< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 14 of 24

Secure Connectivity Principles for OT — CISA, NCSC-UK

🔒 CISA and the UK National Cyber Security Centre (NCSC-UK) issued Secure Connectivity Principles for Operational Technology (OT) to help asset owners manage increasing connectivity demands. The guidance provides an eight‑principle framework to design, secure, and operate network access into OT environments. It targets operators of essential services and aligns with federal and international collaboration. Stakeholder feedback is invited through a CISA product survey.
read more →

G7 Sets 2034 Deadline for Financial PQC Migration Plan

🔐 The G7 Cyber Expert Group has published a recommended roadmap asking financial firms and public entities to complete transition to post-quantum cryptography (PQC) by 2034 to anticipate future quantum-enabled threats. The non-prescriptive guidance outlines six phased activities from awareness and inventory to migration, testing and validation, with overlapping timelines beginning in 2025. It stresses a risk- and standards-based approach, crypto agility and cross-jurisdiction collaboration to reduce fragmentation and enhance interoperability.
read more →

State and Local Cybersecurity: Framework in Place to Act

🛡️ The White House’s March 2025 Executive Order and Congress’s State and Local Cybersecurity Grant Program (SLCGP) together create a framework for strengthening defenses at state, local and tribal levels. The proposed PILLAR Act would extend and reinforce funding, oversight and scope. Success requires restoring disbursements, aligning with NIST standards, and building local capacity through partnerships and workforce development.
read more →

Time to Require Identity Verification for Internet Users

🔐 Australia's 2026 law banning under-16s from social media has reignited debate over whether internet services should require identity verification. Tony Anscombe argues that distinguishing verified and unverified users could reduce abuse, targeted fraud and underage exposure while letting people filter unwanted content. He warns verification methods (biometrics, government ID) carry privacy and data-retention risks and that bans may drive minors to circumvent restrictions, so a balanced regulatory approach is needed.
read more →

Congressional Delays Weaken U.S. Cybersecurity Posture

⚠️ The White House renominated seasoned Coast Guard and Energy Department cyber official Sean Plankey to lead CISA, a step that eases an urgent leadership gap but does not resolve broader legislative gridlock. Experts cite both executive deprioritization and congressional dysfunction—blocked confirmations, holds, and delayed reports—as drivers of a hollowed-out agency. Quick Senate confirmation, reauthorization of CISA 2015, and restored grant funding are needed to begin rebuilding capacity.
read more →

Parliament Seeks Industry Input on Cyber Security Bill

🏛️ The Parliamentary Public Bill Committee is inviting industry submissions to inform scrutiny of the Cyber Security and Resilience Bill (CSRB), the planned successor to the NIS Regulations 2018. Now at committee stage after its second reading, the bill proposes expanded scope, tighter incident-reporting, mandatory supply‑chain risk management and alignment with the NCSC Cyber Assessment Framework. The committee will hear oral evidence from 3 February and has urged prompt written responses as it may conclude early.
read more →

CISA Retires Ten Emergency Directives After Review

🔐 CISA has formally closed ten Emergency Directives issued between 2019 and 2024 after finding their objectives were met and required remediations implemented across federal civilian agencies. The agency said many issues were absorbed into Binding Operational Directive 22-01 and are now tracked via the known exploited vulnerabilities (KEV) catalog. A subset of directives were closed because requirements no longer matched current risk posture, while Emergency Directives remain available for urgent threats.
read more →

California Regulators Target Sale of Sensitive Health Data

⚖️California privacy regulators have taken enforcement action under the Delete Act, penalizing a marketing firm and a global analytics provider for trading in sensitive consumer profiles without proper registration. The agency fined Rickenbacher Data LLC (operating as Datamasters) $45,000 and ordered it to stop selling and delete California data. Separately, S&P Global was fined $62,600 for failing to register as a data broker. Officials highlighted risks from lists linked to medical conditions, race, age, political views and spending.
read more →

Germany, Israel Sign Cybersecurity and Security Pact

🔒 Germany and Israel have formalized a cyber and security pact aimed at deepening cooperation against growing digital and physical threats. Signed in Jerusalem by Federal Interior Minister Alexander Dobrindt and Prime Minister Benjamin Netanyahu, the agreement emphasizes closer networking of security authorities and joint work on cybercrime, AI and drone defense. Germany will also assume leadership of the U.S.-led OSC role in Jerusalem and plans to leverage Israeli technologies and experience to strengthen German security.
read more →

SBOM Explained: Software Bill of Materials and Compliance

📄 A Software Bill of Materials (SBOM) is a structured, machine-readable inventory that records every component and dependency inside a software product. An SBOM improves visibility across complex supply chains and helps vendors and buyers quickly identify affected systems after incidents such as SolarWinds or Log4j. U.S. policy and forthcoming European rules are driving wider adoption, and the NTIA defines minimum elements and acceptable formats (SPDX, CycloneDX, SWID). Generating SBOMs via Software Composition Analysis or build tooling and integrating them into DevSecOps processes is now considered best practice.
read more →

California Bars Data Broker from Reselling Health Data

🛑 The California Privacy Protection Agency ordered Rickenbacher Data LLC, operating as Datamasters, to stop selling Californians' health and personal information and fined the firm $45,000 for failing to register as a data broker under the California Delete Act. Regulators found Datamasters bought and resold hundreds of millions of records—names, emails, addresses and phone numbers—targeting people by medical conditions, age, perceived race, political views and purchases. The agency ordered deletion of previously acquired California records by the end of December, requires any newly received Californian data to be purged within 24 hours, and imposed five years of compliance measures; CalPrivacy also fined S&P Global $62,600 for an administrative registration lapse.
read more →

CISA Retires 10 Emergency Cybersecurity Directives

🔒 CISA has retired 10 Emergency Directives issued between 2019 and 2024 that were intended to protect Federal Civilian Executive Branch (FCEB) agencies from high-risk vulnerabilities. The directives covered DNS tampering, multiple Windows Patch Tuesday flaws, SolarWinds, Microsoft Exchange, Pulse Connect Secure, Print Spooler, VMware, and a nation-state compromise of Microsoft corporate email. CISA said the required actions were completed or are now enforced through BOD 22-01, and emphasized continued advancement of Secure by Design principles across federal systems.
read more →

CISA Retires Ten Emergency Cyber Directives at Once

🛡️ CISA has retired ten Emergency Directives issued between 2019 and 2024, stating the required mitigations have been completed or are now encompassed by BOD 22-01. The agency said this is the largest single closure of Emergency Directives to date. The action moves responsibility for ongoing remediation to the Known Exploited Vulnerabilities (KEV) catalog and its mandated federal patching timelines. CISA retains authority to require accelerated fixes for high-risk flaws, as in a recent one-day order for exploited Cisco CVEs.
read more →

Texas TRO Briefly Blocks Samsung Smart TV Tracking

🛑 A Texas district court briefly issued a temporary restraining order barring Samsung from collecting audio and visual data from Texas smart TVs under its Automated Content Recognition (ACR) program, citing deceptive enrollment practices and allegations that the Chinese Communist Party could access the information. The TRO, signed Jan. 5, said users were subjected to confusing disclosures and 'dark patterns' that defeat meaningful opt-out and claimed screenshots could be captured roughly every 500 milliseconds. The order initially blocked ACR activity relating to Texas consumers until Jan. 19, but the judge vacated the TRO the next day; the underlying lawsuit remains pending and a hearing is scheduled for Jan. 9.
read more →

Texas Court Bars Samsung From Collecting Smart TV Data

⚖️ The State of Texas secured a temporary restraining order against Samsung, barring it from collecting audio and visual data about what Texas consumers watch on Samsung smart TVs using Automated Content Recognition (ACR). The court found the enrollment process deceptive and opaque, relying on 'dark patterns' that make informed consent impractical. The order halts ACR use, sale, transfer, and data collection for Texas-based TVs pending further proceedings.
read more →

CISA Retires Ten Emergency Directives, Strengthening Security

🛡️ CISA announced the retirement of ten Emergency Directives issued between 2019 and 2024 after required mitigations were implemented or their coverage was incorporated into BOD 22‑01 and CISA’s Known Exploited Vulnerabilities catalog. The closures include directives tied to specific CVEs and high‑profile incidents such as SolarWinds and Exchange. CISA said the action reflects strengthened federal remediation, operational collaboration, and continued emphasis on Secure by Design principles.
read more →

New BSI Portal Enables NIS2 Registration and Reporting

🛡️ The new BSI portal lets companies register as NIS2 entities and report significant IT security incidents to the Federal Office for Information Security. Launched after NIS2 took effect in Germany in early December, the platform provides risk-analysis tools, legal guidance for registrants and access to the Alliance for Cyber Security. Hosted on AWS, it aims to deliver real-time data, daily situation reports and anonymous vulnerability reporting, though the cloud choice has attracted criticism over digital sovereignty.
read more →

US Withdraws Support for Global Cyber and Hybrid Forums

📰 The Trump administration has suspended US support for the Global Forum on Cyber Expertise (GFCE) and the European Centre of Excellence for Countering Hybrid Threats (Hybrid CoE) as part of a wider exit from 66 international organizations following an executive order signed on January 7. The move, described as being 'contrary to the interests of the United States', will affect cooperation on cybersecurity capacity building, incident response and efforts to counter hybrid threats. GFCE is a multi-stakeholder forum focused on cyber capacity, while Hybrid CoE is a Helsinki-based hub addressing disinformation, cyber-attacks and related tactics.
read more →

UK launches £210M plan to strengthen public cyberdefenses

🔒 The UK is investing more than £210 million to boost cyber defenses across government departments and the wider public sector through a new Government Cyber Action Plan. The initiative creates a dedicated Government Cyber Unit, mandates minimum security standards, and strengthens incident response capabilities. A new Software Security Ambassador Scheme will promote best practices with firms including Cisco, Palo Alto Networks, Sage, NCC Group, and Santander. The plan builds on the Cyber Security and Resilience Bill and earlier measures to curb ransom payments and telecom spoofing.
read more →

UK Launches Government Cyber Unit and Ambassador Scheme

🔐 The UK government has launched a Government Cyber Unit and a Software Security Ambassador Scheme under a £210m Cyber Action Plan to boost public sector resilience. The unit, led by the Government Chief Information Security Officer within the Department for Science, Innovation and Technology, will coordinate risk management and incident response across departments. The ambassador scheme promotes the voluntary Software Security Code of Practice and has drawn participants such as Cisco and Santander. While welcomed by many, some experts warn the funding may be insufficient to address the scale of threats exposed by recent 2025 incidents.
read more →