Cyber Cookie mascotCyber Cookie
Menu ▾

Section Archive

Compliance Pulse

77 entries across all issues

Issue #87· September 11, 2026
Compliance Pulse

EU Cyber Resilience Act: 24-Hour Breach Reporting Starts Today

Starting today, any organisation that sells internet-connected products in the EU must report actively exploited vulnerabilities or serious security incidents to ENISA (the European Union Agency for Cybersecurity) within 24 hours of discovery, per Dark Reading. A fuller notification is due within 72 hours. Missing the window risks fines of up to €15 million or 2.5% of global annual revenue. Physical location doesn't matter — if you sell into EU markets, this applies to you. Small enterprises under 50 employees have limited exemptions; larger organisations do not.

Issue #85· September 9, 2026
Compliance Pulse

FBI Publishes Its First Public Cybersecurity Strategy

The FBI has released a 17-page public cybersecurity strategy, its first ever, according to The Record. The document outlines four pillars: imposing costs on attackers, supporting victims, working with private industry, and building the FBI's own digital capabilities. The bureau says it will pursue more frequent disruptive operations rather than waiting for large-scale joint actions a handful of times a year. For everyday users, this signals a more aggressive federal posture toward ransomware gangs and state-sponsored hackers.

Issue #83· September 7, 2026
Compliance Pulse

No major compliance or regulatory updates today.

The BSI advisory referenced in today's Berlin breach story is an operational warning rather than a new regulation or mandate. No new government directives, data protection authority rulings, or legislative changes affecting cybersecurity compliance were announced in the last 24 hours.

Issue #81· September 4, 2026
Compliance Pulse

US and UK Sign Formal Agreement to Coordinate Scam Compound Takedowns

The United States Department of Justice and the UK's National Crime Agency signed a memorandum of understanding this week committing both countries to parallel investigations and shared intelligence on the organised crime networks running Southeast Asian scam compounds, according to The Record. More than $12 billion was stolen from Americans alone last year through these schemes. The two agencies have already identified overlapping cases and plan a joint disruption event in London in October.

Issue #79· August 31, 2026
Compliance Pulse

ChatGPT, Reddit, and Roblox Now Under EU's Toughest Platform Rules

The European Commission has designated ChatGPT, Reddit, and Roblox as Very Large Online Platforms or Search Engines under the Digital Services Act (DSA — EU rules requiring large platforms to actively manage harmful content and systemic risks). All three declared over 45 million monthly EU users. They now have until January 2027 to comply with obligations including risk assessments for illegal content, algorithmic transparency, and protections for minors. For everyday users, this means stronger rights around how these platforms moderate content and handle your data.

Issue #77· August 28, 2026
Compliance Pulse

White House Bans Foreign-Made Power Grid Equipment Over Backdoor Risk

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity transmission and generation, citing concerns that equipment may contain digital backdoors allowing foreign governments remote access, according to The Record.

The order covers high-voltage transmission infrastructure, control rooms, substations, and associated software. Senior officials have 120 days to produce rules identifying which countries "warrant particular scrutiny." Agencies must also inventory currently deployed at-risk equipment and submit replacement plans.

For critical infrastructure operators, compliance reviews should begin now rather than at the 120-day deadline.

Issue #75· August 26, 2026
Compliance Pulse

CISA: Over 100 Water Systems Hit in July, Linked to Iranian Threat Actors

CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks in July 2026, according to Security Week. The attacks, linked to Iranian threat actors, focused on programmable logic controllers (PLCs — the computers that physically operate industrial equipment) connected directly to the public internet via cellular modems. At least 12 states were affected, though no significant disruption occurred. CISA has published updated guidance urging water utilities to remove unnecessary internet exposure, enforce multi-factor authentication, and monitor industrial control systems continuously.

Issue #73· August 24, 2026
Compliance Pulse

Uber Handed €825 Million GDPR Fine Over Automated Driver Decisions

The Dutch Data Protection Authority has fined Uber €825 million ($964 million) for violating the EU's General Data Protection Regulation (GDPR — the EU's rules governing how companies handle personal data), according to SecurityWeek. The authority found Uber used automated software to permanently suspend driver accounts between 2018 and 2022 with no human review and no meaningful notice to drivers. GDPR prohibits fully automated decisions that significantly affect people. Uber has said it will appeal. For anyone who earns income through platform apps, this ruling is a reminder that automated bans without human oversight are increasingly the target of regulators across Europe.

Issue #72· August 24, 2026
Compliance Pulse

TikTok Pays $400 Million Over Children's Privacy Violations

TikTok has settled a US Department of Justice lawsuit for $400 million, resolving allegations it collected personal data from children under 13 without parental consent — and ignored parent requests to delete those accounts, according to Security Week. The case was brought under COPPA (the Children's Online Privacy Protection Act), the federal law requiring parental consent before collecting data from young children. If your child uses TikTok, review their account settings and check what data the app holds. You have the right to request deletion.

Issue #70· August 21, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch Critical MLflow Flaw Within Two Weeks

CISA has added CVE-2026-64849 to its Known Exploited Vulnerabilities catalogue and ordered U.S. federal agencies to patch within two weeks, according to Bleeping Computer. MLflow is an open-source platform used to build and manage AI applications. The flaw allows an unauthenticated attacker to reach internal systems and steal cloud credentials such as AWS access keys. Attackers began scanning for vulnerable instances within hours of the CVE being assigned.

What you should do: If your organisation uses MLflow, upgrade to version 3.15.0 immediately and audit your logs for signs of unauthorised access.