Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

103 articles found · #cybersecurite

Charter: 4.9M emails exposed — phishing‑resistant MFA is now essential

A vishing attack abused a Microsoft Entra account to exfiltrate customer data from Salesforce. FIDO2/WebAuthn MFA is now the state of the art expected by GDPR Article 32.

French Council of State 2026 — Health Data Hub: DLP impact and EU transfers

The French Council of State (20/03/2026) upholds CNIL’s authorization for Health Data Hub on Microsoft Ireland in France and confirms no transfers outside the EU. A well‑configured DLP proves and enforces these flow limits technically.

ILR — NIS 2 guidelines for governing bodies (17/02/2026)

ILR reiterates the 24‑hour early warning via SERIMA, then 72 hours and 1 month. See how a managed SOC/SIEM helps meet NIS 2 deadlines without stress.

Tycoon 2FA: device code campaign bypasses Microsoft MFA

On May 12, 2026, eSentire detailed a Tycoon 2FA campaign abusing the OAuth Device Code flow to steal tokens without passwords. Why phishing-resistant FIDO2/WebAuthn MFA is required to meet GDPR Article 32.

French Supreme Court (Mar 5, 2026) reshapes qualified e-signatures

Since March 5, 2026, only a Qualified Electronic Signature (QES) shifts the burden of proof. How to evidence QTSP, QSCD and LTV to secure contracts and compliance.

West Pharmaceutical (4 May 2026): why immutable, isolated backups are vital (DORA)

On 4 May 2026, West Pharmaceutical suffered a ransomware attack with data theft and encryption, halting manufacturing and shipping. Here is the backup architecture that prevents prolonged outages and meets DORA.

Instructure/Canvas: 275M users at risk — 24/7 SOC to meet NIS2 Art. 23

ShinyHunters breached Instructure/Canvas, threatening up to 275M records. How a managed SOC/SIEM enables 24h qualification and ILR notification under NIS2 Art. 23.

ENISA 2026: Exercise Methodology to Operationalize DORA Article 24

ENISA releases a cybersecurity exercise methodology with ready-to-use kits. In practice: DORA Article 24–aligned tabletop tests to speed decision-making and reduce ransomware impact.

FlowerStorm (KrakVM) evades email filters and the NIS 2 stakes

The FlowerStorm phishing kit runs obfuscated JavaScript in KrakVM to intercept MFA. Here is how an email gateway, DMARC/SPF/DKIM, and a 24/7 SOC help meet NIS 2 in Luxembourg.

CSSF — Circular 25/893: tightened ICT alerting and reporting under DORA

The CSSF tightens ICT incident classification and notification under DORA via eDesk. Here is how an EDR/XDR stack enables timely detection, qualification, and reporting with harmonized deadlines.

CSSF 25/883 amends 22/806: continuous cloud oversight

On 9 April 2025, the CSSF adjusted 22/806 via 25/883 to align ICT outsourcing with DORA. Here’s how a robust CSPM prevents cloud leaks and demonstrates compliance.

ChipSoft ransomware: why immutable, isolated backups are non-negotiable

The ChipSoft (HiX) attack disrupted hospital services and exposed data. Here’s how immutable backups and an isolated backup network meet DORA/NIS 2 and prevent prolonged outages.

← Newer Page 7 / 9 Older →