< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 2 of 24

Twenty-Five Years of Mass Surveillance Is Enough

📝 This essay, coauthored with Cindy Cohn and first published in Lawfare, traces the post-9/11 shift from targeted warrants to widespread mass surveillance by government and private actors. It outlines how data brokers, corporate tracking, and programs like the NSA’s Upstream and Section 702 collections have expanded governmental access to Americans’ communications. The authors argue these practices undermine Fourth and First Amendment protections and call for reassessment.
read more →

CISA Updates Insider Threat Mitigation Guide

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) has released a revised Insider Threat Mitigation Guide, published on September 9, expanding case studies, statistics and guidance for hybrid and remote work, AI-related risks, and adverse employee separations. The update, originally issued in 2020, aims to help security and HR professionals and leaders at all levels, offering practical resources for organizations regardless of program maturity. CISA emphasized the growing impact of insider threats on critical infrastructure and consolidated the guide into a more streamlined format with new content on access control and visitor screening.
read more →

US Sanctions Xinbi Guarantee for Global Scam Facilitation

⚖️ The US Treasury has sanctioned Xinbi Guarantee, a Chinese-language marketplace linked to large-scale fraud, money laundering and other criminal activity. The marketplace — alleged to have processed over $24bn in transactions since 2022 — connected scam operators in Southeast Asia with merchants offering financial services, fake IDs, AI deepfake tools and OTC crypto exchanges. OFAC also targeted supporting entities including SafeW Technology and Anwen Technology, while authorities and blockchain firms reported freezing $52.8m in cryptoassets and evidence the marketplace has gone offline.
read more →

France Launches New Government Cyber Response Unit

🛡️ The French national cybersecurity agency, ANSSI, has created a new incident response unit named REACTIV to support state services and coordinate responses to data breaches. The mechanism allows ANSSI to require ministries to take urgent protective measures and to lead centralized technical crisis communications during attacks affecting government services. Resource details for REACTIV have not yet been disclosed, prompting some skepticism about its operational capacity.
read more →

G7 urges accelerated shift to quantum-safe encryption

🔒 The G7, led by France's ANSSI during the 2026 Presidency, has issued a call to action urging governments and organizations to begin transitioning to post-quantum cryptography (PQC). The document reframes quantum threats as near-term risks and recommends a phased, risk-based approach: inventory cryptographic assets, map dependencies, and prioritize protection of critical systems. It also urges procurement of PQC-integrated products and early migration to lower costs, and sets five priorities including awareness, national strategies, R&D, public–private partnerships, and integrating PQC into cybersecurity requirements.
read more →

White House launches Project Watershed 250 pilot

🛡️ The White House has launched Project Watershed 250, a pilot program in Texas to provide water and wastewater utilities with federal and private-sector cybersecurity resources at no cost. Announced jointly by Governor Greg Abbott and National Cyber Director Sean Cairncross, the six-month initiative will deploy expertise from vendors including Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos. Supported by Texas Cyber Command, the pilot aims to identify vulnerabilities and strengthen defenses for rural and urban water providers amid growing OT-targeted threats tied to nation-state actors.
read more →

FSB warns of frontier AI risks to financial stability

⚠️ The Financial Stability Board (FSB) has warned that frontier AI models are reshaping the cyber-threat landscape and posing systemic risks to the global financial system. Chaired by Bank of England governor Andrew Bailey, the FSB urged firms and authorities to bolster vulnerability management, response and recovery capabilities, and to prepare for disruptions from concentrated third-party tech providers. The letter highlighted both the defensive potential of AI and the need for matched resilience and preparedness.
read more →

Meta Agrees to Proposed $18B Settlement Over Teen Harms

📰 Meta has reached a proposed settlement of up to $18 billion with a bipartisan coalition of 52 state attorneys general resolving a 2023 lawsuit alleging Facebook and Instagram were designed to encourage compulsive use by children and teens. The agreement, pending court approval, requires new protections for under-18 users including default time limits, nighttime restrictions, hidden like counts, stronger parental tools, and expanded age verification. An independent auditor will oversee compliance and Meta is barred from making misleading safety claims.
read more →

US Treasury Targets Iran-Linked Cyber Actors

🛡️ The U.S. Department of the Treasury announced Operation Economic Outcast, imposing sanctions on nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks. The measures target an MOIS-affiliated cyber group accused of widespread compromises of U.S. critical infrastructure and financially motivated theft, and designate five individuals tied to the Tehran-based Mabna Institute. Treasury and partner agencies emphasized cutting Iran's financial lifelines, while the State Department’s Rewards for Justice offers up to $10 million for information on malicious cyber actors.
read more →

TikTok Agrees to $400M COPPA Settlement with DOJ

📢 The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliates over alleged violations of the Children’s Online Privacy Protection Act (COPPA). The suit, filed in 2024, accused TikTok of allowing users under 13 to create regular accounts outside a restricted Kids Mode, collecting and retaining personal data without parental consent, and failing to delete data upon request. The settlement resolves those allegations while acknowledging that TikTok has since made compliance and privacy changes.
read more →

NIST outlines risks and challenges of multi‑cloud use

🔍 The US National Institute of Standards and Technology (NIST) has warned organisations about unique cybersecurity and compliance challenges in multi-cloud environments, where using multiple cloud service providers complicates consistent policy enforcement, controls and authentication. The report, published on August 21, identifies 23 specific challenges across identity and access, vulnerability management, incident response and data protection. NIST calls for improved governance, automation and standardisation and is seeking public comment until October 5, 2026.
read more →

TikTok to Pay $400M in U.S. Child Privacy Settlement

📰 The U.S. Department of Justice announced that ByteDance-owned TikTok agreed to pay $400 million to resolve a 2024 lawsuit alleging violations of child privacy laws. The settlement includes $300 million payable immediately and $100 million contingent on vacating a prior consent decree tied to Musical.ly. The complaint, filed with the FTC, accused TikTok of enabling under-13 accounts and improperly collecting data in "Kids Mode," claims the company has disputed as largely tied to past practices. The DoJ called the recovery among the largest under COPPA and noted TikTok has since strengthened age controls and parental oversight.
read more →

White House Memo Expands Private Cyber Operations Role

📝 This week's Threat Source newsletter by Mick Baccio examines a recent presidential memorandum directing DOJ and DHS to create a program that allows private companies to conduct government-authorized cyber surveillance and effects operations against transnational criminal organizations. The piece highlights operational questions about attribution, intelligence handling, and geopolitical risk, and notes Talos reporting on AI-driven Chinese cybercrime group UAT-10147 and critical active exploits.
read more →

NCSC urges stricter controls for agentic AI systems

🛡️ The UK NCSC has issued interim advice urging organizations deploying autonomous AI agents to use sandboxing, human oversight and tightly controlled access to limit unintended or malicious activity. It recommends assessing required autonomy, threat-modeling prompts, tools and networks, and avoiding sole reliance on model-level safeguards. For higher-risk deployments the agency advises robust sandboxes, deny-by-default network controls, separate execution and inference infrastructure, and short-lived, minimal credentials. Organizations should assign distinct identities to agents, maintain named human oversight with real-time monitoring, log agent activity, and ensure the ability to halt autonomous operations immediately. The guidance is interim and will be superseded by formal guidance under development.
read more →

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

ICO urges police to tighten facial recognition governance

🔎 The UK Information Commissioner’s Office (ICO) has called on police forces using live facial recognition (LFR) to strengthen data governance and align practice with legal requirements. Emily Keaney, deputy commissioner for regulatory policy, highlighted audits showing inconsistent compliance across five forces and urged improvements in oversight, record-keeping, training and accuracy checks. The ICO noted forces are engaging with the findings and stressed robust protections are essential to maintain public trust.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

UK Legal Regulator Issues AI Safety Warning

🛡️ The Solicitors Regulation Authority (SRA) has issued a warning to solicitors and law firms about using AI responsibly after spotting hallucinations and data leaks. The notice emphasizes that regulated individuals remain accountable for AI outputs and must maintain appropriate human oversight, governance and secure handling of client data. The SRA highlighted risks including false case citations, potential contempt of court and breaches of client confidentiality when information is entered into public AI tools.
read more →

ETSI Proposes 17 Standards for EU Cyber Resilience Act

🛡️ The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 draft cybersecurity standards to align products with the EU Cyber Resilience Act (CRA). The drafts, published on 13 August, define minimum security features—such as modern cryptography, secure-by-default settings, SBOMs and update capabilities—across network, edge, IoT and security product categories. Submissions from 41 member bodies are under public enquiry, with stakeholder comments invited through mid-September to mid-November 2026 and final standards expected by December 2026 ahead of CRA enforcement in December 2027.
read more →

White House memo expands private cyber offensive role

📝A White House memorandum signed by President Donald Trump directs the National Coordination Center (NCC) to create a program enabling vetted U.S. private companies to conduct cyber surveillance and cyber effects operations against foreign Transnational Criminal Organizations (TCOs). The NCC must implement the program within 60 days and impose oversight, minimization, and reporting requirements to prevent operations from targeting U.S. persons or systems. The move broadens private sector involvement in offensive cyber actions, while raising legal and security concerns given existing prohibitions on private actors conducting cyber attacks without court authorization.
read more →