Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

109 articles found · #cybersecurite

ENISA publishes its Cybersecurity Exercise Methodology (16 Feb 2026)

ENISA releases a comprehensive methodology and toolkit to design and run cyber exercises. Here is how to align it with DORA (Art. 24) and NIS 2 for robust compliance evidence.

UniCredit Romania: €12k GDPR fine — preventing misdirected emails

On 29 May 2026, Romania’s ANSPDCP fined UniCredit Bank SA for security shortcomings (Art. 32) and late breach notification (Art. 33) after mailings to wrong recipients. Here is practical DLP that prevents this and evidences compliance.

NIS 2 Luxembourg: 9 days to ILR self‑registration

Essential and important entities in Luxembourg must self‑register with the ILR by 10 July 2026. Legal basis, risks, and this week’s action plan.

ANSSI — ReCyF: Microsegmentation as a key NIS 2 control

ANSSI’s ReCyF (March 17, 2026) details concrete NIS 2 measures. Network microsegmentation limits lateral movement, protects sensitive environments, and streamlines evidence of compliance.

NIS 2 in Luxembourg: ILR expectations on the 10 measures (Art. 21)

Since the 5 May 2026 law, the ILR details the 10 minimum NIS 2 Article 21 measures and related supervision. Management must approve, implement and evidence these measures, including MFA and supply chain controls.

Charter/Spectrum: vishing, Entra, Salesforce — FIDO2 MFA as the GDPR/NIS2 countermeasure

ShinyHunters allegedly vished a Charter/Spectrum employee, took over a Microsoft Entra account, and exfiltrated Salesforce data. Phishing‑resistant MFA (FIDO2/WebAuthn) meets GDPR Art. 32 and blocks the initial access.

CSSF 26/906: governance and DORA-grade immutable backups by June 30

CSSF 26/906 requires PSPs/EMIs to reassess governance and risk management by 30 June 2026. Immutable, isolated backups are the DORA-proof of ransomware resilience.

European Commission cloud attack — CSPM as a key control under CSSF 22/806

On March 27, 2026, the European Commission confirmed an intrusion and data exfiltration affecting Europa.eu’s cloud infrastructure. How CSPM meets CSSF 22/806 requirements and prevents such scenarios.

Romania: €125,000 fine against Renault for security failures (GDPR Art. 32)

On 25 March 2026, Romania’s ANSPDCP fined Renault Commercial Romania (~€125,000) for GDPR Article 32 failures and processor governance. Modern DLP evidences “appropriate” measures and curbs uncontrolled data transfers.

Clinical Diagnostics (NL): gynecological records leak — GDPR-aligned DLP

After the massive leak at Clinical Diagnostics, a modern DLP aligned with GDPR (Art. 32 and 44–49) reduces exfiltration and provides the evidence authorities expect.

AEPD fines Yoti €950,000 — Automated DPIA becomes essential

On March 10, 2026, the AEPD fined Yoti €950,000 for unlawful biometrics, invalid consent and excessive retention. A tooled, automated DPIA is now key to reduce risk and evidence GDPR compliance.

Outsider Enterprise dismantled: urgent need for phishing‑resistant FIDO2 MFA

FBI, Google, and Black Lotus Labs dismantled “Outsider Enterprise,” a PhaaS linked to >1M URLs and ≈$1.9B in losses. Why FIDO2/WebAuthn MFA is now the “appropriate measure” under GDPR Article 32.

← Newer Page 5 / 10 Older →