Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

96 articles found · #solution

Authentication logs: key evidence (French Conseil d’État, 26/06/2023) and NIS 2

The Conseil d’État validated purpose‑bound access to authentication logs. To meet NIS 2 (24h) and CSSF expectations, a Logging + SIEM + Forensics setup is now essential.

Forg365: a PhaaS targets Microsoft 365 via device code — IAM for NIS 2 and GDPR

On July 9, 2026, ZeroBEC revealed Forg365, a PhaaS combining device‑code and AiTM against Microsoft 365, with public IOCs. Here’s how concrete IAM governance fulfills NIS 2 Art. 21 and GDPR Art. 32.

Foxconn: 8 TB stolen — a DLP to meet GDPR (May 2026)

After the “Nitrogen” attack on Foxconn (~8 TB, 11M files), here’s how a design‑centric DLP meets GDPR Articles 32 and 44‑49 and prevents exfiltration without halting production.

LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup

The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.

Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance

On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.

French Council of State — Beaucaire: Authentication Bar Raised

The French Council of State upheld CNIL’s warning over weak passwords. Here’s how to move to phishing‑resistant MFA (FIDO2/WebAuthn) compliant with GDPR Article 32 — and prove it.

ANSSI ReCyF: immutable, isolated backups to meet DORA Art. 12

ANSSI’s ReCyF (17/03/2026) calls for immutable, isolated backups to counter ransomware. Here’s how to deploy them and evidence compliance with DORA Art. 12 and NIS 2.

Dutch AP and Council for the Judiciary: data leak via Ivanti EPMM

On 9 February 2026, the Dutch data authority (AP) and the Council for the Judiciary confirmed a leak via Ivanti EPMM flaws exposing professional contact data. How to turn MDM into evidence of control under GDPR Art. 32 and NIS 2.

South Staffordshire Water: £963k fine for detection failures

The ICO fined South Staffordshire Water £963,900 for ~5% monitoring coverage and near-absent detection. Here’s why a 24/7 operated EDR/XDR stack is now essential.

EvilTokens/ARToken: device-code attacks on Microsoft 365 — move to FIDO2

ARToken abuses the OAuth device-code flow to compromise Microsoft 365 accounts despite MFA. Move to FIDO2/WebAuthn and tailored access policies to reduce risk and demonstrate GDPR Article 32 compliance.

CSSF 25/903: Support PSF — the inventory/CMDB as key evidence

CSSF 25/903 strengthens 24/850 and requires structured evidence on support PSF ICT organization. An automated inventory/CMDB becomes central to trace assets, dependencies and controls, and to meet NIS 2 obligations.

European Commission: Europa.eu breach — how a CSPM prevents the next one

On March 27, 2026, the European Commission confirmed data exfiltration from its cloud hosting Europa.eu. Here’s how a CSPM evidences compliance (GDPR Art. 32, CSSF 22/806) and prevents a repeat.

← Newer Page 2 / 8 Older →