Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
99 articles found · #nis-2
MAG: 8.7M customers exposed — third‑party risk hits airports
Manchester Airports Group confirms unauthorized access to parking, lounge, Fast Track and Wi‑Fi data, affecting around 8.7M customers. The case highlights third‑party risk and GDPR/NIS 2 notification duties.
CNIL fines Free/Free Mobile €42M for weak VPN MFA
CNIL fines Free/Free Mobile €42M for weak VPN MFA and failed detection after data exfiltration affecting ~24.6M contracts. Here is the phishing-resistant MFA that would have prevented most of it.
MyDr: 19M health records exposed — third‑party risk hits Europe
Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.
ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2
ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.
RingCentral: 1.6M emails exposed — move to phishing-resistant MFA
After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.
WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery
On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.
Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23
On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).
UK Government Investments: 51 staff exposed — asset inventory is decisive
UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.
“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response
Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.
NIS 2: EU adopts the supply chain Toolbox — what ILR will check
On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.
15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force
As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.
FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2
FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.