Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

96 articles found · #solution

ENISA Secure by Design: a measurable IAM for GDPR 25 and NIS 2

ENISA’s Secure by Design and Default Playbook provides checklists and minimal evidence. Here’s how a measurable IAM operationalizes these requirements while meeting GDPR art. 25 and NIS 2.

RingCentral: 1.6M emails exposed — move to phishing-resistant MFA

After the ShinyHunters attack, ~1.6M RingCentral emails leaked. A FIDO2/WebAuthn MFA would have broken the attack chain and meets GDPR Article 32 requirements.

Odido (Netherlands): 6.2M customers — a 24/7 SOC to meet NIS2 Art. 23

On 7–8 February 2026, Odido suffered a CRM-targeted attack: ~6.2M individuals exposed. Here’s how a 24/7 SOC and modern SIEM enable detection, containment, and on-time NIS2 notifications (24h/72h/1 month).

VG Düsseldorf (02/04/2026): Transport Encryption Can Suffice

On April 2, 2026, the VG Düsseldorf held that well‑governed email transport encryption can satisfy GDPR Article 32 without mandating end‑to‑end in all cases—provided effectiveness is evidenced by measures and logs.

UK Government Investments: 51 staff exposed — asset inventory is decisive

UKGI acknowledged an internal file exposed the names and work emails of 51 staff for ~40 hours. A CMDB covering information assets and sharing surfaces operationalizes NIS 2 Art. 21 and prevents such leaks.

“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response

Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.

FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2

FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.

CJEU C‑340/21: proving adequacy (GDPR Art. 32) requires logs

The CJEU (C‑340/21) places the burden on controllers to prove adequacy (GDPR Art. 32). In practice: 24/7 SIEM/SOC and robust logging to detect, investigate, and notify the ILR within 24h under NIS 2.

BSI Releases TR‑03188 'Passkey Server' (v1.0, July 2026)

BSI releases TR‑03188 v1.0, an operational guide to deploy server‑side passkeys (FIDO2/WebAuthn). A milestone for phishing‑resistant MFA and GDPR Article 32 compliance.

Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR

On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.

ENISA Cybersecurity Exercise Methodology and DORA Article 24 Compliance

ENISA released a cybersecurity exercise methodology and toolkit that directly meet DORA Article 24 scenario-based testing requirements, with concrete artifacts to evidence compliance.

CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups

Since 28/05/2025, the CSSF requires annual aggregated estimation of costs/losses from major ICT incidents (JC 2024 34). Immutable, isolated 3‑2‑1‑1‑0 backups cut financial impact and provide the required evidence.

Page 1 / 8 Older →