technology readiness list for CIOs

🔒 CISA has released an advisory mapping post-quantum cryptography (PQC) standards to common enterprise hardware and software categories to help CIOs and security teams evaluate quantum-safe readiness. Issued in response to the June 6, 2025 executive order, the guidance lists product classes that already implement, or are transitioning to, NIST-aligned PQC algorithms. CISA emphasizes many implementations provide PQC for key establishment (KEM/KGA) but not yet for digital signatures and authentication, so categories on the list are not fully quantum resistant. The advisory references FIPS 203–205 as the baseline for required primitives.
read more →

Supreme Court Review: Geofence Warrants and the Fourth

⚖️ The U.S. Supreme Court is weighing the constitutionality of geofence warrants in the appeal of Okello Chatrie, convicted after a 2019 Richmond-area robbery. Police obtained anonymized location records from Google for devices near the crime scene, which led investigators to Chatrie and evidence seized during a subsequent search. Chatrie’s appeal contends such warrants violate the Fourth Amendment. The Court’s decision could recalibrate the balance between investigative tools and individual location privacy.
read more →

EU Opens DSA Probe into X Over Alleged Grok Sexual Images

⚖️ The European Commission has opened formal proceedings under the Digital Services Act to examine whether X properly assessed risks before deploying the Grok AI tool, after reports it produced sexually explicit and potentially child sexual abuse material. UK and Californian authorities are conducting parallel probes, and regulators say these apparent harms “seem to have materialised.” X later restricted image-generation and editing to paid subscribers while it faces enforcement as a VLOP and a recent c120 million fine for DSA transparency breaches.
read more →

CISA Publishes PQC-Capable Product Categories List

🔐 CISA has published an initial list of hardware and software product categories that either support or are expected to support post-quantum cryptography (PQC) standards, following Executive Order 14306 issued on 6 June 2025. Compiled in collaboration with the NSA, the list covers cloud services, collaboration and web software, endpoint security and networking products, and is intended to guide procurement and risk planning as organizations prepare for quantum threats.
read more →

Ireland Seeks New Police Powers for Digital Surveillance

🕵️ The Irish government proposes new powers to allow police to intercept communications, including encrypted messages, and to authorize targeted, warrant-backed use of spyware. The draft measures would expand legal authority for interception, compel assistance from service providers and device makers, and define covert access procedures along with oversight obligations. Civil liberties groups and security experts warn the reforms risk weakening encryption, increasing misuse, and eroding privacy without robust independent safeguards.
read more →

Germany to Authorize Cross-Border Cyber Counterstrikes

🛡️ Germany plans to adopt a more offensive cyber posture, saying it will "strike back, also abroad," and aim to disrupt attackers and destroy their infrastructure. The Interior Ministry proposes joint operational responsibility for the Federal Criminal Police Office (BKA) and intelligence services and is creating a new defense center against hybrid threats. Minister Alexander Dobrindt said he will introduce laws in the first half of the year to expand intelligence powers for information gathering and operational action.
read more →

NHS Calls for Stronger Supplier Cybersecurity Measures

🏥The NHS has issued an open letter (22 January) signaling more proactive engagement with suppliers to bolster cyber resilience across health and social care. The initiative builds on last year’s voluntary cybersecurity supply chain charter and responds to persistent ransomware and supply-chain threats. NHS England stresses this is not an audit but a partnership to identify risks and agree proportionate remediation. Expectations include MFA, patched systems, effective logging and immutable backups with tested recovery plans.
read more →

CISA Publishes Product Categories for PQC Adoption

🔐 The Cybersecurity and Infrastructure Security Agency (CISA) released an initial list of Product Categories for technologies that use post-quantum cryptography standards. Developed under Executive Order 14306 (June 6, 2025) and in coordination with the NSA, the list identifies hardware and software types that already support or are expected to adopt PQC, including cloud services, web software, networking, and endpoint security. CISA will update the list regularly to guide procurement and migration planning.
read more →

CISA Guidance on Product Categories for PQC Adoption

🔒 CISA published lists identifying hardware and software product categories where post-quantum cryptography (PQC) standards are already in use or expected to be widely available. Issued under Executive Order 14306, the guidance directs agencies to plan acquisitions to prefer PQC-capable products in listed categories and urges vendors to implement and test PQC features. It distinguishes categories that have implemented PQC for key establishment from those still transitioning for digital signatures and other functions, and it will be updated periodically.
read more →

TikTok Forms U.S. Joint Venture to Continue Operations

🔒 TikTok USDS Joint Venture LLC was formed to allow TikTok to continue operating in the U.S. under a majority-American ownership while ByteDance retains 19.9%. U.S. users' data and a retrained recommendation algorithm will be hosted in Oracle's secure U.S. cloud and protected under defined safeguards for algorithm security, content moderation, and software assurances. An independent, audited cybersecurity and privacy program will follow standards such as NIST CSF, NIST 800-53, ISO 27001, and CISA requirements.
read more →

Over 160,000 Companies Notify Regulators of GDPR Breaches

📈 The number of organisations reporting GDPR breaches rose 22% in 2025 to a daily average of 443, according to DLA Piper, making this the first year since 2018 that notifications topped 400. Germany, the Netherlands and Poland recorded the most reports, and analysts pointed to geopolitical unrest and emerging AI-enabled threats as contributors. Annual GDPR fines remained stable at €1.2bn, with Ireland issuing the largest share, including a €530m penalty for TikTok over international data transfers.
read more →

EU Revises Cybersecurity Rules to Curb High-Risk Suppliers

🔐 The European Commission has unveiled a cybersecurity package to strengthen the EU’s resilience against state and criminal cyber and hybrid threats. The proposals focus on reducing risks from high-risk suppliers outside the EU—particularly in critical infrastructure like mobile networks—using a common, risk-based framework. The plan updates the European Cybersecurity Certification Framework to speed product testing, eases compliance burdens for SMEs, and reinforces ENISA’s role in threat analysis, incident response and vulnerability management.
read more →

EU Proposes Cybersecurity Act 2.0 to Strengthen EU Defenses

🔒 The European Commission has proposed an update to the Cybersecurity Act, published on 20 January, to address shortcomings in the original regulation. The package aims to streamline the European cybersecurity certification framework, introduce a trusted ICT supply chain security framework across 18 critical sectors, and require certification schemes to be developed within 12 months by default. It also expands ENISA's powers to lead incident support, vet suppliers, and pilot skill attestation.
read more →

UK launches Report Fraud to replace Action Fraud service

🛡️Report Fraud has launched in the UK to replace the criticised Action Fraud service, providing a single, modern national reporting, triage and intelligence platform across England, Wales and Northern Ireland. The service incorporates real-time analytics powered by Palantir and Microsoft, an interactive portal for victims to track and update cases, proactive notifications, and instant intelligence sharing with police and businesses. A new National Crime Analysis Service (N-CAS) will underpin analytics, and a national "Every Report Counts" advertising campaign will promote the launch.
read more →

EU Commission Proposal Would Allow Bans on High-Risk Vendors

🔒 The EU Commission has proposed a legal mechanism to ban network-equipment vendors it considers high-risk, a move widely seen as targeting Chinese firms such as Huawei and ZTE though the draft does not name specific companies. The plan would let Brussels require member states to replace prohibited technology in critical infrastructure within three years. It would also strengthen ENISA with additional staff and funding to coordinate EU-wide cybersecurity and ransomware defenses.
read more →

EU Cybersecurity Overhaul to Bar High-Risk Suppliers

🔒 The European Commission has proposed a comprehensive cybersecurity package that would require the removal of high-risk suppliers from sensitive telecommunications networks and give Brussels authority to coordinate EU-wide risk assessments. The measure aims to strengthen defenses against state-backed actors and cybercrime targeting critical infrastructure while addressing uneven uptake of the 2020 5G Security Toolbox. The proposal also expands ENISA's remit to issue early threat alerts, centralize incident reporting, streamline voluntary certification, and support joint assessments across 18 critical sectors, with member states required to transpose changes within one year of approval.
read more →

AI and the Corporate Capture of Public Knowledge Debate

📚 The essay links Aaron Swartz’s fight for open access to today’s large AI firms that scrape and monetize vast amounts of public and private knowledge. It argues that AI companies are effectively appropriating research and creative works, settling liabilities as a cost of business while public access and accountability erode. The piece warns this corporate capture shifts control of information from democratic institutions to private platforms.
read more →

Global Agencies Publish Secure Connectivity Guidance for OT

🔐 The US Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC) and the Federal Bureau of Investigation (FBI), alongside international partners, have released principles to secure operational technology (OT) connectivity. Led by NCSC-UK, the guidance offers a shared framework to design and manage secure connectivity across OT environments. It emphasizes embedding cybersecurity into network design to reduce exposure to both state-backed and opportunistic adversaries. The document warns that increased interconnection brings benefits such as real-time analytics and predictive maintenance, but also raises risks that could cause physical harm, environmental damage or service disruption.
read more →

FTC Restricts GM from Selling Drivers' Location Data

📍 The Federal Trade Commission has finalized an order prohibiting General Motors and its OnStar unit from collecting, using, or sharing consumers' precise geolocation and driving-behavior data without express consent. The FTC said GM harvested location data every three seconds through the discontinued Smart Driver feature and sold it to third parties, including consumer reporting agencies, which could affect insurance outcomes. Under the order GM is barred from sharing such data with consumer reporting agencies for five years, must obtain express consent for collection and sharing for 20 years, and must give U.S. customers access, deletion rights, and the ability to disable precise location tracking.
read more →

International Principles for Secure OT Connectivity

🛡️ CISA, the UK’s NCSC, the FBI and international partners published the Secure Connectivity Principles for Operational Technology (OT), a joint guide led by NCSC‑UK to mitigate insecure and exposed connectivity and defend against opportunistic and nation‑state cyber threats. The guidance provides a practical framework and eight key principles to help OT owners and operators design, secure, and manage connectivity. Agencies also urge OT device manufacturers and integrators to embrace secure‑by‑design practices and recommend organizations assess OT connectivity and implement mitigations to strengthen critical infrastructure resilience.
read more →