From the Desk
Compliance & GRC
Regulatory updates, compliance frameworks, governance, risk management.
20
Stories filed
3
Desks covered
≥ 6/10
Editorial floor
Coverage:RegulatoryComplianceSecurity
§
On the Compliance & GRC Desk
The latest stories filtered for your beat, organised by sub-section.
Security13 stories
- CISOs Feel the Heat Over AI RiskCISO attrition driven by unclear AI governance mandates creates compliance continuity risk — if security leadership turns over during NIS2 or DORA implementation, programme timelines slip.20 Jul
- Microsoft confirms Windows Server Update Services sync delays20 Jul
- Security incident disclosure – July 202619 Jul
- Abbott probes two cyber incidents amid extortion claimsDual incidents at a regulated healthcare entity highlight the regulatory exposure when legacy systems lack modern security controls required under frameworks like NIS2.17 Jul
- Ernst & Young discloses data breach after support system hackA breach at EY via a third-party system raises questions about processor/sub-processor accountability under GDPR and NIS2 supply-chain obligations.17 Jul
- Dairy company Fairlife suspends production in US after cyber incident17 Jul
- Windows Server 2022 reach end of mainstream support in 90 days17 Jul
- Coca-Cola says Fairlife ransomware attack halts US dairy productionA ransomware-driven production halt at a critical supplier may trigger NIS2 incident-reporting obligations for affected downstream partners in the EU.16 Jul
- Windows 11 24H2 Home and Pro reach end of support in 90 days16 Jul
- xChk: Bring Your Own Identity -- Heterogeneous Assurance with Verifier-Determined Sufficiency16 Jul
- Identity Attacks Overtake Exploits as Top Ransomware CauseNIS2 and DORA mandate appropriate access-control measures; evidence that standard MFA fails 97% of the time when targeted challenges the adequacy of current controls.15 Jul
- Why “Least Privilege” Fails in Real Environments15 Jul
- Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-SchneiderRegulators are beginning to reference quantum readiness in risk-management frameworks; early cryptographic inventories support compliance with evolving requirements.15 Jul
Regulatory4 stories
- AI Watermark Evidence Fails Forensic Readiness: An Empirical EvaluationIf AI watermarks are demonstrably unreliable, compliance teams must rethink how they will meet EU AI Act transparency mandates that assume watermarking is a dependable mechanism.20 Jul
- E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI AssistantsThe EU forcing Google to open Android sensor access to rival AI assistants signals an expanding DMA enforcement posture that may affect how enterprises manage mobile data exposure.17 Jul
- UK investigates TikTok for alleged age-verification lapses, exposing kids to online harmsOfcom's investigation into TikTok's age-verification shortcomings under the Online Safety Act signals escalating enforcement that could set precedents affecting any platform handling EU/UK minors' data.16 Jul
- The Shift: A New Era of AI RegulationDiverging US and EU AI regulatory regimes create dual-compliance obligations; security leaders must track export controls alongside the EU AI Act.15 Jul
Compliance3 stories
- X-rated Compliance Theater: An Empirical Evaluation of European Age Verification Systems in Adult WebsitesAn empirical evaluation finding European age-verification systems to be largely performative raises questions about regulatory enforcement credibility and upcoming Digital Services Act requirements.17 Jul
- 23andMe to pay $18 million in new genetics data breach settlementThe multi-state settlement signals an aggressive enforcement posture toward sensitive data handlers that European compliance teams should monitor for GDPR equivalence.16 Jul
- Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design ApproachPresents a privacy-by-design architecture for IoMT elderly care systems that tackles GDPR-compliant pseudonymisation at the edge—directly relevant to organisations deploying connected health devices in the EU.16 Jul