< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 3 of 24

White House Authorizes Private Hack-Back Program

📝 The White House issued a National Security Presidential Memorandum directing the National Coordination Center to establish a program allowing vetted private security firms to apply for authorization to conduct cyber operations against foreign transnational criminal organizations. The program, overseen by executive directors from the Justice and Homeland Security departments, requires companies to post a $1 million bond, adhere to strict legal and constitutional safeguards, and immediately halt activities that exceed approved limits, such as accidentally targeting U.S. systems or citizens. It targets disruption of ransomware, phishing, financial fraud, sextortion, and impersonation schemes and aims to leverage private sector capabilities under government control.
read more →

US Authorizes Private Help in Offensive Cyber Operations

🔒 The White House has approved a memorandum allowing federal law enforcement to collaborate with private companies on limited offensive cyber operations against foreign actors targeting the US. The National Security Presidential Memorandum (NSPM) signed on August 12 builds on earlier executive actions and tasks the Homeland Security Task Force’s National Coordination Center to oversee the program. Rigorous procedures and legal safeguards are promised, while experts warn about attribution difficulties and escalation risks.
read more →

Administration Clears Path for Supervised Private Cyber Operations

🛡️ A presidential memorandum directs the National Coordination Center to establish a program allowing vetted US companies to conduct government-supervised cyber surveillance and cyber effects operations against foreign groups targeting US interests. Participating firms must contract with the DOJ or DHS, undergo vetting, and obtain written approval for each operation, with officials given 60 days to set procedures. The plan raises concerns about collateral damage, attribution errors, corporate liability, and privacy implications for threat intelligence sharing.
read more →

NIST Seeks Input to Modernize NVD for AI Era

🛡️ NIST has issued a request for information to modernize the National Vulnerability Database (NVD) to better address AI-driven challenges and incorporate automation. The RFI, published on August 12, asks stakeholders for forward-looking perspectives and practical recommendations to improve the NVD’s scalability, interoperability, transparency and utility. NIST noted that traditional periodic scanning and manual remediation are becoming inadequate as AI-enabled tools and faster technology cycles increase vulnerability volumes. Responses are invited through October 13, with the aim of creating a more continuous, contextual and automated vulnerability management system.
read more →

Cybersecurity needs a new operating model for AI era

🔒 The article argues that AI has compressed the timeline between exposure and exploitation, undermining a longstanding security operating model built for human-speed attackers. The ECB’s July 7, 2026 supervisory letter requires major banks to submit AI-focused cybersecurity action plans by Oct. 31, 2026, signaling that AI-driven threats are a long-term, operational reality. Regulators and agencies now emphasize risk-based prioritization, evidence-based decisions, and accelerated remediation to maintain resilience.
read more →

Prosecution Over Phone Wipe Raises Border Search Questions

🔐 The prosecution of an American who provided a code that wiped his GrapheneOS-powered Pixel phone highlights tensions at the U.S. border. The feature in GrapheneOS deliberately erases device contents when a specific passcode is entered, and the defendant’s phone ran this OS. The case probes constitutional protections at the border and the government’s stance that border zones are not subject to the same rights until entry is authorized. GrapheneOS maintains the feature is legal and constitutionally protected.
read more →

FCC Blocks New Foreign-Produced Robots and Inverters

🔒 The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, generally blocking new models from receiving US equipment authorization for import, marketing, or sale. Previously authorized units and existing owners are unaffected, and federal purchases remain permitted. A waiver allows security and compatibility software updates through at least January 1, 2029, while manufacturers may seek Conditional Approval by January 1, 2028.
read more →

CISA's Six-Step Blueprint for Infrastructure Isolation

🔒 The US CISA and Five Eyes partners published CI Fortify, a six-step guide to isolate and protect critical infrastructure during cyber incidents. The guide outlines identifying vital systems and customers, classifying trust levels, mapping interconnections, and building separation points. It emphasizes physical isolation and phased isolation plans while acknowledging operational constraints and the need for encryption and robust risk management.
read more →

NCSC issues guidance for disruptive cyber incidents

🛡️ The UK's National Cyber Security Centre (NCSC) has published What To Do When Cyber-Attacks Disrupt Your Organisation, outlining three chronological stages for response: immediate hours and days, recovery to minimum viable operations, and longer-term restoration to business as usual. The guidance emphasizes preparing in advance, practicing realistic simulations, and engaging NCSC-vetted incident response firms to build resilience against escalating threats such as AI-accelerated attacks.
read more →

Guidance for isolating critical infrastructure OT

🔒 New joint guidance from U.S. and Australian cybersecurity agencies, including CISA and the ACSC, advises critical infrastructure operators to prepare to isolate vital operational technology systems during cyber incidents. The document defines concepts like vital systems, isolation points, and graduated versus physical isolation, and stresses planning, documentation, and regular testing. It highlights trade-offs, operational impacts, and the need to maintain manual operations and secure offline plans.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →

EU fines Google €890M for Digital Markets Act breaches

📰 The European Commission fined Google €890 million for violating the EU's Digital Markets Act, finding the company favoured its own services in Google Search and restricted app developers on Google Play. Google was designated a DMA gatekeeper in September 2023 and investigated from March 2024. The fine splits into €460 million for search favouritism and €430 million for app store steering, and Google must comply within 60 days or face further penalties.
read more →

End-to-End Encryption and the Going Dark Debate

🔐 This article summarizes a new paper updating 2012 research on encryption and globalization, focusing on “Round 3” of the Going Dark Debate over end-to-end encryption (E2EE). It outlines the technical foundations, market changes, and government proposals to limit E2EE for law enforcement and national security. The paper identifies five distinct E2EE scenarios and explains why broad restrictions would harm cybersecurity, commerce, and government operations. It concludes by urging skepticism toward new claims for restricting effective encryption, noting persistent lessons from prior rounds.
read more →

Police Chiefs Back Cybercrime Risk Orders Reform

🛡️ Senior UK law enforcement leaders have urged stronger legal tools after two men were jailed for the 2024 TfL hack, calling for Cybercrime Risk Orders (CCROs) to manage high-risk suspects. Sentenced under Section 3ZA of the Computer Misuse Act, the case—described as the largest cybercrime prosecution—highlighted investigation complexity, cross-border cooperation, and gaps in existing powers for underage offenders. Debate continues over CCROs’ practicality and enforcement.
read more →

EU orders Google to open Android to rival AI agents

📰 The European Commission issued two rulings under the Digital Markets Act requiring Google to open Android to third-party AI assistants and to share search data with rival engines. Google warned the measures could harm user privacy and security, while EU regulators said the steps are needed to ensure fair competition. Security leaders caution CISOs to reassess device and data governance as agents gain system-level reach.
read more →

EU orders Google to open Android sensors to rivals

🔎 The European Commission has ordered Google to grant rival AI assistants the same access to Android sensors and system features that Gemini enjoys, including camera, microphone, screen contents, background controls, and wake-word activation. Google must deliver the changes in the next major release, Android 18, or by 1 August 2027, with some concurrent hotword features delayed until Android 19. The decision, adopted under the Digital Markets Act on 16 July, also requires Google to provide anonymised Search query datasets to competing search engines and AI chatbots under strict safeguards and cost-based fees. The measures define a mix of restricted features requiring certification and open features available to all third-party apps, set up a Qualified AI Assistant Programme, and impose timelines and audit and anonymisation conditions.
read more →

Regulating Corporate Responsibility for AI Privacy

🛡️ Daniel Solove argues in the Wall Street Journal that individual control over personal data is insufficient to protect privacy in the AI era. He urges shifting regulatory focus to hold companies accountable—similar to food and drug oversight—through measures like data minimization, fiduciary duties, and liability for negligent design. Solove also recommends liability for harmful algorithms and multi-stakeholder review of technologies to ensure safer outcomes.
read more →

CISA Guidance Urges Formal Coordinated Disclosure

🔒 CISA and four international cybersecurity agencies have issued joint guidance urging software vendors and online service providers to establish coordinated vulnerability disclosure (CVD) programs. The guidance outlines how to publish clear disclosure policies, maintain communication with researchers, and handle reports for software, hardware, and network products. It supports CISA’s Secure by Design initiative and emphasizes prioritization, exploitability-based assessment, and validating compensating controls when patches are unavailable.
read more →

US launches Gold Eagle to accelerate vulnerability response

🛡️ The US government has launched Gold Eagle, a program led by CISA, the Treasury and the Department of Defense to speed detection and remediation of software vulnerabilities. The initiative, previewed in Executive Order 14409, aims to centralize reporting and reduce duplicate scans, likely using the VINCE platform with public-private participation. Experts warn the plan may not address the core remediation capacity and coordination issues that limit patch deployment.
read more →

UK updates National Risk Register with cyber scenarios

🔒 The UK government has expanded its National Risk Register to include several new cyber-related scenarios affecting digital infrastructure, water systems, policing, and a potential large-scale IT outage. The July 14 update also adds a section on interference in democratic processes, covering attacks on election infrastructure and online information operations. Likelihoods are generally assessed as low but impacts range from moderate to catastrophic, prompting plans for a national resilience campaign to boost household preparedness.
read more →