Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

96 articles found · #nis-2

KDDI: 12.23M emails and 7.62M passwords compromised

On July 7, 2026, KDDI confirmed unauthorized access to ~12.233M emails and ~7.616M passwords from its ISP email platform—an emblematic supply chain case with lessons for European companies.

NIS 2 in Luxembourg: executive liability and mandatory training

Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.

Nextcloud: 367,000 records exposed (invoices, emails, scripts)

Cybernews reports an exposed Nextcloud ElasticSearch database with ~367,000 records (~8 GB) of staff and clients: invoices, emails, and scripts. The exposure was closed on May 27, 2026.

ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS

ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.

ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure

Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.

Medtronic notifies 3.8M+ people after data breach

Medtronic confirms an April 2026 intrusion exposed personal and health data. More than 3.8 million people have been notified since July 2, 2026.

ENISA issues Frontier AI recommendations for cybersecurity

On 7 July 2026, ENISA released an actionable report to help authorities, defenders and operators prepare for the Frontier AI era, aligned with NIS 2, the CRA and the AI Act.

CSSF — DORA: ICT register due March 31, 2026; inventory is critical

The CSSF opened the DORA ICT register collection with stricter validations. Without an automated, reliable inventory/CMDB, submissions risk rejection and supply chain blind spots remain.

Italy: €100,000 fine against Lepida over LepidaID shortcomings

Italy’s DPA fined Lepida S.c.p.A. €100,000 for GDPR violations in managing LepidaID (>1.5M users). Transparency, data minimization, and excessive log retention were flagged.

ILR — NIS 2 incident notification: 24h to alert, your SOC must deliver

In June 2026, the ILR released a “NIS 2 incident notification” guide: early warning within 24h, notification at 72h, and a final report within 1 month. Here’s the SIEM/SOC stack to achieve this without panic.

CSSF — Ivanti EPMM: RCE exploited, mandatory DORA notification

On 10 February 2026, the CSSF warned of two actively exploited Ivanti EPMM RCEs (CVE‑2026‑1281/1340) and reminded firms that this constitutes a major ICT incident to notify (Circulars 25/893 and 24/847).

BSI v2.0 “Logging and Detection”: What It Changes for Your Logs and SIEM

In April 2026, BSI released v2.0 of its minimum standard “Protokollierung und Detektion.” Here’s how to align logging, detection, and investigation with NIS 2 and DORA, and meet ILR/CSSF expectations.

← Newer Page 4 / 8 Older →