< ciso
brief />
Regulation and Policy Brief Banner

All news in category “Regulation and Policy Brief”

468 articles · page 8 of 24

Insurers Retreat from Covering AI-Generated Outputs

🛡️ Several major insurers are quietly limiting or excluding coverage for losses tied to AI-generated outputs across cybersecurity and errors-and-omissions policies. Carriers cite inability to trace model reasoning and nondeterministic outputs, prompting policy carve-outs, declinations for AI vendors, and premium increases for AI use. Underwriters are probing customers' AI governance and distinguishing governed deployments from experimental systems.
read more →

ENISA Seeks Top-Level Role in CVE Program Governance

🔐 ENISA is pursuing top-level root status in the CVE Program as it is being onboarded by the US Cybersecurity and Infrastructure Security Agency (CISA) to become a TL-Root CNA. Agency leaders told VulnCon26 attendees the move, targeted for 2026 or early 2027, would secure European representation on the CVE Program Board. ENISA plans to onboard EU national CERTs and CSIRTs as CNAs and is expanding its vulnerability team to support this role.
read more →

UK Cyber Security Council Adds Associate Professional Title

🔐 The UK Cyber Security Council has launched a new Associate Cyber Security Professional title, with applications open from 13 April to 17 May. The entry-level certification places holders on the UK Cyber Security Professional Register, requiring demonstration of competence across five key areas and a commitment to 75 hours of CPD over three years. Applicants can fast-track if they hold aligned qualifications, and the scheme aims to help early-career candidates prove their readiness to employers.
read more →

Federal Cyber Funding Shifts in Trump’s 2027 Budget

🔍 The Trump administration's proposed 2027 budget trims total civilian federal cybersecurity funding by about $227 million, falling from $12.455 billion in 2026 to $12.228 billion in 2027. The request directs the largest increases to the Department of Justice (+$312M) and State (+$174M) while cutting Department of Homeland Security cyber funding and imposing deep reductions at CISA and the NSF. Enterprises should reassess dependencies on federal cyber support, accelerate private-sector threat intelligence ties, and review compliance assumptions given reduced federal capacity.
read more →

CMMC 2.0 Compliance: Scaling Controls with AI and Automation

🔒 CMMC 2.0 requires federal contractors to demonstrate how they protect controlled unclassified information (CUI), shifting assessments from self-attestation to verified evidence. The standard prioritizes a risk-based, environment-specific approach that values documented, defensible safeguards rather than one-size-fits-all controls. That change elevates the need for clear data scoping, consistent administrative processes and reliable evidence capture. Automation and governed AI can streamline recurring reviews and produce verifiable artifacts, but only if organizations mature processes and explicitly document AI use and data flows.
read more →

Hong Kong Police Can Force Disclosure of Encryption Keys

🔐 On March 23, 2026, Hong Kong authorities amended enforcement of the National Security Law, allowing police to demand passwords or other assistance to access personal electronic devices, including phones, laptops, and hard drives. The U.S. Consulate General issued a security alert on March 26 warning that refusal to comply is now a criminal offense. Authorities may also seize and retain devices they allege are linked to national security offenses. The change applies even to travellers transiting the airport.
read more →

Shifting to Proactive Cyber: Disruption Over Passive Defense

🔒 The White House's new cyber strategy and recent moves by major tech firms mark a clear shift from reactive defense toward proactive cyber, emphasizing disruption of adversaries earlier in the attack chain. Industry leaders frame this as the legal, intelligence-driven use of takedowns, litigation, public exposure of tools, and product hardening to impose cost and friction on attackers. While large platform providers can act at scale, enterprises are urged to focus on fundamentals, share telemetry, and support coordinated disruption rather than conduct offensive operations themselves.
read more →

Cambodia Enacts Tough New Law Against Scam Compounds

🔒 Cambodia has enacted the Law on Combating Online Scams, effective immediately, imposing steep penalties for organisers of scam compounds. The law threatens ringleaders with 5–10 years imprisonment and fines up to $250,000, escalating to 10–20 years and larger fines where violence, forced labour, or trafficking are involved. It also shields coerced victims from prosecution.
read more →

New Mexico Ruling Threatens End-to-End Encryption Safety

🔒 Mike Masnick argues the New Mexico court ruling against Meta applies a troubling 'design choices create liability' framework that could undermine end-to-end encryption. The state used Meta's 2023 decision to add E2EE in Messenger as evidence that the company 'shielded' predators, and is seeking court-ordered changes to 'protect minors from encrypted communications.' The ruling risks forcing companies to weaken security features and stop documenting internal safety tradeoffs.
read more →

U.S. Bans Import of Foreign-Made Consumer Routers Nationwide

🔒 The Executive Branch has determined that foreign-made consumer routers create a supply-chain vulnerability and pose a severe cybersecurity risk that could disrupt U.S. critical infrastructure and harm U.S. persons. Any new router manufactured outside the United States must receive FCC approval before it can be imported, marketed, or sold; approval requires disclosure of foreign investors or influence and a plan to shift manufacturing to the U.S. Certain devices may be exempted by the Department of Defense or DHS, though neither agency has listed exceptions yet. Existing home routers do not need to be discarded, and market impacts may favor companies able to produce domestically, such as Starlink, while vendors like Netgear—which manufactures abroad—face new compliance and cost pressures.
read more →

U.S. Cyber Strategy Signals Possible Private Hackback

🛡️ The 2026 U.S. Cyber Strategy for America largely reiterates longstanding White House cyber priorities but adopts a noticeably more aggressive tone. One sentence — “We will unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities.” — reads like an explicit invitation for corporate hackback. The author argues this is a dangerous and ill-considered idea because it risks misattribution, vigilantism, extrajudicial punishment, and escalation rather than strengthening security.
read more →

FBI Advises Caution Using Chinese Mobile Apps Over Privacy

🔒 The FBI has issued a public service announcement warning Americans about privacy and data-security risks posed by foreign-developed mobile applications, particularly those maintained by Chinese companies. The bureau says some apps may collect extensive personal data — even when only active — and may store information on servers in China or require consent to share data. The FBI recommends disabling unnecessary sharing, updating device software, and installing apps only from official app stores.
read more →

Evolving Expectations of What's Possible with AI in Privacy

🔒 Kent Walker, Google's President of Global Affairs, outlined how rapidly evolving user expectations are shaping AI development at the IAPP Global Summit 2026. He highlighted Personal Intelligence in Search and the Ukraine national assistant Diia.AI as examples of context-aware, task-oriented assistants. Google’s rollout approach emphasizes trusted testers, staged expansion, continuous feedback, and clear controls over agents’ access, while applying guardrails such as Gemini avoiding proactive assumptions. Walker urged investment in privacy-enhancing technologies, new transparency models, and global standards to align data protection with these innovations.
read more →

ICO fines UK alarm provider £100,000 for nuisance calls

📞 The Information Commissioner’s Office (ICO) fined Birmingham-based monitored alarm provider TMAC £100,000 after staff used false identities on marketing sales calls and the firm made over 260,000 calls to numbers registered on the Telephone Preference Service. The ICO said TMAC deliberately targeted individuals over 60 between February and September 2024, impersonating local crime and fire prevention initiatives to trick recipients. The regulator stressed these actions breached the Privacy and Electronic Communications Regulations and highlighted the importance of public reporting in enabling enforcement.
read more →

UK Sanctions Chinese Crypto Marketplace Xinbi over Scam Hubs

🚨 The UK has imposed sanctions on the China-based cryptocurrency marketplace Xinbi, accusing it of enabling large-scale scam operations across Southeast Asia and facilitating crypto laundering. Authorities say Xinbi, which reportedly handled over $19.7 billion of inflows, sold victim data and traded satellite internet equipment used to contact targets. The action targets Xinbi and related firms and individuals linked to the Prince Group and #8 Park, and includes plans to freeze London properties.
read more →

UK Sanctions Xinbi Marketplace Linked to Asian Scam Centers

🚫 The UK’s Foreign, Commonwealth and Development Office has sanctioned Xinbi, a Chinese-language marketplace accused of selling stolen personal data and satellite internet equipment to Southeast Asian scam networks and assisting North Korean actors with cryptocurrency laundering. Chainalysis links Xinbi to over $19.9 billion in transactions from 2021–2025. The measures also target #8 Park and operator Legend Innovation Co, aiming to sever Xinbi from legitimate crypto services and disrupt payments to scam centers.
read more →

AI Regulation Emerges as Central Issue in U.S. Midterms

🗳️The December Trump executive order constrains state AI regulation by directing federal lawsuits and withholding funds from states that attempt limits, effectively prioritizing industry interests over local consumer protections. Polling in 2025 shows broad bipartisan support for greater state and federal oversight, yet the order reshapes political fault lines ahead of the midterms. Candidates may use AI as a wedge—highlighting job displacement, datacenter opposition, and corporate concentration—while organizers work to broaden the debate beyond local fights.
read more →

FCC Bans Import and Sale of All Foreign-Made Routers

🔒 The FCC has banned the import and sale of all consumer-grade internet routers manufactured in foreign countries, saying they pose an 'unacceptable risk' to US national security. The rule, announced on 23 March, allows only devices with conditional DoD or DHS approval, effectively blocking most future consumer models because many are made abroad. The agency cited incidents such as the Volt, Flax and Salt Typhoon attacks, while industry experts caution that governance, patching and lifecycle management — not just country of origin — drive much of the risk.
read more →

Wyden Raises Alarm Over Hidden Section 702 Secret Law

🔔 Sen. Ron Wyden warned on the Senate floor that a classified, previously undisclosed interpretation of Section 702 is affecting Americans’ privacy and has been withheld from public and congressional debate. He raised the issue while opposing the nomination of Joshua Rudd to lead the NSA, citing Rudd’s unwillingness to accept basic constitutional limits on surveillance. Wyden said he has repeatedly asked administrations to declassify the matter and is still awaiting a response from DNI Gabbard. He urged Congress to openly debate the matter before Section 702 is reauthorized.
read more →

FCC Blocks New Foreign-Made Consumer Routers Nationwide

🔒 The FCC announced a ban on imports of new foreign-made consumer routers, citing unacceptable cyber and national security risks after an Executive Branch determination. New models are placed on the Covered List unless granted Conditional Approval by the Department of War or DHS; Starlink routers are exempt. Existing customer-owned devices and previously authorized models remain legal to use and sell.
read more →