Compliance

How AI can fix cybersecurity compliance: From dashboards to continuous execution

How AI can fix cybersecurity compliance: From dashboards to continuous execution 2026-10-08 at 08:00 By Help Net Security Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their […]

How AI can fix cybersecurity compliance: From dashboards to continuous execution Read More »

NIS2 compliance: 7 low-cost steps to secure credentials

NIS2 compliance: 7 low-cost steps to secure credentials 2026-10-06 at 08:00 By Help Net Security Security budgets rarely stretch to cover a full NIS2 programme in one pass. Credential controls are where a constrained team can start, because they make access visible, revocable, and reviewable without new infrastructure. NIS2 compliance rests on risk-management measures that […]

NIS2 compliance: 7 low-cost steps to secure credentials Read More »

Three questions a hospital CISO should ask a healthcare fintech vendor

Three questions a hospital CISO should ask a healthcare fintech vendor 2026-10-05 at 08:30 By Mirko Zorz In this Help Net Security video, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers […]

Three questions a hospital CISO should ask a healthcare fintech vendor Read More »

Security tools can now scan Claude Enterprise chats and uploads for sensitive data

Security tools can now scan Claude Enterprise chats and uploads for sensitive data 2026-09-30 at 09:31 By Anamarija Pogorelec More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses. CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare […]

Security tools can now scan Claude Enterprise chats and uploads for sensitive data Read More »

EU Cyber Resilience Act requirements for containers and Kubernetes

EU Cyber Resilience Act requirements for containers and Kubernetes 2026-09-30 at 08:00 By Help Net Security Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets. Reporting obligations will begin on Sept. 11, 2026, […]

EU Cyber Resilience Act requirements for containers and Kubernetes Read More »

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections 2026-09-28 at 13:40 By Associated Press A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek. This article […]

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections Read More »

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit 2026-09-22 at 08:00 By Help Net Security By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable […]

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit Read More »

Google hit with €403 million GDPR fine over location tracking

Google hit with €403 million GDPR fine over location tracking 2026-09-21 at 15:23 By Anamarija Pogorelec Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from […]

Google hit with €403 million GDPR fine over location tracking Read More »

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor 2026-09-21 at 07:00 By Anamarija Pogorelec Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said […]

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor Read More »

Comp AI Raises $34 Million for AI-Native Compliance and Security

Comp AI Raises $34 Million for AI-Native Compliance and Security 2026-09-17 at 16:00 By Ionut Arghire The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Comp AI Raises $34 Million for AI-Native Compliance and Security Read More »

MSPs say nearly half their customers rely on them for CISO services

MSPs say nearly half their customers rely on them for CISO services 2026-09-16 at 07:30 By Anamarija Pogorelec MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the […]

MSPs say nearly half their customers rely on them for CISO services Read More »

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities 2026-09-14 at 15:23 By Sinisa Markovic The EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations started binding manufacturers. ENISA built the tool and runs its day-to-day operations, a […]

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities Read More »

HelmGuard Raises $7.3 Million for Agentic GRC and Security

HelmGuard Raises $7.3 Million for Agentic GRC and Security 2026-09-09 at 20:23 By Ionut Arghire The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

HelmGuard Raises $7.3 Million for Agentic GRC and Security Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

LevelBlue Strengthens Cyber Resilience for Australian Critical Infrastructure with New Sydney SOC

LevelBlue Strengthens Cyber Resilience for Australian Critical Infrastructure with New Sydney SOC 2026-08-27 at 05:00 By LevelBlue is making a multi-million-dollar investment in a new local Security Operations Center (SOC) in Sydney, going live August 25, 2026. The Sydney SOC gives Australian organizations, with a particular focus on critical infrastructure owners and operators, access to […]

LevelBlue Strengthens Cyber Resilience for Australian Critical Infrastructure with New Sydney SOC Read More »

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught […]

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts 2026-08-24 at 15:42 By Associated Press Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated […]

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Read More »

AWS makes it easier to spot firewall rules that have gone quiet

AWS makes it easier to spot firewall rules that have gone quiet 2026-08-24 at 07:00 By Anamarija Pogorelec AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability […]

AWS makes it easier to spot firewall rules that have gone quiet Read More »

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind 2026-08-21 at 11:41 By Eduard Kovacs Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek. This article […]

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Read More »

17 draft Cyber Resilience Act standards are open for comment

17 draft Cyber Resilience Act standards are open for comment 2026-08-14 at 07:30 By Anamarija Pogorelec A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to […]

17 draft Cyber Resilience Act standards are open for comment Read More »

Scroll to Top