Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
33 articles found · #soc
Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23
On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).
FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2
FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.
CJEU C‑340/21: proving adequacy (GDPR Art. 32) requires logs
The CJEU (C‑340/21) places the burden on controllers to prove adequacy (GDPR Art. 32). In practice: 24/7 SIEM/SOC and robust logging to detect, investigate, and notify the ILR within 24h under NIS 2.
Dutch AP and Council for the Judiciary: data leak via Ivanti EPMM
On 9 February 2026, the Dutch data authority (AP) and the Council for the Judiciary confirmed a leak via Ivanti EPMM flaws exposing professional contact data. How to turn MDM into evidence of control under GDPR Art. 32 and NIS 2.
South Staffordshire Water: £963k fine for detection failures
The ICO fined South Staffordshire Water £963,900 for ~5% monitoring coverage and near-absent detection. Here’s why a 24/7 operated EDR/XDR stack is now essential.
LAUNDRY BEAR/NCSC: 'beehive' targets Zimbra — messaging security (NIS 2)
NCSC and partners expose “LAUNDRY BEAR”: a zero‑click campaign against Zimbra. This is the email stack (SEG + DMARC/SPF/DKIM) and NIS 2 actions to reduce risk and notify properly.
CNIL fines Free/Free Mobile €42M and why to move to FIDO2 MFA
CNIL fined Free and Free Mobile €42M for insufficient security, including weak VPN authentication. Deploying FIDO2/WebAuthn MFA concretely meets GDPR Article 32 and reduces risk.
ILR — CP/N26/2 consultation and NIS 2 24-hour notification
ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.
ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS
ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.
ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure
Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.
ManoMano: 38M customers hit via contractor — DLP as GDPR proof
ManoMano confirmed a breach affecting ~38M people via a support contractor. Here’s how modern DLP demonstrates GDPR Article 32 and secures extra-EU transfers (Arts. 44–49).
ILR — NIS 2 incident notification: 24h to alert, your SOC must deliver
In June 2026, the ILR released a “NIS 2 incident notification” guide: early warning within 24h, notification at 72h, and a final report within 1 month. Here’s the SIEM/SOC stack to achieve this without panic.