Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
109 articles found · #cybersecurite
ILR — CP/N26/2 consultation and NIS 2 24-hour notification
ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.
CSSF 25/893: reporting a major incident in 4h with EDR/XDR
CSSF Circular 25/893 formalizes DORA reporting for major ICT incidents and significant cyber threats. A well‑tuned EDR/XDR stack speeds up detection, classification, and 4h/72h/1‑month notifications.
NIS 2 in Luxembourg: executive liability and mandatory training
Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.
AssuranceAmerica: 6.99M drivers exposed — DLP that evidences GDPR
AssuranceAmerica confirms data exfiltration affecting 6.99M people. How a cloud/SaaS‑centric DLP limits impact and provides the evidences expected under GDPR Article 32.
ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS
ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.
ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure
Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.
ManoMano: 38M customers hit via contractor — DLP as GDPR proof
ManoMano confirmed a breach affecting ~38M people via a support contractor. Here’s how modern DLP demonstrates GDPR Article 32 and secures extra-EU transfers (Arts. 44–49).
Instructure/Canvas: 275M Users Impacted — Modern DLP Is Now Essential
Instructure (Canvas) confirmed a breach claimed by ShinyHunters, potentially affecting up to 275M users and 3.6 TB of content. Here’s how modern DLP meets GDPR Article 32 and secures transfers (Arts. 44–49).
CSSF — DORA: ICT register due March 31, 2026; inventory is critical
The CSSF opened the DORA ICT register collection with stricter validations. Without an automated, reliable inventory/CMDB, submissions risk rejection and supply chain blind spots remain.
ILR — NIS 2 incident notification: 24h to alert, your SOC must deliver
In June 2026, the ILR released a “NIS 2 incident notification” guide: early warning within 24h, notification at 72h, and a final report within 1 month. Here’s the SIEM/SOC stack to achieve this without panic.
CSSF — Ivanti EPMM: RCE exploited, mandatory DORA notification
On 10 February 2026, the CSSF warned of two actively exploited Ivanti EPMM RCEs (CVE‑2026‑1281/1340) and reminded firms that this constitutes a major ICT incident to notify (Circulars 25/893 and 24/847).
BSI v2.0 “Logging and Detection”: What It Changes for Your Logs and SIEM
In April 2026, BSI released v2.0 of its minimum standard “Protokollierung und Detektion.” Here’s how to align logging, detection, and investigation with NIS 2 and DORA, and meet ILR/CSSF expectations.