< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief

437 articles · page 2 of 22

EU fines Google €890M for Digital Markets Act breaches

📰 The European Commission fined Google €890 million for violating the EU's Digital Markets Act, finding the company favoured its own services in Google Search and restricted app developers on Google Play. Google was designated a DMA gatekeeper in September 2023 and investigated from March 2024. The fine splits into €460 million for search favouritism and €430 million for app store steering, and Google must comply within 60 days or face further penalties.
read more →

End-to-End Encryption and the Going Dark Debate

🔐 This article summarizes a new paper updating 2012 research on encryption and globalization, focusing on “Round 3” of the Going Dark Debate over end-to-end encryption (E2EE). It outlines the technical foundations, market changes, and government proposals to limit E2EE for law enforcement and national security. The paper identifies five distinct E2EE scenarios and explains why broad restrictions would harm cybersecurity, commerce, and government operations. It concludes by urging skepticism toward new claims for restricting effective encryption, noting persistent lessons from prior rounds.
read more →

Police Chiefs Back Cybercrime Risk Orders Reform

🛡️ Senior UK law enforcement leaders have urged stronger legal tools after two men were jailed for the 2024 TfL hack, calling for Cybercrime Risk Orders (CCROs) to manage high-risk suspects. Sentenced under Section 3ZA of the Computer Misuse Act, the case—described as the largest cybercrime prosecution—highlighted investigation complexity, cross-border cooperation, and gaps in existing powers for underage offenders. Debate continues over CCROs’ practicality and enforcement.
read more →

EU orders Google to open Android to rival AI agents

📰 The European Commission issued two rulings under the Digital Markets Act requiring Google to open Android to third-party AI assistants and to share search data with rival engines. Google warned the measures could harm user privacy and security, while EU regulators said the steps are needed to ensure fair competition. Security leaders caution CISOs to reassess device and data governance as agents gain system-level reach.
read more →

EU orders Google to open Android sensors to rivals

🔎 The European Commission has ordered Google to grant rival AI assistants the same access to Android sensors and system features that Gemini enjoys, including camera, microphone, screen contents, background controls, and wake-word activation. Google must deliver the changes in the next major release, Android 18, or by 1 August 2027, with some concurrent hotword features delayed until Android 19. The decision, adopted under the Digital Markets Act on 16 July, also requires Google to provide anonymised Search query datasets to competing search engines and AI chatbots under strict safeguards and cost-based fees. The measures define a mix of restricted features requiring certification and open features available to all third-party apps, set up a Qualified AI Assistant Programme, and impose timelines and audit and anonymisation conditions.
read more →

Regulating Corporate Responsibility for AI Privacy

🛡️ Daniel Solove argues in the Wall Street Journal that individual control over personal data is insufficient to protect privacy in the AI era. He urges shifting regulatory focus to hold companies accountable—similar to food and drug oversight—through measures like data minimization, fiduciary duties, and liability for negligent design. Solove also recommends liability for harmful algorithms and multi-stakeholder review of technologies to ensure safer outcomes.
read more →

CISA Guidance Urges Formal Coordinated Disclosure

🔒 CISA and four international cybersecurity agencies have issued joint guidance urging software vendors and online service providers to establish coordinated vulnerability disclosure (CVD) programs. The guidance outlines how to publish clear disclosure policies, maintain communication with researchers, and handle reports for software, hardware, and network products. It supports CISA’s Secure by Design initiative and emphasizes prioritization, exploitability-based assessment, and validating compensating controls when patches are unavailable.
read more →

US launches Gold Eagle to accelerate vulnerability response

🛡️ The US government has launched Gold Eagle, a program led by CISA, the Treasury and the Department of Defense to speed detection and remediation of software vulnerabilities. The initiative, previewed in Executive Order 14409, aims to centralize reporting and reduce duplicate scans, likely using the VINCE platform with public-private participation. Experts warn the plan may not address the core remediation capacity and coordination issues that limit patch deployment.
read more →

UK updates National Risk Register with cyber scenarios

🔒 The UK government has expanded its National Risk Register to include several new cyber-related scenarios affecting digital infrastructure, water systems, policing, and a potential large-scale IT outage. The July 14 update also adds a section on interference in democratic processes, covering attacks on election infrastructure and online information operations. Likelihoods are generally assessed as low but impacts range from moderate to catastrophic, prompting plans for a national resilience campaign to boost household preparedness.
read more →

DoD Suspends CMMC Phase II Pending Reform Review

🛡️ The US Department of Defense has paused the rollout of CMMC Phase II, originally due November 10, 2026, while it conducts a 60-day review to reduce compliance burdens and foster innovation in the defense industrial base. The DoD will rely on NIST SP 800-171 self-assessments and select government-led checks during the interim, and has formed a CMMC Reform Task Force to realign the program with acquisition priorities.
read more →

US Sanctions VPN and Malware Providers Linked to Ransomware

🔒 The U.S. Treasury's OFAC sanctioned virtual private network provider First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and a Belarusian cryptor vendor, Yegeniy Silayev, for enabling ransomware operations. Authorities say 1VPNS marketed no-logs service to cybercriminals and used false identities to obtain infrastructure, while Silayev sold tools to evade malware detection. The action follows a multinational takedown and server seizures tied to widespread cybercrime.
read more →

EU and UK announce joint cyber sanctions on Russia

🛡️ The EU and the UK issued coordinated sanctions targeting Russian individuals, entities, and intelligence units accused of orchestrating cyberattacks across Europe. Designations include GRU and FSB-linked officers, cybercriminals, and private firms alleged to recruit hackers and run malware operations. Officials cite sustained campaigns against government and critical infrastructure since 2010 and recent disruptive attempts in Poland. The measures follow broader EU proposals to strengthen cybersecurity and precede additional sanctions on foreign companies tied to attacks.
read more →

AI Data Centers and Concentration of Corporate Power

📰 Local opposition to AI data centers reflects real concerns about land use, energy costs, environmental impact, and few local jobs, especially in lower-income communities. The authors warn this focus can distract from the broader threat: the concentration of power and wealth in AI companies and their political influence. They argue that policy responses should target corporate power, taxation of AI computation, public AI alternatives, and stronger regulation rather than only blocking data centers.
read more →

EU extends controversial message scanning through 2028

🔎 Members of the European Parliament failed to block an interim measure that extends mass scanning of private communications through 2028. The motion to reject and an amendment requiring warrants both secured more votes in favor than against, but neither reached the necessary absolute majority due to many absences. The extension permits service providers to scan DMs and emails on platforms like Discord, Instagram, Gmail and iCloud without warrants, while end-to-end encrypted services remain unaffected. Supporters argue it combats child sexual abuse; critics warn it threatens privacy and could lead to false positives affecting enterprises.
read more →

UK launches Cyber Resilience Pledge for businesses

🛡️ The UK government announced the Cyber Resilience Pledge, with over 60 businesses signing up after its unveiling at CYBERUK in April alongside a £90m support package. Signatories such as Microsoft UK, Marks & Spencer and Vodafone commit to board-level cyber accountability, NCSC training, Early Warning registration and risk-based Cyber Essentials adoption across supply chains. The scheme targets medium and large firms with the aim of driving baseline security improvements across suppliers.
read more →

France ends certification of non-quantum encryption

🔒 France’s cybersecurity agency ANSSI announced it will stop certifying security products that lack quantum-resistant encryption beginning in 2027, accelerating a national shift to post-quantum cryptography. ANSSI’s decision effectively forces French government bodies and critical operators to adopt quantum-safe solutions, as its approval is required for official use. The agency advised businesses to purchase only quantum-safe products by 2030 to ensure compliance and future-proofing.
read more →

CJEU upholds €4.1B antitrust fine against Google

📢 The Court of Justice of the European Union has dismissed Google's final appeal against a €4.1 billion antitrust fine related to Android. The ruling affirms that Google used pre-installation, anti-fragmentation agreements, and certain revenue-sharing deals to strengthen its dominant position and restrict competition. Google contests the decision, noting changes to its practices since 2018 and arguing that market realities have shifted.
read more →

Cybersecurity Mission Creep in U.S. Policy Debates

🔍 Cybersecurity Mission Creep examines how policymakers increasingly reframe diverse social and regulatory problems as matters of cybersecurity, a process the paper labels cybersecuritization. This reframing elevates issues—from misinformation and child safety to antitrust and trafficking—to existential security threats, enabling urgency-driven legal and political responses. The article warns that this trend simplifies complex issues, channels deference to specialists, and risks eroding public trust and governance transparency.
read more →

FTC fines Amazon for withholding fraud victims’ records

🔎 The FTC says Amazon will pay a $2.25 million penalty after allegedly blocking identity-theft victims from obtaining transaction records required under Section 609(e) of the FCRA. The complaint claims Amazon customer service denied record requests citing "privacy" or "security," often delivered records after the 30-day statutory window, and sometimes refused law enforcement requests. The order requires Amazon to provide requested records within 30 days and notify affected consumers who previously requested records since April 2024.
read more →

Bill would require mandatory AI incident reporting

📝 A proposed AI Incident Reporting Act would obligate developers of designated high-capability models to report major safety and security incidents to the Commerce Department. Reports would be required within seven days of discovery, with 48-hour notifications to congressional leaders for imminent or ongoing serious harm. The bill tasks the Secretary of Commerce with defining capability thresholds and grants the department investigative and enforcement powers, including fines up to $2 million per violation.
read more →