< ciso
brief />
Tag Banner

All news with #cyber resilience act tag

24 articles

ETSI Proposes 17 Standards for EU Cyber Resilience Act

🛡️ The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 draft cybersecurity standards to align products with the EU Cyber Resilience Act (CRA). The drafts, published on 13 August, define minimum security features—such as modern cryptography, secure-by-default settings, SBOMs and update capabilities—across network, edge, IoT and security product categories. Submissions from 41 member bodies are under public enquiry, with stakeholder comments invited through mid-September to mid-November 2026 and final standards expected by December 2026 ahead of CRA enforcement in December 2027.
read more →

White House Authorizes Private Hack-Back Program

📝 The White House issued a National Security Presidential Memorandum directing the National Coordination Center to establish a program allowing vetted private security firms to apply for authorization to conduct cyber operations against foreign transnational criminal organizations. The program, overseen by executive directors from the Justice and Homeland Security departments, requires companies to post a $1 million bond, adhere to strict legal and constitutional safeguards, and immediately halt activities that exceed approved limits, such as accidentally targeting U.S. systems or citizens. It targets disruption of ransomware, phishing, financial fraud, sextortion, and impersonation schemes and aims to leverage private sector capabilities under government control.
read more →

US Authorizes Private Help in Offensive Cyber Operations

🔒 The White House has approved a memorandum allowing federal law enforcement to collaborate with private companies on limited offensive cyber operations against foreign actors targeting the US. The National Security Presidential Memorandum (NSPM) signed on August 12 builds on earlier executive actions and tasks the Homeland Security Task Force’s National Coordination Center to oversee the program. Rigorous procedures and legal safeguards are promised, while experts warn about attribution difficulties and escalation risks.
read more →

Administration Clears Path for Supervised Private Cyber Operations

🛡️ A presidential memorandum directs the National Coordination Center to establish a program allowing vetted US companies to conduct government-supervised cyber surveillance and cyber effects operations against foreign groups targeting US interests. Participating firms must contract with the DOJ or DHS, undergo vetting, and obtain written approval for each operation, with officials given 60 days to set procedures. The plan raises concerns about collateral damage, attribution errors, corporate liability, and privacy implications for threat intelligence sharing.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

Cloudflare joins UK cyber resilience pledge

🔐 Cloudflare announced it has joined the UK government's Cyber Resilience Pledge as a founding signatory, aligning with the pledge’s pillars of democratized security, leadership accountability, and radical transparency. The post highlights rising cyber threats — including massive DDoS volumes and AI-driven attack vectors — and describes how Cloudflare's global network, zero trust controls, and free protections support resilience across the UK economy. Cloudflare emphasizes supply-chain assurance, board-level governance, and international certifications to meet the pledge's aims.
read more →

UK launches Cyber Resilience Pledge for businesses

🛡️ The UK government announced the Cyber Resilience Pledge, with over 60 businesses signing up after its unveiling at CYBERUK in April alongside a £90m support package. Signatories such as Microsoft UK, Marks & Spencer and Vodafone commit to board-level cyber accountability, NCSC training, Early Warning registration and risk-based Cyber Essentials adoption across supply chains. The scheme targets medium and large firms with the aim of driving baseline security improvements across suppliers.
read more →

The modern CISO is becoming the next CFO

🛡️ The role of the CISO is evolving from a technical operator into a broad, enterprise-level executive responsible for cyber resilience, regulatory compliance, AI governance and business risk. As cyber risk becomes business risk, organizations are expanding security leadership—adding deputy CISOs and specialized teams—while keeping centralized accountability. The author argues the CISO should report independently (e.g., to the CEO, COO or CRO) and that AI increases the need for clear human accountability.
read more →

Seven common cyber risk assessment mistakes to avoid

🔍 A cyber risk assessment should be a decision tool that ties technical findings to business impact, yet many organizations fall into common pitfalls. Experts warn against rote, checklist-driven assessments, sugarcoating results, narrow scoping, and overreliance on risk registers that mask assumptions. Other frequent missteps include failing to link risks to business outcomes, confusing compliance with true security, and neglecting the implications of new technologies like AI. The article outlines seven practical gotchas and recommends context-driven, continuous risk assessment involving business stakeholders to produce actionable, defensible insights.
read more →

Five Eyes Urges Urgent AI-Driven Cyber Resilience

🛡️ The Five Eyes cybersecurity agencies warned on June 22 that frontier AI is already reshaping offensive and defensive cyber capabilities and urged businesses to prioritize cyber resilience. They cautioned that AI accelerates attacks by lowering barriers and shrinking the window between discovery and exploitation, while also offering defensive benefits. The group recommended a whole-of-organization response focused on basics, secure-by-design, defence in depth, and integrating AI into security operations. Practical steps included reducing attack surfaces, accelerating patching, addressing legacy systems, strengthening access controls, and preparing incident response.
read more →

OpenSSF Warns of Poor CRA Readiness in Open Source

🔒 The Open Source Security Foundation (OpenSSF) warns of broad unfamiliarity and structural unreadiness for the EU Cyber Resilience Act (CRA), with 66% of surveyed manufacturers and developers reporting limited awareness. The report highlights confusion over applicability, deadlines, penalties and roles like manufacturers versus stewards, and notes low adoption of full Software Bills of Materials (SBOMs). OpenSSF also flags risky reliance on private forks and passive upstream dependence as potential compliance failures.
read more →

Resilience and Self-Reliance in Cyber Conflict

🛡️ Dmytro Kuleba, Ukraine’s former foreign minister, told Infosecurity Europe that preparation, resilience and self-reliance are crucial for cybersecurity professionals facing wartime threats. He cited KyivStar’s rapid recovery from a December 2023 hack and stressed the value of wargaming and muscle-memory incident response. Kuleba warned that innocuous services such as CRMs can be weaponized and urged businesses to distrust products from potential adversaries.
read more →

AI-Driven Scanning Raises Vulnerability Expectations

🔍 ENISA chief Hans de Vries told ESET World that AI-powered vulnerability scanners mean firms can no longer claim ignorance of software bugs. He warned that the Cyber Resilience Act and emerging AI tools require security by design and that failure to use AI coherently risks exploitation and litigation. The NCSC also expects AI to expose poorly coded systems while vendors adopt AI to remove flaws.
read more →

Europe's Push for Tech Sovereignty and Security Agenda

🔒 European policymakers are accelerating a push for greater tech sovereignty in response to shifting geopolitical trust and concerns over dependence on US and other foreign technologies. The debate spans legal, operational and supply-chain dimensions, with proposals under the EU’s Tech Sovereignty Package and revisions to procurement and the Cybersecurity Act. Achieving autonomy will require investment in local R&D, talent, interoperable systems and realistic timelines, while avoiding protectionist measures that stifle competition. The private sector must factor geopolitical risk into procurement to scale credible European alternatives.
read more →

What Boards Must Demand in the Age of AI Exploitation

⚠️ Boards and executive teams can no longer treat large vulnerability backlogs as a tolerable nuisance: agentic AI has collapsed attackers’ cost and speed of exploitation. Security leaders must present operational truth — not just compliance metrics — about current High and Critical findings, remediation timelines, and exposure costs. Boards should demand measurable remediation programs and a plan to reduce vulnerability accrual at the source. Regulation such as CRA and DORA raise legal and financial stakes, and 'patch faster' is not a complete answer when emergency fixes risk production outages.
read more →

Navigating Fragmented Cybersecurity Regulation in Europe

🔎 This Fortinet podcast episode examines the evolving EU-centric cybersecurity regulatory landscape and its implications for global businesses. Host Joe Robertson speaks with Dr. Tommaso De Zan of Access Partnership about layered rules such as NIS2, the Cyber Resilience Act, DORA, and emerging cloud sovereignty initiatives. They contrast horizontal and vertical regulations, highlight differences between regulations and directives, and emphasize that industry accepts rules but resents uncertainty. Practical advice includes early policy monitoring, engagement in consultations, and embedding security into products and operations.
read more →

Germany to Authorize Cross-Border Cyber Counterstrikes

🛡️ Germany plans to adopt a more offensive cyber posture, saying it will "strike back, also abroad," and aim to disrupt attackers and destroy their infrastructure. The Interior Ministry proposes joint operational responsibility for the Federal Criminal Police Office (BKA) and intelligence services and is creating a new defense center against hybrid threats. Minister Alexander Dobrindt said he will introduce laws in the first half of the year to expand intelligence powers for information gathering and operational action.
read more →

World Economic Forum: AI, Geopolitics and Rising Cyber Risk

🔍 The World Economic Forum’s Global Cybersecurity Outlook warns cybersecurity risk will accelerate in 2026, driven primarily by advances in AI, deepening geopolitical fragmentation and supply‑chain complexity. Based on survey responses from 804 leaders (including 316 CISOs) across 92 countries, the report finds eroding confidence in national preparedness and divergent priorities between CEOs and CISOs. It highlights both the risk and defensive potential of AI and calls for strengthening collective cyber resilience through collaboration, governance and balanced adoption with robust safeguards.
read more →

Parliament Seeks Industry Input on Cyber Security Bill

🏛️ The Parliamentary Public Bill Committee is inviting industry submissions to inform scrutiny of the Cyber Security and Resilience Bill (CSRB), the planned successor to the NIS Regulations 2018. Now at committee stage after its second reading, the bill proposes expanded scope, tighter incident-reporting, mandatory supply‑chain risk management and alignment with the NCSC Cyber Assessment Framework. The committee will hear oral evidence from 3 February and has urged prompt written responses as it may conclude early.
read more →

Vaillant CISO: From Technology to Strategic Cyber Leadership

🔒 Raphael Reiß, CISO at Vaillant Group, warns that rising geopolitical tensions and increasingly professional cybercriminals — now aided by AI — have lowered the barrier to complex attacks. Vaillant applies a holistic, multilayered security approach that spans IT, global production and customer-facing products, combining preventive and reactive controls. Reiß emphasises people-first awareness training and pragmatic compliance with standards such as NIS2, DORA and the Cyber Resilience Act. His advice is direct: analyse your starting point and start rather than wait.
read more →