Cyber Cookie mascotCyber Cookie
Menu ▾

Section Archive

Compliance Pulse

77 entries across all issues

Issue #87· September 11, 2026
Compliance Pulse

EU Cyber Resilience Act: 24-Hour Breach Reporting Starts Today

Starting today, any organisation that sells internet-connected products in the EU must report actively exploited vulnerabilities or serious security incidents to ENISA (the European Union Agency for Cybersecurity) within 24 hours of discovery, per Dark Reading. A fuller notification is due within 72 hours. Missing the window risks fines of up to €15 million or 2.5% of global annual revenue. Physical location doesn't matter — if you sell into EU markets, this applies to you. Small enterprises under 50 employees have limited exemptions; larger organisations do not.

Issue #85· September 9, 2026
Compliance Pulse

FBI Publishes Its First Public Cybersecurity Strategy

The FBI has released a 17-page public cybersecurity strategy, its first ever, according to The Record. The document outlines four pillars: imposing costs on attackers, supporting victims, working with private industry, and building the FBI's own digital capabilities. The bureau says it will pursue more frequent disruptive operations rather than waiting for large-scale joint actions a handful of times a year. For everyday users, this signals a more aggressive federal posture toward ransomware gangs and state-sponsored hackers.

Issue #83· September 7, 2026
Compliance Pulse

No major compliance or regulatory updates today.

The BSI advisory referenced in today's Berlin breach story is an operational warning rather than a new regulation or mandate. No new government directives, data protection authority rulings, or legislative changes affecting cybersecurity compliance were announced in the last 24 hours.

Issue #81· September 4, 2026
Compliance Pulse

US and UK Sign Formal Agreement to Coordinate Scam Compound Takedowns

The United States Department of Justice and the UK's National Crime Agency signed a memorandum of understanding this week committing both countries to parallel investigations and shared intelligence on the organised crime networks running Southeast Asian scam compounds, according to The Record. More than $12 billion was stolen from Americans alone last year through these schemes. The two agencies have already identified overlapping cases and plan a joint disruption event in London in October.

Issue #79· August 31, 2026
Compliance Pulse

ChatGPT, Reddit, and Roblox Now Under EU's Toughest Platform Rules

The European Commission has designated ChatGPT, Reddit, and Roblox as Very Large Online Platforms or Search Engines under the Digital Services Act (DSA — EU rules requiring large platforms to actively manage harmful content and systemic risks). All three declared over 45 million monthly EU users. They now have until January 2027 to comply with obligations including risk assessments for illegal content, algorithmic transparency, and protections for minors. For everyday users, this means stronger rights around how these platforms moderate content and handle your data.

Issue #77· August 28, 2026
Compliance Pulse

White House Bans Foreign-Made Power Grid Equipment Over Backdoor Risk

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity transmission and generation, citing concerns that equipment may contain digital backdoors allowing foreign governments remote access, according to The Record.

The order covers high-voltage transmission infrastructure, control rooms, substations, and associated software. Senior officials have 120 days to produce rules identifying which countries "warrant particular scrutiny." Agencies must also inventory currently deployed at-risk equipment and submit replacement plans.

For critical infrastructure operators, compliance reviews should begin now rather than at the 120-day deadline.

Issue #75· August 26, 2026
Compliance Pulse

CISA: Over 100 Water Systems Hit in July, Linked to Iranian Threat Actors

CISA has confirmed that more than 100 internet-exposed water and wastewater systems were targeted in cyberattacks in July 2026, according to Security Week. The attacks, linked to Iranian threat actors, focused on programmable logic controllers (PLCs — the computers that physically operate industrial equipment) connected directly to the public internet via cellular modems. At least 12 states were affected, though no significant disruption occurred. CISA has published updated guidance urging water utilities to remove unnecessary internet exposure, enforce multi-factor authentication, and monitor industrial control systems continuously.

Issue #73· August 24, 2026
Compliance Pulse

Uber Handed €825 Million GDPR Fine Over Automated Driver Decisions

The Dutch Data Protection Authority has fined Uber €825 million ($964 million) for violating the EU's General Data Protection Regulation (GDPR — the EU's rules governing how companies handle personal data), according to SecurityWeek. The authority found Uber used automated software to permanently suspend driver accounts between 2018 and 2022 with no human review and no meaningful notice to drivers. GDPR prohibits fully automated decisions that significantly affect people. Uber has said it will appeal. For anyone who earns income through platform apps, this ruling is a reminder that automated bans without human oversight are increasingly the target of regulators across Europe.

Issue #72· August 24, 2026
Compliance Pulse

TikTok Pays $400 Million Over Children's Privacy Violations

TikTok has settled a US Department of Justice lawsuit for $400 million, resolving allegations it collected personal data from children under 13 without parental consent — and ignored parent requests to delete those accounts, according to Security Week. The case was brought under COPPA (the Children's Online Privacy Protection Act), the federal law requiring parental consent before collecting data from young children. If your child uses TikTok, review their account settings and check what data the app holds. You have the right to request deletion.

Issue #70· August 21, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch Critical MLflow Flaw Within Two Weeks

CISA has added CVE-2026-64849 to its Known Exploited Vulnerabilities catalogue and ordered U.S. federal agencies to patch within two weeks, according to Bleeping Computer. MLflow is an open-source platform used to build and manage AI applications. The flaw allows an unauthenticated attacker to reach internal systems and steal cloud credentials such as AWS access keys. Attackers began scanning for vulnerable instances within hours of the CVE being assigned.

What you should do: If your organisation uses MLflow, upgrade to version 3.15.0 immediately and audit your logs for signs of unauthorised access.

Issue #68· August 19, 2026
Compliance Pulse

CISA: Medusa Ransomware Has Now Hit Over 500 Critical Infrastructure Organisations

CISA, leading a joint advisory with the FBI and the Department of Health and Human Services, confirmed that the Medusa ransomware gang has breached more than 500 critical infrastructure organisations in the United States since 2021 — up from 300 just over a year ago, according to Bleeping Computer. Targets include healthcare, finance, government, and education. The advisory recommends patching known vulnerabilities, segmenting networks to limit lateral movement (an attacker's ability to move from one system to others once inside), and blocking untrusted remote access.

Issue #66· August 16, 2026
Compliance Pulse

CISA Adds Cisco Firewall Flaw to Its Must-Patch List

CISA — the US Cybersecurity and Infrastructure Security Agency — has added CVE-2026-20349, a high-severity vulnerability in Cisco firewall software, to its Known Exploited Vulnerabilities catalog. The flaw is actively being used to temporarily knock Cisco firewalls offline. US civilian federal agencies were required to apply fixes by 14 August 2026. If your organisation runs Cisco firewalls and has not yet patched, treat this as urgent. Full details are available via Help Net Security.

Issue #65· August 15, 2026
Compliance Pulse

France's Tax Authority Confirms Breach of Up to 600,000 Citizens' Records

France's Directorate General of Public Finances (DGFiP) confirmed that an attacker accessed its internal systems in late June after stealing or misusing an employee's identity, according to The Record. A hacker using the alias ZeroBytes claims to have extracted data on over 600,000 people, including tax identification numbers, family details, and financial status — the kind of data that enables highly targeted fraud. French authorities have opened a criminal complaint and will notify affected individuals. It is the latest in a string of French government breaches this year.

Issue #64· August 14, 2026
Compliance Pulse

EU Cyber Resilience Act: 17 Draft Standards Open for Comment

Seventeen draft technical standards for the EU's Cyber Resilience Act (a law requiring connected products sold in Europe to meet mandatory cybersecurity requirements) are now open for review, according to Help Net Security. The standards cover products including smart home assistants, password managers, and connected toys. Manufacturers who follow an approved standard gain a presumption of legal compliance. The comment window closes between mid-September and mid-November 2026, with the full obligation kicking in at the end of 2027. Small businesses selling any connected hardware or software into European markets should read the relevant draft now, not after the deadline.

Issue #63· August 13, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch CVE-2026-68820 by 25 August

The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-68820, the Windows WinSock privilege escalation flaw exploited by North Korea's Lazarus Group, to its Known Exploited Vulnerabilities catalogue, according to The Record. Federal agencies have until 25 August to apply the patch. For everyone else, the directive underlines what the evidence already shows: this is the only confirmed in-the-wild exploit from August's Patch Tuesday. A device restart is required and no workaround exists.

Issue #62· August 12, 2026
Compliance Pulse

CISA Confirms Ransomware Gangs Are Actively Exploiting a SharePoint RCE Flaw

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to confirm that ransomware groups are actively exploiting CVE-2026-45659, a high-severity SharePoint flaw that allows low-privileged attackers to execute code on unpatched servers, per Bleeping Computer. Federal agencies were ordered to patch within three days of the July 1 listing. Shadowserver currently tracks over 8,500 SharePoint servers exposed online, with more than 200 still unpatched. If you run SharePoint on-premises, apply Microsoft's latest patches now and enable Windows Antimalware Scan Interface (AMSI) integration for your SharePoint web applications.

Issue #61· August 11, 2026
Compliance Pulse

US Senators Propose $300 Million a Year to Secure Water Infrastructure

Two Democratic senators introduced the Water Cyber Shield Act this week, proposing $300 million in annual funding to improve cybersecurity across US water and wastewater systems. The bill would give the EPA authority to conduct security assessments, mandate corrective action when vulnerabilities are found, and require incident reporting in line with the forthcoming CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act). The push follows attacks on at least 30 water systems across 12 states, attributed to groups linked to Iran's military. For everyday residents: cleaner regulation of the systems that supply your drinking water is the goal.

Issue #60· August 10, 2026
Compliance Pulse

The EU AI Act Is Now Being Enforced — and You Can File a Complaint

As of 2 August 2026, the EU's AI Office and national authorities began actively enforcing the AI Act — the world's first broad legal framework regulating artificial intelligence — according to Help Net Security.

Fines run up to €15 million or 3% of global annual turnover. The AI Office has launched a public complaints tool, a whistleblower channel for insiders, and a downstream complaints process for businesses building on top of others' AI systems. For most people and small businesses, the most important thing to know is that the mechanism now exists: if you believe an AI system has caused harm, there is a formal place to report it.

Issue #59· August 9, 2026
Compliance Pulse

No major compliance updates today.

The TrueConf supply chain attack is worth flagging for organisations operating under vendor risk or software integrity policies. Kaspersky's finding that attackers replaced a signed installer with an unsigned malicious version is a direct argument for enforcing code-signing verification policies — checking that software carries a valid, unaltered digital signature before installation. If your organisation has a vendor management framework, a check on whether software update integrity is contractually required from suppliers is a reasonable next step.

Issue #58· August 7, 2026
Compliance Pulse

EU AI Act Enforcement Begins — Fines Are Not the First Risk

The EU AI Act's transparency obligations under Article 50 are now in scope for enforcement. Organisations that deploy AI systems interacting with people must disclose that users are talking to AI. Violations carry fines of up to €15 million or 3% of global turnover.

In practice, the first year will likely bring corrective orders before large fines. The real near-term risk is being ordered to suspend or withdraw an AI process at short notice — potentially more disruptive than any financial penalty.

If your organisation uses AI-assisted customer communication or ticketing, audit it now.

Help Net Security

Issue #57· August 6, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch Three Actively Exploited Flaws by End of July 7

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal civilian agencies to apply mitigations by the end of Friday, July 7, according to Bleeping Computer. The flaws affect IBM's Langflow AI agent framework (CVSS 9.8), N-able's N-central remote monitoring platform, and Apache Tomcat. All three are confirmed as actively exploited. Non-federal organisations running any of these products should treat the federal deadline as a prompt to patch immediately — attackers do not check whether your organisation is a government agency.

Issue #56· August 5, 2026
Compliance Pulse

Cyberattacks on US Water Systems Now Confirmed Across 12 States

A hacking campaign targeting water and wastewater facilities has spread to at least 12 US states, according to Security Week. Attackers targeted internet-exposed Rockwell Automation MicroLogix PLCs (programmable logic controllers — the computers that operate physical industrial equipment), remotely altering configurations, changing IP addresses, and locking out operators. Reported effects include pressure loss and flooding at some sites. CISA has urged the water sector to take OT (operational technology) systems offline from public internet access immediately. Iran is the primary suspect, though no official attribution has been made.

Issue #55· August 4, 2026
Compliance Pulse

The EU AI Act Is Now Being Enforced — Chatbots and Deepfakes Must Identify Themselves

As of 2 August 2026, the European Commission began enforcing the AI Act, according to Help Net Security. Chatbots must now disclose they are automated systems, and AI-generated or altered content must carry detectable labels. Companies that ignore the rules face fines up to €15 million or 3% of global turnover. For everyday users, this means any AI you interact with in Europe is legally required to say so.

Issue #54· August 3, 2026
Compliance Pulse

South Korea Fines KT $38 Million After Femtocell Attack Went Undetected for 11 Months

South Korea's data protection authority, the PIPC, has fined telecom giant KT approximately $38 million after hackers extracted a certificate from a lost KT femtocell (a small, low-power personal mobile base station), built a counterfeit one, and used it to intercept customer authentication codes and make fraudulent payments, according to Infosecurity Magazine. The breach went undetected for 11 months. Investigators also found 38 internal servers infected with backdoor malware, and KT is facing further complaints for deleting logs and submitting false information during the investigation. The lesson for any business: gaps in basic access control will eventually cost far more than fixing them would have.

Issue #52· August 1, 2026
Compliance Pulse

CISA and 16 Partner Agencies Update the Rules for Software Ingredient Lists

CISA, alongside 16 government agencies spanning four continents, has published updated minimum requirements for SBOMs (Software Bills of Materials — standardised ingredient lists that detail every component inside a piece of software), according to Dark Reading.

The updated guidance supersedes 2021 rules and introduces 10 new data fields, including digital signatures to verify an SBOM's authenticity and expanded dependency tracking that now requires listing not just direct components but also those components' own dependencies.

For everyday users, this matters because better software transparency means organisations can identify vulnerable components faster when the next major flaw surfaces.

Issue #51· July 31, 2026
Compliance Pulse

CISA Tells Water Utilities: Disconnect Your PLCs Now

CISA (the US Cybersecurity and Infrastructure Security Agency) published an urgent alert on July 30 calling on water and wastewater operators to immediately remove internet-exposed PLCs (programmable logic controllers — the hardware that automates physical processes like pumps and valves) from public access, according to Security Week.

The alert follows a coordinated attack on 30+ Minnesota water systems on July 26–27. Attackers locked operators out by changing passwords and disconnecting equipment remotely. CISA links the attack pattern to Iranian-linked threat groups. Water customers in affected regions were told drinking water remained safe.

What to do: If you work in critical infrastructure, read advisory AA26-097A.

Issue #50· July 30, 2026
Compliance Pulse

FCC Bans New Foreign-Made Robots and Power Inverters Over Security Risks

The US Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, according to The Hacker News. New models cannot be imported, marketed, or sold in the US without conditional approval from federal agencies. Devices already owned by consumers are unaffected. The FCC cited documented vulnerabilities including researchers gaining root-level access to household robots and remote control of autonomous quadruped units. For businesses that rely on these devices in warehouses or energy systems, new procurement decisions just got more complicated.

Issue #49· July 29, 2026
Compliance Pulse

UK's NCSC Publishes Step-by-Step Recovery Guidance for Organisations Under Attack

The UK's National Cyber Security Centre has released a new guide — What To Do When Cyber-Attacks Disrupt Your Organisation — covering the first hours of an attack through to full recovery, according to Infosecurity Magazine. The document covers immediate triage, getting back to minimum viable operations, and long-term rebuilding. The NCSC's key message is unambiguous: a written plan is not enough. Organisations need to physically rehearse shutdown, failover, and rebuild procedures before an incident — not read about them during one.

Issue #48· July 28, 2026
Compliance Pulse

Senator Calls for Federal VPN Purge Within Two Years

Senator Ron Wyden has written to CISA, the Office of Management and Budget, and NIST demanding the removal of all legacy public-facing VPNs from federal networks, citing repeated exploitation by Russian and Chinese state-backed attackers through products from Cisco, Fortinet, Ivanti, and Check Point, according to The Record.

The proposal calls for a two-year deadline to replace ageing remote-access systems with zero-trust architecture — a security model that continuously verifies every user rather than trusting anyone already inside the network. For small businesses, the signal is clear: if legacy VPNs are too risky for federal agencies, they are worth reconsidering for your organisation too.

Issue #47· July 26, 2026
Compliance Pulse

No major compliance updates today.

This week's threat landscape offers no respite: active exploitation of an unpatched Java library flaw and a sophisticated browser-based malware delivery campaign both carry significant implications for organisations subject to data protection obligations. If your team operates affected Java services, document your mitigations now — regulators will ask.

Issue #46· July 25, 2026
Compliance Pulse

UK Gets New PM, Keeps Its Cybersecurity Minister

New UK Prime Minister Andy Burnham reshuffled government this week but reappointed cybersecurity minister Liz Lloyd, according to The Record. Lloyd will continue steering the Cyber Security and Resilience Bill through the House of Lords, where line-by-line scrutiny begins in September. The bill extends cyber regulations to data centres and managed service providers, and sets incident reporting deadlines for energy, water, and healthcare operators. Continuity in the brief matters: the bill must pass this year, and a new minister six weeks out would have risked delay.

Issue #45· July 24, 2026
Compliance Pulse

FedRAMP Is Replacing Annual Audits With Continuous, Measurable Proof

FedRAMP 20X, the updated US framework governing cloud security for federal agencies, moves away from point-in-time annual audits and replaces them with continuously validated Key Security Indicators — machine-readable evidence that controls are actually working, not just documented. Under the old model, an organisation could describe a control and pass. Under 20X, it must prove the control holds up, repeatedly, on a short revalidation cycle. For cloud vendors serving US government clients, this is a fundamental shift in how compliance is structured. Full details at Bleeping Computer.

Issue #44· July 23, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch Langflow by July 24

CISA has added CVE-2026-0770, a critical remote code execution flaw in Langflow (an open-source tool for building AI agent workflows), to its Known Exploited Vulnerabilities catalogue, according to Bleeping Computer. Federal agencies must patch by July 24, 2026. The flaw allows unauthenticated attackers to run commands as root. Over 220 exploitation attempts from 64 unique IP addresses were recorded before the CISA directive was issued. Private organisations running Langflow should treat this as equally urgent.

Issue #43· July 22, 2026
Compliance Pulse

Spain Fines 23andMe Nearly $3 Million for the 2023 Genetic Data Breach

Spain's data protection authority (AEPD) has fined 23andMe, the DNA testing company, €2.4 million for cybersecurity failures that contributed to the 2023 breach of 6.9 million people's genetic records, according to The Record. The regulator found that 23andMe lacked mandatory multi-factor authentication and placed no limits on how much data a single account or IP address could download — basic protections that would have slowed the credential stuffing attack (where attackers try username and password combinations stolen from other breaches). The firm also notified Spanish authorities 12 days after learning of the breach, violating GDPR's notification requirements.

For everyday users: genetic data is among the most sensitive data that exists, and the fine signals European regulators are watching how companies protect it.

Issue #42· July 21, 2026
Compliance Pulse

Dutch Intelligence Warns of Russian Camera Hijacking Across NATO States

The Netherlands' civilian and military intelligence services (AIVD and MIVD) published an advisory on July 10 warning that Russian intelligence is systematically hijacking internet-connected security cameras across EU and NATO countries to monitor military logistics and weapons shipments, according to The Hacker News. In Ukraine, the access has reportedly been used to target military personnel directly. The entry method in most cases: default passwords and outdated firmware.

What you should do: Change default passwords on any internet-connected cameras at your home or business, and check the manufacturer's website for firmware updates.

Issue #41· July 20, 2026
Compliance Pulse

UK Police Cite TfL Hack in Push for New Cybercrime Powers

Two members of the Scattered Spider cybercriminal group were sentenced to five and a half years each for the 2024 Transport for London hack, in what the UK National Crime Agency called the country's largest-ever cybercrime prosecution, according to Infosecurity Magazine. The attack cost TfL £29 million in damages and £10 million in lost income, affecting between seven and ten million people.

Senior officers are now pushing for Cybercrime Risk Orders, a proposed legal tool included in the May 2026 King's Speech, expected to be introduced in late 2027 or early 2028. The goal is to restrict high-risk offenders — including those under 18 — while investigations are still ongoing.

Issue #40· July 19, 2026
Compliance Pulse

Age Verification Laws Are Tightening Globally — and Fines Are Growing

More than 30 age verification laws are now enforceable worldwide, according to Bleeping Computer. The UK's Online Safety Act will restrict under-16 social media access from spring 2027. Australia has already introduced under-16 rules and is considering doubling maximum fines to $99 million following early non-compliance. Half of U.S. states now mandate some form of age verification. For everyday users, this means more platforms will request identity or biometric checks. Ask before you hand anything over: is this processed on my device or sent to a server?

Issue #39· July 18, 2026
Compliance Pulse

23andMe Pays $18 Million After Millions of Genetic Profiles Were Stolen

A coalition of 42 US state attorneys general has reached an $18 million settlement with 23andMe over its 2023 data breach, which exposed the ancestry and personal data of over six million people, according to Infosecurity Magazine. The breach stemmed from credential stuffing (attackers using passwords stolen elsewhere to access accounts). New data security requirements have been imposed on TTAM Research, the company that acquired 23andMe's customer data through bankruptcy. The rules include formal risk analysis, a new data security advisory board, and the right for customers to delete their data.

What you should do: If you were a 23andMe customer, you can request deletion of your data through TTAM Research directly.

Issue #38· July 17, 2026
Compliance Pulse

CISA Orders Federal Patches for Actively Exploited Fortinet Flaws by Sunday

CISA added two critical Fortinet FortiSandbox vulnerabilities — CVE-2026-39808 and CVE-2026-25089, both rated CVSS 9.1 — to its Known Exploited Vulnerabilities catalogue on July 16, according to Infosecurity Magazine. US federal agencies must patch by July 19 under Binding Operational Directive (BOD) 26-04. For cloud deployments without available patches, CISA says to stop using the product entirely. Private sector organisations are not legally bound by BOD deadlines, but with active exploitation confirmed, the same urgency applies.

Issue #37· July 16, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch SharePoint Within Three Days

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft SharePoint (Microsoft's web-based collaboration and document management platform) privilege escalation flaw, CVE-2026-56164, to its Known Exploited Vulnerabilities list, according to Security Week. Federal agencies have three days to patch. The July 2026 Patch Tuesday update resolves this flaw along with two additional critical SharePoint bugs. If your organisation runs SharePoint on-premises, apply Microsoft's latest patches now and check whether your SharePoint servers are directly exposed to the internet.

Issue #36· July 15, 2026
Compliance Pulse

CISA Orders Federal Agencies to Patch SharePoint by July 17

CISA has added three actively exploited Microsoft SharePoint Server vulnerabilities to its Known Exploited Vulnerabilities catalogue and ordered US federal agencies to patch by July 17, 2026, per Bleeping Computer. Attackers are using these flaws to bypass authentication, run remote code, and deploy malware on exposed on-premises SharePoint servers. Nearly 10,000 internet-facing SharePoint servers are currently visible online, with over 800 confirmed unpatched. If your organisation runs SharePoint on its own servers rather than in the cloud, apply Microsoft's latest patches now and avoid exposing SharePoint directly to the internet.

Issue #35· July 14, 2026
Compliance Pulse

EU and UK Sanction Russian Cyber Operators in Largest-Ever Package

The EU and UK jointly sanctioned dozens of Russian individuals and entities this week, citing coordinated cyberattacks against European critical infrastructure, government networks, and public services, according to Help Net Security. The EU called it its largest-ever cyber sanctions package. The UK separately sanctioned individuals linked to Lumma Stealer — credential-theft malware with at least 2,100 confirmed UK victims in the last six months. For everyday users, the practical note is this: credential theft is an active, state-linked operation, not just opportunistic crime.

Issue #34· July 12, 2026
Compliance Pulse

Australia Issues Active-Exploitation Warning for CMS Platforms

Australia's cybersecurity authority has issued an alert warning of a global campaign actively exploiting unpatched content management system platforms. While full details were unavailable at time of writing, the advisory signals that exploitation is confirmed and ongoing rather than theoretical, according to Bleeping Computer. For small businesses and organisations running public-facing websites, this is a prompt to check your CMS version and update today. Regulatory exposure from a compromised website can compound the technical damage significantly.

Issue #33· July 11, 2026
Compliance Pulse

European Parliament Revives Mass Messaging Scan Law

The European Parliament has voted to extend a law permitting major technology companies to voluntarily scan users' messages for child sexual abuse material (CSAM), according to The Record. The measure, which does not apply to end-to-end encrypted platforms like Signal, runs until 2028. Critics raised concerns about the procedural mechanism used — an absolute majority vote, held the day before summer recess, where absent members effectively count as votes in favour. A broader and more contested permanent framework, informally called Chat Control 2.0, remains under negotiation and could eventually extend scanning to encrypted communications.

Issue #32· July 10, 2026
Compliance Pulse

EU Hauls Four Countries to Court Over Overdue Cybersecurity Law

The European Commission has filed legal proceedings against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive — the EU's baseline cybersecurity law for hospitals, energy networks, and public services — more than 20 months past the October 2024 deadline, according to The Record.

Daily financial penalties are being sought until each country fully transposes the law. For businesses operating in these countries: NIS2 compliance obligations apply to you regardless of where government proceedings stand. Do not wait for the fine to land before checking your incident reporting obligations.

Issue #31· July 9, 2026
Compliance Pulse

70+ Cyber Firms Sign CREST AI Security Charter

Industry body CREST launched its AI Charter on July 9, with 73 founding signatories committing to nine principles for responsible AI use in cybersecurity, according to Infosecurity Magazine. The principles cover transparency with clients, human oversight of AI decisions, and strict data handling rules. For everyday users, this means security firms that signed up must tell you when AI is involved in their services and how it affects your data. CREST reports that 69% of cybersecurity providers already use AI daily — this charter is the industry trying to get ahead of regulation before regulation gets ahead of them.

Issue #30· July 8, 2026
Compliance Pulse

Texas App Store Age Verification Law Is Now Enforceable

The US Supreme Court has allowed Texas's App Store Accountability Act (TASAA) to take effect while lower courts continue debating its constitutionality, according to The Record. The law requires app stores and developers to verify that users under 18 have parental consent before downloading apps. For app developers and platform operators, this means age-gating is no longer a future concern — it is a current legal requirement in Texas. The Fifth Circuit hears full arguments in August, but enforcement is live now.

Issue #29· July 7, 2026
Compliance Pulse

UK Launches Voluntary Cyber Resilience Pledge with 60+ Signatories

The UK government has launched a Cyber Resilience Pledge, with over 60 organisations including Marks & Spencer, Nationwide, and Microsoft UK committing to board-level cybersecurity accountability, per Infosecurity Magazine. Signatories must register for the NCSC's free Early Warning alert service and push Cyber Essentials certification (a government-backed security baseline standard) down their supply chains.

For smaller suppliers, this creates real pressure to meet a minimum security standard to retain contracts with larger partners. Businesses with under £20m turnover that achieve Cyber Essentials certification are eligible for free cyber-liability insurance.

Issue #28· July 6, 2026
Compliance Pulse

France Will Stop Certifying Products Without Quantum-Safe Encryption by 2027

France's national cybersecurity agency, ANSSI, has announced it will halt certification of security products that lack quantum-resistant encryption (encryption designed to resist attacks from quantum computers, which can break many current standards) starting in 2027, as reported by Schneier on Security. Government agencies and critical infrastructure operators in France are required to use ANSSI-certified products, making this a practical phase-out deadline. Businesses supplying the French public sector should begin evaluating quantum-safe alternatives now — 2027 is closer than it sounds.