Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

96 articles found · #nis-2

ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2

ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.

RingCentral: 1.6M emails exposed — move to phishing-resistant MFA

After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23

On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).

UK Government Investments: 51 staff exposed — asset inventory is decisive

UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.

“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response

Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.

NIS 2: EU adopts the supply chain Toolbox — what ILR will check

On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2

FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.

NIS 2 in Luxembourg: scope, categories and self‑registration

Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.

CJEU C‑340/21: proving adequacy (GDPR Art. 32) requires logs

The CJEU (C‑340/21) places the burden on controllers to prove adequacy (GDPR Art. 32). In practice: 24/7 SIEM/SOC and robust logging to detect, investigate, and notify the ILR within 24h under NIS 2.

BSI Releases TR‑03188 'Passkey Server' (v1.0, July 2026)

BSI releases TR‑03188 v1.0, an operational guide to deploy server‑side passkeys (FIDO2/WebAuthn). A milestone for phishing‑resistant MFA and GDPR Article 32 compliance.

Page 1 / 8 Older →