Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

99 articles found · #nis-2

MAG: 8.7M customers exposed — third‑party risk hits airports

Manchester Airports Group confirms unauthorized access to parking, lounge, Fast Track and Wi‑Fi data, affecting around 8.7M customers. The case highlights third‑party risk and GDPR/NIS 2 notification duties.

CNIL fines Free/Free Mobile €42M for weak VPN MFA

CNIL fines Free/Free Mobile €42M for weak VPN MFA and failed detection after data exfiltration affecting ~24.6M contracts. Here is the phishing-resistant MFA that would have prevented most of it.

MyDr: 19M health records exposed — third‑party risk hits Europe

Polish health software vendor MyDr suffered a breach disclosed August 12–13, 2026: nearly 19M people and over 12,000 facilities may be affected. Poland’s PM suggested extortion as the motive.

ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2

ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.

RingCentral: 1.6M emails exposed — move to phishing-resistant MFA

After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.

WEBA (BE) hit by Qilin: ransomware, customer data accessed, 48 h recovery

On August 10, 2026, Belgian retailer WEBA was hit by a ransomware attack. Customer data was accessed; operations resumed on August 12. Qilin claimed responsibility on August 16; WEBA says no ransom was paid.

Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23

On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).

UK Government Investments: 51 staff exposed — asset inventory is decisive

UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.

“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response

Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.

NIS 2: EU adopts the supply chain Toolbox — what ILR will check

On 13/02/2026, the EU adopted the EU ICT Supply Chain Security Toolbox. Under NIS 2 and Implementing Regulation 2024/2690, supplier management becomes prescriptive and must be evidenced in Luxembourg before the ILR.

15 August 2026: the Dutch Cybersecurity Act (NIS 2 NL) has entered into force

As of 15 August 2026, the Dutch NIS 2 law (Cyberbeveiligingswet) applies. For groups in Luxembourg with activities or providers in the Netherlands, obligations now apply on both sides of the border.

FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2

FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.

Page 1 / 9 Older →