Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
103 articles found · #cybersecurite
LAUNDRY BEAR/NCSC: 'beehive' targets Zimbra — messaging security (NIS 2)
NCSC and partners expose “LAUNDRY BEAR”: a zero‑click campaign against Zimbra. This is the email stack (SEG + DMARC/SPF/DKIM) and NIS 2 actions to reduce risk and notify properly.
CSSF 26/906: strengthened governance and risk — an ISO 27001 ISMS to evidence NIS 2
CSSF 26/906 tightens governance and risk for payment/e-money institutions, with compliance due by 30 June 2026. A certified ISO 27001 ISMS operationalizes these requirements and NIS 2 Article 21.
Pope Francis: Data Breach Exposes 700,000 Users of Official Prayer App
The Vatican's official prayer app suffered a major data breach, exposing personal information of over 700,000 users. A security flaw in the code allowed unauthorized access to sensitive data, highlighting risks associated with poorly secured mobile applications.
CSSF 26/904: stronger ICT evidence — inventory/CMDB becomes essential
CSSF Circular 26/904 tightens investment firms’ self‑assessment by requiring concrete evidence on ICT organization. An automated inventory and a relational CMDB are the most reliable way to demonstrate effective control.
CNIL fines Free/Free Mobile €42M and why to move to FIDO2 MFA
CNIL fined Free and Free Mobile €42M for insufficient security, including weak VPN authentication. Deploying FIDO2/WebAuthn MFA concretely meets GDPR Article 32 and reduces risk.
CSSF 26/914: AMLA supervision — the ICT inventory becomes vital
CSSF 26/914 identifies entities eligible for AMLA’s direct supervision. Governance and traceability tighten: a reliable, continuous inventory/CMDB is now essential to evidence NIS 2/ISO 27001 controls.
ILR — CP/N26/2 consultation and NIS 2 24-hour notification
ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.
CSSF 25/893: reporting a major incident in 4h with EDR/XDR
CSSF Circular 25/893 formalizes DORA reporting for major ICT incidents and significant cyber threats. A well‑tuned EDR/XDR stack speeds up detection, classification, and 4h/72h/1‑month notifications.
NIS 2 in Luxembourg: executive liability and mandatory training
Since 5 May 2026, Luxembourg’s NIS 2 law requires management bodies to approve and oversee cybersecurity measures and to undertake training. Sanctions can be severe and executives are explicitly targeted.
AssuranceAmerica: 6.99M drivers exposed — DLP that evidences GDPR
AssuranceAmerica confirms data exfiltration affecting 6.99M people. How a cloud/SaaS‑centric DLP limits impact and provides the evidences expected under GDPR Article 32.
ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS
ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.
ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure
Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.