Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
91 articles found · #solution
CNIL fines Free/Free Mobile €42M and why to move to FIDO2 MFA
CNIL fined Free and Free Mobile €42M for insufficient security, including weak VPN authentication. Deploying FIDO2/WebAuthn MFA concretely meets GDPR Article 32 and reduces risk.
CSSF 26/914: AMLA supervision — the ICT inventory becomes vital
CSSF 26/914 identifies entities eligible for AMLA’s direct supervision. Governance and traceability tighten: a reliable, continuous inventory/CMDB is now essential to evidence NIS 2/ISO 27001 controls.
ILR — CP/N26/2 consultation and NIS 2 24-hour notification
ILR opens consultation on national NIS 2 incident notification (CP/N26/2). Here are the rules, the 24/72/30 timeline, and the SIEM/SOC stack to report within 24 hours reliably.
CSSF 25/893: reporting a major incident in 4h with EDR/XDR
CSSF Circular 25/893 formalizes DORA reporting for major ICT incidents and significant cyber threats. A well‑tuned EDR/XDR stack speeds up detection, classification, and 4h/72h/1‑month notifications.
AssuranceAmerica: 6.99M drivers exposed — DLP that evidences GDPR
AssuranceAmerica confirms data exfiltration affecting 6.99M people. How a cloud/SaaS‑centric DLP limits impact and provides the evidences expected under GDPR Article 32.
ILR CP/N26/1: Evidence your NIS 2 measures with an ISO 27001 ISMS
ILR opens consultation on periodic notification of NIS 2 “security measures.” An ISO 27001 ISMS provides evidence, traceability, and the required format to notify with confidence.
ShinyHunters: SSO vishing targeting Salesforce/Okta — FIDO2 as countermeasure
Mandiant details a “ShinyHunters” vishing campaign stealing SSO accounts to loot Salesforce and other SaaS. Phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces notification risk.
ManoMano: 38M customers hit via contractor — DLP as GDPR proof
ManoMano confirmed a breach affecting ~38M people via a support contractor. Here’s how modern DLP demonstrates GDPR Article 32 and secures extra-EU transfers (Arts. 44–49).
Instructure/Canvas: 275M Users Impacted — Modern DLP Is Now Essential
Instructure (Canvas) confirmed a breach claimed by ShinyHunters, potentially affecting up to 275M users and 3.6 TB of content. Here’s how modern DLP meets GDPR Article 32 and secures transfers (Arts. 44–49).
CSSF — DORA: ICT register due March 31, 2026; inventory is critical
The CSSF opened the DORA ICT register collection with stricter validations. Without an automated, reliable inventory/CMDB, submissions risk rejection and supply chain blind spots remain.
ILR — NIS 2 incident notification: 24h to alert, your SOC must deliver
In June 2026, the ILR released a “NIS 2 incident notification” guide: early warning within 24h, notification at 72h, and a final report within 1 month. Here’s the SIEM/SOC stack to achieve this without panic.
CSSF — Ivanti EPMM: RCE exploited, mandatory DORA notification
On 10 February 2026, the CSSF warned of two actively exploited Ivanti EPMM RCEs (CVE‑2026‑1281/1340) and reminded firms that this constitutes a major ICT incident to notify (Circulars 25/893 and 24/847).