Compliance

AWS makes it easier to spot firewall rules that have gone quiet

AWS makes it easier to spot firewall rules that have gone quiet 2026-08-24 at 07:00 By Anamarija Pogorelec AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability […]

AWS makes it easier to spot firewall rules that have gone quiet Read More »

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind 2026-08-21 at 11:41 By Eduard Kovacs Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek. This article

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Read More »

17 draft Cyber Resilience Act standards are open for comment

17 draft Cyber Resilience Act standards are open for comment 2026-08-14 at 07:30 By Anamarija Pogorelec A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to

17 draft Cyber Resilience Act standards are open for comment Read More »

What the first year of EU AI Act transparency enforcement could look like

What the first year of EU AI Act transparency enforcement could look like 2026-08-07 at 08:30 By Mirko Zorz In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders

What the first year of EU AI Act transparency enforcement could look like Read More »

Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway

Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway 2026-08-06 at 15:00 By SecurityWeek News (Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field. The post Podcast: Compliance Won’t Save You: The

Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway Read More »

EU begins enforcing AI Act, putting AI models under the microscope

EU begins enforcing AI Act, putting AI models under the microscope 2026-08-04 at 09:49 By Sinisa Markovic Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect,

EU begins enforcing AI Act, putting AI models under the microscope Read More »

Companies push AI, sysadmins keep it on a short leash

Companies push AI, sysadmins keep it on a short leash 2026-07-31 at 08:00 By Anamarija Pogorelec In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared

Companies push AI, sysadmins keep it on a short leash Read More »

Timeless Compliance: Why Better Questions Beat Bigger Frameworks

Timeless Compliance: Why Better Questions Beat Bigger Frameworks 2026-07-30 at 18:46 By Matt Honea The best compliance programs aren’t the biggest ones. They’re the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger

Timeless Compliance: Why Better Questions Beat Bigger Frameworks Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

AI can’t fix cybersecurity’s hiring problem

AI can’t fix cybersecurity’s hiring problem 2026-07-22 at 07:30 By Anamarija Pogorelec Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year,

AI can’t fix cybersecurity’s hiring problem Read More »

The Windows 10 hangover is becoming a security problem

The Windows 10 hangover is becoming a security problem 2026-07-20 at 11:37 By Anamarija Pogorelec Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered

The Windows 10 hangover is becoming a security problem Read More »

Nearly half of open-source AI projects never reach production

Nearly half of open-source AI projects never reach production 2026-07-20 at 07:00 By Anamarija Pogorelec Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as

Nearly half of open-source AI projects never reach production Read More »

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday 2026-07-17 at 14:08 By SecurityWeek News Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek. This article is

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday Read More »

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules 2026-07-14 at 09:37 By Eduard Kovacs A new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek. This article is an excerpt

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules Read More »

GitHub’s new tool helps prevent costly open-source license violations

GitHub’s new tool helps prevent costly open-source license violations 2026-07-02 at 07:00 By Anamarija Pogorelec GitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and identify dependencies whose licenses require review. The feature is available to GitHub Advanced Security customers and

GitHub’s new tool helps prevent costly open-source license violations Read More »

Getting boards to fund ERM means speaking their currency

Getting boards to fund ERM means speaking their currency 2026-07-01 at 07:00 By Help Net Security In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a

Getting boards to fund ERM means speaking their currency Read More »

Healthcare leaders see a fatal cyber incident as inevitable

Healthcare leaders see a fatal cyber incident as inevitable 2026-06-26 at 08:00 By Mirko Zorz Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside

Healthcare leaders see a fatal cyber incident as inevitable Read More »

Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure

Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure 2026-06-17 at 07:30 By Help Net Security In this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. He opens with a 3.47 a.m. call: the team cannot confirm

Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure Read More »

The checklist problem behind critical infrastructure cyber safety

The checklist problem behind critical infrastructure cyber safety 2026-06-17 at 07:00 By Anamarija Pogorelec An asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for

The checklist problem behind critical infrastructure cyber safety Read More »

Software supply chains are heading for a transparency test

Software supply chains are heading for a transparency test 2026-06-16 at 12:24 By Anamarija Pogorelec Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling,

Software supply chains are heading for a transparency test Read More »

Scroll to Top