Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
96 articles found · #nis-2
DGFiP: 600,000 tax records for sale — warning on stealth exfiltration
On 14 August 2026, France’s Finance Ministry confirmed a DGFiP breach with over 600,000 tax records exported. A stealth exfiltration via a spoofed VPN, fueling targeted fraud risks.
Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR
On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.
NIS 2: common 24h/72h/1‑month templates — what ILR expects
On 26 May 2026, the EU adopted common incident reporting templates (24h/72h/1 month). In Luxembourg, ILR confirms this sequencing and sets out the expected content for entities.
Authentication logs: key evidence (French Conseil d’État, 26/06/2023) and NIS 2
The Conseil d’État validated purpose‑bound access to authentication logs. To meet NIS 2 (24h) and CSSF expectations, a Logging + SIEM + Forensics setup is now essential.
Forg365: a PhaaS targets Microsoft 365 via device code — IAM for NIS 2 and GDPR
On July 9, 2026, ZeroBEC revealed Forg365, a PhaaS combining device‑code and AiTM against Microsoft 365, with public IOCs. Here’s how concrete IAM governance fulfills NIS 2 Art. 21 and GDPR Art. 32.
Foxconn: 8 TB stolen — a DLP to meet GDPR (May 2026)
After the “Nitrogen” attack on Foxconn (~8 TB, 11M files), here’s how a design‑centric DLP meets GDPR Articles 32 and 44‑49 and prevents exfiltration without halting production.
Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance
On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.
PNLD: 135,000 police and partner contacts published on the dark web
The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.
ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12
ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.
NIS 2 in Luxembourg: what ILR really expects under Article 21
ILR clarifies board duties and expected controls for NIS 2 Article 21, aligned with Implementing Regulation (EU) 2024/2690 and Luxembourg’s 5 May 2026 law.
Dutch AP and Council for the Judiciary: data leak via Ivanti EPMM
On 9 February 2026, the Dutch data authority (AP) and the Council for the Judiciary confirmed a leak via Ivanti EPMM flaws exposing professional contact data. How to turn MDM into evidence of control under GDPR Art. 32 and NIS 2.
NIS 2 vs DORA in Luxembourg: notify in 24 h or 4 h?
Verifiable fact: CSSF Circular 25/893 (27/05/2025) aligns DORA reporting with a first notification “within 4 hours” after classification. NIS 2 requires a preliminary alert “within 24 hours.” Key issue: who to notify, when, and against which clock in Luxembourg.