Compliance

TikTok Finalizes a Deal to Form a New American Entity

TikTok Finalizes a Deal to Form a New American Entity 2026-01-26 at 14:37 By Associated Press TikTok has finalized a deal to create a new American entity, avoiding the looming threat of a ban in the United States. The post TikTok Finalizes a Deal to Form a New American Entity appeared first on SecurityWeek. This […]

TikTok Finalizes a Deal to Form a New American Entity Read More »

AWS releases updated PCI PIN compliance report for payment cryptography

AWS releases updated PCI PIN compliance report for payment cryptography 2026-01-26 at 07:05 By Anamarija Pogorelec Amazon Web Services has published an updated Payment Card Industry Personal Identification Number (PCI PIN) compliance package for its AWS Payment Cryptography service, confirming a recent third-party audit of the platform. The report package is now accessible through AWS’s

AWS releases updated PCI PIN compliance report for payment cryptography Read More »

Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements

Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements 2026-01-23 at 15:31 By Kevin Townsend Cyber regulations are where politics meets business – where business becomes subject to political realities. The post Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements appeared first on SecurityWeek. This article is an excerpt from

Cyber Insights 2026: Regulations and the Tangled Mess of Compliance Requirements Read More »

Security leaders push for continuous controls as audits stay manual

Security leaders push for continuous controls as audits stay manual 2026-01-21 at 07:03 By Anamarija Pogorelec Security teams say they want real-time insight into controls, but still rely on periodic checks that trail daily operations. New RegScale research shows how wide that gap remains and where organizations are directing time, staff, and budget to manage

Security leaders push for continuous controls as audits stay manual Read More »

Privacy teams feel the strain as AI, breaches, and budgets collide

Privacy teams feel the strain as AI, breaches, and budgets collide 2026-01-20 at 07:31 By Anamarija Pogorelec Privacy programs are under strain as organizations manage breach risk, new technology, and limited resources. A global study from ISACA shows that AI is gaining ground in privacy work, with use shaped by governance, funding, and how consistently

Privacy teams feel the strain as AI, breaches, and budgets collide Read More »

Investor Lawsuit Over CrowdStrike Outage Dismissed

Investor Lawsuit Over CrowdStrike Outage Dismissed 2026-01-14 at 19:20 By Eduard Kovacs A judge has ruled that the plaintiffs failed to demonstrate intent to defraud investors.  The post Investor Lawsuit Over CrowdStrike Outage Dismissed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Investor Lawsuit Over CrowdStrike Outage Dismissed Read More »

CISO Assistant: Open-source cybersecurity management and GRC

CISO Assistant: Open-source cybersecurity management and GRC 2026-01-14 at 13:25 By Mirko Zorz CISO Assistant is an open-source governance, risk, and compliance (GRC) platform designed to help security teams document risks, controls, and framework alignment in a structured system. The community edition is maintained as a self-hosted tool for organizations that want direct access to

CISO Assistant: Open-source cybersecurity management and GRC Read More »

Passwords are where PCI DSS compliance often breaks down

Passwords are where PCI DSS compliance often breaks down 2026-01-08 at 07:36 By Sinisa Markovic Most PCI DSS failures do not start with malware or a targeted attack. They start with everyday behavior. Reused passwords. Credentials stored in spreadsheets. Shared logins are passed around during busy periods. For CISOs, password hygiene remains one of the

Passwords are where PCI DSS compliance often breaks down Read More »

What European security teams are struggling to operationalize

What European security teams are struggling to operationalize 2026-01-07 at 08:32 By Anamarija Pogorelec European security and compliance teams spend a lot of time talking about regulation. A new forecast report from Kiteworks suggests the harder problem sits elsewhere. According to the report, many European organizations have strong regulatory frameworks on paper, driven by GDPR

What European security teams are struggling to operationalize Read More »

Passwords are still breaking compliance programs

Passwords are still breaking compliance programs 2026-01-06 at 07:32 By Sinisa Markovic The security stack has grown, but audits still stumble on passwords. CISOs see this every year. An organization may have strong endpoint tools, layered network defenses, and a documented access policy. Then the audit turns to shared credentials, spreadsheet-based password storage, or accounts

Passwords are still breaking compliance programs Read More »

New State Laws Impact AI Governance, Risk, and Compliance

New State Laws Impact AI Governance, Risk, and Compliance 2026-01-05 at 18:48 By Scott Swanson New York has started a movement to reshape the AI compliance landscape for companies doing business in the state. Other states are following suit making Governance and AI Compliance an increasingly critical endeavor. This article is an excerpt from LevelBlue

New State Laws Impact AI Governance, Risk, and Compliance Read More »

Pharma’s most underestimated cyber risk isn’t a breach

Pharma’s most underestimated cyber risk isn’t a breach 2026-01-05 at 08:47 By Mirko Zorz Chirag Shah, Global Information Security Officer & DPO at Model N examines how cyber risk in pharma and life sciences is shifting beyond traditional breaches toward data misuse, AI-driven exposure and regulatory pressure. He explains why executives still underestimate silent control

Pharma’s most underestimated cyber risk isn’t a breach Read More »

Understanding AI insider risk before it becomes a problem

Understanding AI insider risk before it becomes a problem 2026-01-05 at 07:31 By Help Net Security In this Help Net Security video, Greg Pollock, Head of Research and Insights at UpGuard, discusses AI use inside organizations and the risks tied to insiders. He explains two problems. One involves employees who use AI tools to speed

Understanding AI insider risk before it becomes a problem Read More »

What shadow AI means for SaaS security and integrations

What shadow AI means for SaaS security and integrations 2026-01-02 at 08:30 By Help Net Security In this Help Net Security video, Jaime Blasco, CTO at Nudge Security, discusses why shadow AI matters to security teams. He describes how AI adoption happens in two ways, through company led programs and through employees choosing tools on

What shadow AI means for SaaS security and integrations Read More »

Five identity-driven shifts reshaping enterprise security in 2026

Five identity-driven shifts reshaping enterprise security in 2026 2025-12-24 at 11:18 By Help Net Security 2026 marks the tipping point when artificial intelligence begins to fundamentally reshape cyber risk. After several years of widespread adoption, AI moves beyond influencing how we work and starts transforming the enterprise itself. AI is now embedded at every layer

Five identity-driven shifts reshaping enterprise security in 2026 Read More »

Governance maturity defines enterprise AI confidence

Governance maturity defines enterprise AI confidence 2025-12-24 at 08:17 By Anamarija Pogorelec AI security has reached a point where enthusiasm alone no longer carries organizations forward. New Cloud Security Alliance research shows that governance has become the main factor separating teams that feel prepared from those that do not. Governance separates confidence from uncertainty Governance

Governance maturity defines enterprise AI confidence Read More »

Weak enforcement keeps PCI DSS compliance low

Weak enforcement keeps PCI DSS compliance low 2025-12-23 at 09:41 By Sinisa Markovic Payment card breaches continue to surface across industries, even after years of investment in security standards. A new study links this pattern to enforcement, showing that PCI DSS compliance trails behind HIPAA, GDPR, and the EU’s NIS2 Directive. A compliance gap that

Weak enforcement keeps PCI DSS compliance low Read More »

Session tokens give attackers a shortcut around MFA

Session tokens give attackers a shortcut around MFA 2025-12-22 at 07:45 By Help Net Security In this Help Net Security video, Simon Wijckmans, CEO at cside, discusses why session token theft is rising and why security teams miss it. He walks through how web applications rely on browsers to store session tokens after login often

Session tokens give attackers a shortcut around MFA Read More »

Banks built rules for yesterday’s crime and RegTech is trying to fix that

Banks built rules for yesterday’s crime and RegTech is trying to fix that 2025-12-17 at 08:32 By Sinisa Markovic Criminals are moving money across borders faster, and financial institutions are feeling the squeeze. Compliance teams feel this strain every day as they try to keep up with schemes that shift through accounts, intermediaries, and digital

Banks built rules for yesterday’s crime and RegTech is trying to fix that Read More »

Scroll to Top