< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 7 of 24

FTC to Bar Kochava From Selling Americans' Location Data

🔒 The Federal Trade Commission will ban data broker Kochava and its subsidiary Collective Data Solutions (CDS) from selling precise geolocation data without consumers' affirmative express consent as part of a settlement stemming from an August 2022 suit. The FTC alleged Kochava supplied paid clients — via an AWS Marketplace feed — with high-volume raw latitude/longitude transactions that enabled tracking to sensitive sites. Under the proposed court order, sales or transfers of precise location data are prohibited unless consumers directly request a service and explicitly consent; the companies must also implement a sensitive location program, supplier assessments, consent withdrawal and disclosure mechanisms, incident reporting to the FTC, and retention/deletion schedules.
read more →

CISA Launches CI Fortify to Bolster Infrastructure Resilience

🔒 CISA released new guidance called CI Fortify to help critical infrastructure organizations prepare to operate through crises and conflicts and continue delivering essential services while under cyberattack. The guidance centers on two emergency capabilities: Isolation — proactively disconnecting from third-party dependencies and operating without reliable telecommunications — and Recovery — rapidly restoring compromised systems while isolated. CISA urges organizations to begin investing now, test recovery plans, and practice local and manual operations to maintain a baseline of continuity.
read more →

White House Weighs Pre-Release Checks for High-Risk AI

🛡️ The White House is privately discussing whether advanced AI models that could enable cyberattacks should undergo government-led or formal pre-release reviews before public deployment. The talks were prompted by Anthropic’s Mythos, which the company says has identified thousands of high-severity vulnerabilities, and by comparable capabilities from other labs. Officials are weighing options including formal vetting and targeted testing for higher-risk systems. No policy has been finalized and no timeline has been set.
read more →

Regulator Warns: Frontier AI Models Heighten Bank Cyber Risk

⚠ APRA warns that frontier AI models such as Claude Mythos pose a rapidly evolving cyber risk to the banking sector by enabling faster, more automated discovery of vulnerabilities. The regulator found governance often treats AI as “just another technology,” missing distinctive features like predictive behavior, adaptability, bias and data risks, and urged firms to accelerate vulnerability identification and remediation. APRA called for robust security testing of AI‑generated code and deeper assessment of major AI platforms to avoid attackers outpacing current patch cycles.
read more →

US Agencies Issue Zero Trust Guidance for OT Security

🔒 A joint guide from CISA and federal partners outlines how to adapt zero trust principles to operational technology (OT) environments while preserving safety and uptime. It details practical measures such as passive asset discovery, network segmentation, microsegmentation, identity and access controls tailored to legacy devices, and secure remote access via jump hosts with MFA. The guidance calls out risks from IT/OT convergence, including credential compromise, supply-chain vulnerabilities and malware that can disrupt physical processes. It emphasizes compensating controls where modern security features cannot be deployed, and the need for close IT–OT collaboration and integrated incident response.
read more →

CISA Urges Zero Trust Adoption for Operational Technology

🔒 CISA has instructed owners and operators of operational technology to stop assuming network safety and released joint guidance, Adapting Zero Trust Principles to Operational Technology, to apply Zero Trust to systems supporting power, water, transportation, building automation, and weapons-support infrastructure. The 28-page guide — developed with the Department of War, Department of Energy, FBI, State Department and NIST technical input — emphasizes assuming adversaries are inside, validating access by identity, context, and risk, and tailoring controls to OT constraints like latency and safety.
read more →

Adapting Zero Trust Principles for Operational Technology

🔒 CISA, in coordination with the Department of War, Department of Energy, Federal Bureau of Investigation, and Department of State, published joint guidance on applying Zero Trust principles to operational technology. The guidance addresses IT-OT convergence risks, legacy infrastructure limitations, operational and safety constraints, and recommends layered controls such as asset visibility, identity and access management, network segmentation, secure communication protocols, and vulnerability management. It emphasizes continuous validation of access and proactive supply chain risk management to protect critical physical processes.
read more →

Guide to Accelerate Zero Trust for Operational Technology

🔐 CISA and U.S. government partners published Adapting Zero Trust Principles to Operational Technology, a practical guide for OT owners, operators, and Zero Trust practitioners. The guidance explains how to apply Zero Trust in OT environments while minimizing risk to mission-critical systems and accommodating legacy constraints and safety requirements. It highlights establishing zones and conduits, addressing supply chain risks, and implementing robust identity and access management to reduce exposure and strengthen resilience.
read more →

US Sanctions Target Leaders of Cambodian Crypto Scam

🔒 The US Treasury's Office of Foreign Assets Control (OFAC) has designated Senator Kok An and 28 other individuals and entities accused of running a Cambodian network that orchestrated large-scale cryptocurrency fraud. Authorities say scammers operated from compounds embedded in casinos and commercial buildings, using romance lures and fake investment platforms to steal digital assets. The sanctions freeze US-linked assets and bar transactions by US persons to disrupt the network's financial and operational infrastructure.
read more →

House GOP Privacy Bills Challenge Enterprise Data Practices

📜 The House Republican proposals — the SECURE Data Act and the GUARD Financial Data Act — would establish federal privacy standards that broadly preempt stronger state laws while limiting private lawsuits and centralizing enforcement with the FTC and state attorneys general. The bills emphasize data minimization, controller-processor obligations, a federal data broker registry, and new limits on automated profiling and teen data. Critics warn the measures could weaken existing protections, impose heavy operational burdens on CIOs and CISOs, and force vendors and legal teams to rework procurement, retention, and AI training practices.
read more →

DORA and Operational Resilience: Credential Controls

🔐 DORA's Article 9 makes credential management a binding financial risk control for EU financial entities, requiring least-privilege access, phishing‑resistant FIDO2/WebAuthn authentication, and cryptographic key protection. The regulation extends to third-party providers and mandates evidenceable controls. Organisations must deploy vaulting, JIT access, and continuous monitoring to reduce dwell time and meet supervisory expectations.
read more →

Plankey Withdraws After Stalled CISA Nomination Fight

⚠️ Sean Plankey has withdrawn his nomination to lead CISA after a 13-month delay marked by bipartisan holds, unverified allegations, and reported Senate maneuvering. Plankey was first nominated last March, renominated in January, and faced objections from Sen. Rick Scott and Sen. Ron Wyden while working on Coast Guard issues. Conflicting reports — including a contested claim he was escorted out of Coast Guard headquarters — and questions about past financial ties surfaced but remain unresolved. Observers warn the leadership vacuum, amid staff and budget cuts at the agency, poses tangible national security risks; Plankey says he supports the administration’s next nominee.
read more →

UK NCSC Urges Businesses to Offer Passkeys by Default

🔐The UK National Cyber Security Centre now recommends offering passkeys as the default authentication option for consumer accounts, saying passwords are "no longer resilient enough" for modern threats. The agency highlights that FIDO2-based passkeys rely on device-bound cryptographic keys and local verification (biometrics or PINs), making them resistant to phishing and credential reuse. Where passkeys are not yet supported it advises using password managers and strong multi-factor verification, and warns organisations to secure account recovery and fallback processes.
read more →

NCSC Endorses Passkeys as Default Consumer Login Option

🔐 The UK’s National Cyber Security Centre (NCSC) now recommends passkeys as the preferred sign-in method for consumers, advising passwords only when passkeys are unavailable. This follows a year of collaboration with the FIDO Alliance, observed improvements across the passkey ecosystem and successful NHS deployments. The NCSC also urges businesses to adopt passkeys as the default and to use single sign-on (SSO) where possible, with additional business guidance expected.
read more →

UK Commits £90m to Cybersecurity and Resilience Pledge

🔐 The UK government has pledged £90m to bolster national cyber resilience, announced at the NCSC's CYBERUK conference on 22 April, with a particular emphasis on supporting small and medium-sized enterprises. The funding will promote adoption of the Cyber Essentials standard, which recently passed a 10,000 quarterly certification milestone and saw around a 20% uplift in uptake. Ministers will also launch an Cyber Resilience Pledge this summer requiring signatories to make cyber security a board-level responsibility, join the NCSC Early Warning service and mandate Essentials across supply chains.
read more →

UK's Ofcom Investigates Telegram and Teen Chat Sites

🕵️ Ofcom has opened an investigation under the UK's Online Safety Act after receiving evidence that Telegram is being used to share child sexual abuse material (CSAM). The regulator says its probe followed reports from the Canadian Centre for Child Protection and its own assessment. Ofcom is also examining teen chat services Teen Chat and Chat Avenue, and has separately scrutinised X over AI-generated nonconsensual explicit content. Where breaches are found, Ofcom can seek fines up to £18 million or 10% of qualifying worldwide revenue and, in serious cases, request court orders to disrupt or block services in the UK.
read more →

NCSC outlines coordinated NHS plan to boost cyber resilience

🔒 The NCSC has published a coordinated plan to improve NHS cyber resilience, focusing on piloting tools via ACD 2.0, securing the software supply chain, managing vulnerability disclosures, enhancing visibility and promoting services such as Early Warning, the Cyber Action Toolkit and Cyber Essentials. The agency is applying the Software Security Code of Practice in procurement and using data science to prioritise supplier risk while its Vulnerability Reporting Service continues to support GP surgeries, trusts and health boards. Additional measures include the NHS App adopting passkeys, attack surface management, deception-technology experiments, DNS analytics and Threat Hunting Workshops to develop playbooks and strengthen sector collaboration.
read more →

NIST will stop rating lower-priority vulnerabilities

🔍 NIST will stop providing severity scores and detailed enrichment for lower-priority CVEs beginning April 15, citing a surge in submissions that has overwhelmed its capacity. The National Vulnerability Database will continue to list all reported CVEs, but entries deemed low priority will keep only the severity assigned by the submitting CNA. NIST will only add detailed analysis for issues in CISA’s KEV, those affecting U.S. federal software, or critical software defined by EO 14028; organizations may request enrichment for low-priority entries via email to nvd@nist.gov.
read more →

White House Enables Federal Access to Anthropic's Mythos

🔒The White House Office of Management and Budget is preparing protections to allow federal agencies to use a modified version of Anthropic's Claude Mythos model, according to an internal memo reported by Bloomberg. OMB CIO Gregory Barbaccia told Cabinet departments the agency is coordinating with model providers, industry partners, and the intelligence community to establish guardrails before potential release. The move comes while the Department of Defense's supply-chain risk designation against Anthropic remains in force, leaving the vendor barred from defense contracts.
read more →

NIST narrows CVE enrichment to high-priority cases

🔒 NIST will only enrich CVEs in its NVD that meet defined high-priority criteria, citing a 263% surge in submissions from 2020–2025 that overwhelmed its enrichment capacity. Effective April 15, 2026, NIST will prioritize CVEs in CISA's KEV catalog, those affecting software used by the federal government, and software designated critical under EO 14028. CVEs that do not meet those thresholds will remain listed but be marked "Not Scheduled"; stakeholders may request targeted enrichment via email.
read more →