CIS blog post providing recommendations for defending against five emerging risks to public gatherings and large-scale events.
Latest changes
NCSC published guidance on alternative pathways to Cyber Essentials Plus certification. The article discusses pathways from proof of concept to achieving cyber confidence without compromising the int…
At its July 2026 plenary, the EDPB adopted three sets of guidelines: on anonymisation, on web scraping in the context of generative AI, and the final version of guidelines on blockchain. The anonymis…
The European Data Protection Board (EDPB) has published guidance addressing anonymisation techniques and web scraping practices in the context of generative AI systems. The board has also adopted the…
Blog post from NCSC discussing the UK's initiative to develop a national scale, sovereign defence capability using agentic AI for cyber defence. The extract does not indicate specific regulatory requ…
FEMA has clarified that SLCGP (State and Local Cybersecurity Grant Program) and TCGP (Tribal Cybersecurity Grant Program) grants can be used to fund CIS Services. The guidance details what qualifies …
The European Data Protection Board (EDPB) and Anti-Money Laundering Authority (AMLA) are developing Joint Guidelines to clarify how to share information for combating financial crime while protecting…
NCSC blog post featuring insights from industry penetration testers on recommendations and best practices for organisations to improve their security posture and make attacks more difficult.
PCI Security Standards Council has launched the Training Venue Host Program, enabling organizations with suitable training facilities to host PCI SSC training programs and bring payment security educ…
Blog post presenting six key takeaways from a CIS webinar addressing how U.S. State, Local, Tribal, and Territorial (SLTT) agencies can strengthen public safety through collective defense practices.
Blog post #4 in a series on Verifiable Digital Credentials (VDCs), focusing on the presentation side of VDCs—how a holder shows their credential to a verifier in both in-person and online contexts. T…
PCI Security Standards Council announces a new blog series "The AI Exchange: Innovators in Payment Security" designed as an ongoing resource for payment security stakeholders to exchange information …
Podcast episode featuring an interview with Sharon Gai, the keynote speaker for PCI SSC's 2026 North America Community Meeting. Sharon is a global expert in e-commerce, digital strategy, and cross-cu…
Blog post discussing how CIS Controls Accreditation is raising global cybersecurity standards and establishing a trusted benchmark for excellence, resilience, and best practices.
The EDPB has published an updated version of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. The digest analyzes how DPAs implement and enforce compliance with Articles 2…
NIST announced an initial public draft (IPD) of NIST SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, is no…
The EDPB has launched a dedicated contact form enabling stakeholders to report possible inconsistencies in GDPR interpretation across Europe. The initiative supports the EDPB Helsinki Statement commi…
The European Data Protection Board announced the launch of its newly redesigned website and updated brand identity. The new website features improved user experience, more intuitive navigation tailor…
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk. This is a guidance publication addressing the evolving landscape of AI-related cyber threats and risks.
CIS has released updates to multiple CIS Benchmarks and CIS Build Kits in June 2026. The announcement highlights major updates but specific benchmark versions, effective dates, and detailed changes a…
NCSC issued guidance advising organisations using Fortinet services to take action following a global campaign targeting Fortinet firewalls and VPN gateways.
NCSC blog post providing guidance on calibrating oversight levels for AI-assisted software development code based on different risk profiles and code characteristics. The post recommends a spectrum-b…
NCSC CEO Dr Richard Horne highlighted the scale of cyber threats against the UK's critical infrastructure at RUSI's Annual Security Lecture. The statement indicates that hostile states are linked to …
CIS blog article discussing how healthcare organizations can maintain HIPAA compliance and cybersecurity obligations while ensuring patient safety.
PCI Security Standards Council announcement welcoming new Associate Participating Organizations. This is an informational post about membership updates, not a regulatory change or standard update.