Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

109 articles found · #cybersecurite

Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR

On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.

ENISA Cybersecurity Exercise Methodology and DORA Article 24 Compliance

ENISA released a cybersecurity exercise methodology and toolkit that directly meet DORA Article 24 scenario-based testing requirements, with concrete artifacts to evidence compliance.

NIS 2: common 24h/72h/1‑month templates — what ILR expects

On 26 May 2026, the EU adopted common incident reporting templates (24h/72h/1 month). In Luxembourg, ILR confirms this sequencing and sets out the expected content for entities.

CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups

Since 28/05/2025, the CSSF requires annual aggregated estimation of costs/losses from major ICT incidents (JC 2024 34). Immutable, isolated 3‑2‑1‑1‑0 backups cut financial impact and provide the required evidence.

Authentication logs: key evidence (French Conseil d’État, 26/06/2023) and NIS 2

The Conseil d’État validated purpose‑bound access to authentication logs. To meet NIS 2 (24h) and CSSF expectations, a Logging + SIEM + Forensics setup is now essential.

Forg365: a PhaaS targets Microsoft 365 via device code — IAM for NIS 2 and GDPR

On July 9, 2026, ZeroBEC revealed Forg365, a PhaaS combining device‑code and AiTM against Microsoft 365, with public IOCs. Here’s how concrete IAM governance fulfills NIS 2 Art. 21 and GDPR Art. 32.

Foxconn: 8 TB stolen — a DLP to meet GDPR (May 2026)

After the “Nitrogen” attack on Foxconn (~8 TB, 11M files), here’s how a design‑centric DLP meets GDPR Articles 32 and 44‑49 and prevents exfiltration without halting production.

LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup

The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.

Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance

On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.

French Council of State — Beaucaire: Authentication Bar Raised

The French Council of State upheld CNIL’s warning over weak passwords. Here’s how to move to phishing‑resistant MFA (FIDO2/WebAuthn) compliant with GDPR Article 32 — and prove it.

ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12

ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.

NIS 2 in Luxembourg: what ILR really expects under Article 21

ILR clarifies board duties and expected controls for NIS 2 Article 21, aligned with Implementing Regulation (EU) 2024/2690 and Luxembourg’s 5 May 2026 law.

← Newer Page 2 / 10 Older →