Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
91 articles found · #solution
“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response
Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.
FortiBleed targets 430k FortiGate — continuous VM to meet NIS 2
FortiBleed (Lynx/INC) mass-stole Fortinet credentials. Here’s how continuous Vulnerability Management operationalizes NIS 2 Article 21 and reduces exposure before the next campaign.
CJEU C‑340/21: proving adequacy (GDPR Art. 32) requires logs
The CJEU (C‑340/21) places the burden on controllers to prove adequacy (GDPR Art. 32). In practice: 24/7 SIEM/SOC and robust logging to detect, investigate, and notify the ILR within 24h under NIS 2.
BSI Releases TR‑03188 'Passkey Server' (v1.0, July 2026)
BSI releases TR‑03188 v1.0, an operational guide to deploy server‑side passkeys (FIDO2/WebAuthn). A milestone for phishing‑resistant MFA and GDPR Article 32 compliance.
Stadler Rail: $12.3M Ransom Demand — Practical IAM to Meet NIS 2 and GDPR
On July 22, 2026, Stadler Rail rejected a $12.3M ransom after data was exfiltrated via a supplier file-sharing platform. Here is measurable IAM that limits third-party access and aligns with NIS 2 and GDPR.
ENISA Cybersecurity Exercise Methodology and DORA Article 24 Compliance
ENISA released a cybersecurity exercise methodology and toolkit that directly meet DORA Article 24 scenario-based testing requirements, with concrete artifacts to evidence compliance.
CSSF 25/892: quantifying ICT incident costs — adopt 3‑2‑1‑1‑0 immutable backups
Since 28/05/2025, the CSSF requires annual aggregated estimation of costs/losses from major ICT incidents (JC 2024 34). Immutable, isolated 3‑2‑1‑1‑0 backups cut financial impact and provide the required evidence.
Authentication logs: key evidence (French Conseil d’État, 26/06/2023) and NIS 2
The Conseil d’État validated purpose‑bound access to authentication logs. To meet NIS 2 (24h) and CSSF expectations, a Logging + SIEM + Forensics setup is now essential.
Forg365: a PhaaS targets Microsoft 365 via device code — IAM for NIS 2 and GDPR
On July 9, 2026, ZeroBEC revealed Forg365, a PhaaS combining device‑code and AiTM against Microsoft 365, with public IOCs. Here’s how concrete IAM governance fulfills NIS 2 Art. 21 and GDPR Art. 32.
Foxconn: 8 TB stolen — a DLP to meet GDPR (May 2026)
After the “Nitrogen” attack on Foxconn (~8 TB, 11M files), here’s how a design‑centric DLP meets GDPR Articles 32 and 44‑49 and prevents exfiltration without halting production.
LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup
The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.
Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance
On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.