Skip to main content

regulatory-update

  • Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Architecture has moved from best practice to mandatory requirement. OMB M-22-09 federal deadlines are now enforceable, CISA's updated Zero Trust Maturity Model defines the measurement framework, and DORA, CIRCIA, and the UK Cyber Security and Resilience Bill are converging on the same underlying controls. Here's what the board needs to understand about where ZTA compliance now sits.

    regulatory-update
  • DORA Operational Resilience Testing: What Financial Sector CISOs Must Deliver

    DORA Operational Resilience Testing: What Financial Sector CISOs Must Deliver

    DORA's Threat-Led Penetration Testing requirements under Article 26 apply to significant financial entities across the EU and have extraterritorial reach for UK firms with EU operations. Here's what CISOs need to have in place, the testing scope requirements, and how to manage third-party ICT provider involvement.

    regulatory-update
  • FTC AI Accuracy Policy: What Boards and CISOs Need to Know Before July 31

    FTC AI Accuracy Policy: What Boards and CISOs Need to Know Before July 31

    The Federal Trade Commission's new AI Accuracy Policy Statement establishes that AI-generated outputs causing consumer harm may constitute unfair or deceptive practices under existing FTC Act authority. With the public comment period closing July 31 2026, now is the time to assess your AI deployment exposure.

    regulatory-update
  • DORA's First Enforcement Cycle: What Financial Sector CISOs Must Act on Now

    DORA's First Enforcement Cycle: What Financial Sector CISOs Must Act on Now

    DORA has moved from implementation into active supervisory enforcement in 2026. Regulators are specifically targeting incident-reporting failures and deficiencies in the Register of Information. Here's what the first enforcement cycle means for financial sector CISOs and where the near-term audit risk concentrates.

    regulatory-update
  • DORA's First Enforcement Cycle: Fines, Register of Information Failures, and What CISOs Must Fix Now

    DORA's First Enforcement Cycle: Fines, Register of Information Failures, and What CISOs Must Fix Now

    European regulators are issuing the first material penalties under DORA's 2026 enforcement cycle. Register of Information gaps and ICT risk management failures are the lead findings. Here's what boards and CISOs need to do before Q3 supervisory reviews.

    regulatory-update
  • SBOM and Software Transparency: The CISO's 2026 Compliance and Risk Guide

    SBOM and Software Transparency: The CISO's 2026 Compliance and Risk Guide

    SBOMs have moved from a US executive order recommendation to a procurement requirement in both the US and EU. CISOs now face vendor attestation demands, regulatory reporting obligations, and the operational challenge of building SBOM programmes across complex software portfolios.

    regulatory-update
  • UK ICO Enforcement in 2026: What GDPR Enforcement Trends Mean for Security Leaders

    UK ICO Enforcement in 2026: What GDPR Enforcement Trends Mean for Security Leaders

    The ICO's enforcement posture has shifted from primarily reactive to actively proactive over the past two years. This briefing covers the trends shaping UK GDPR enforcement in 2026, what triggers investigations, and the security controls that reduce regulatory exposure.

    regulatory-update
  • EU Cyber Resilience Act: What CISOs at Software Vendors Must Know

    EU Cyber Resilience Act: What CISOs at Software Vendors Must Know

    The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for all products with digital elements sold in the EU. Reporting obligations start September 2026; full enforcement begins December 2027. This briefing covers what matters most for CISOs.

    regulatory-update