Blog

INSIGHT: GDPR Revamp the Opportunity for EU Bank Data-sharing to Fight Financial Crime

GDPR revamp could enhance EU banks' data-sharing to combat financial crime. Current regulations hinder sharing vital information between banks, stalling fraud prevention efforts. MEP Regina Doherty advocates for updates that maintain privacy while enabling quicker responses to scams, emphasizing the urgent need as fraud losses escalate in Europe. Improved data sharing can help detect fraudulent transactions and reduce broader financial crimes, balancing privacy rights and anti-crime measures.

https://www.amlintelligence.com/2025/04/insight-gdpr-revamp-the-opportunity-for-eu-bank-data-sharing-to-fight-financial-crime/

EU Plans Major GDPR Overhaul to Ease Business Compliance Rules

EU plans to amend GDPR to simplify compliance for SMEs, maintaining data privacy principles. Changes include streamlined documentation and reduced complexity for businesses under 500 employees. Intended to boost European digital competitiveness amid AI concerns, reforms will clarify algorithmic processing rules and address cross-border data transfer issues. Balancing privacy with law enforcement needs also under discussion. Legislative proposals expected by June 2025, aiming to harmonize enforcement standards across EU member states.

https://idtechwire.com/eu-plans-major-gdpr-overhaul-to-ease-business-compliance-rules/

DNS: The Secret Weapon CISOs May Be Overlooking in the Fight Against Cyberattacks

DNS is a crucial yet underutilized asset for Chief Information Security Officers (CISOs) in combating cyberattacks. As the first point of detection, DNS can prevent attacks by blocking malicious queries, disrupting command-and-control communications, and stopping data exfiltration. Recent advancements in AI have enabled cybercriminals to adapt rapidly, creating polymorphic malware and sophisticated phishing campaigns. By leveraging protective DNS combined with threat intelligence, CISOs can proactively safeguard their networks from evolving threats, urging a strategic shift to utilize DNS as a frontline defense system in the cybersecurity landscape.

https://www.securityweek.com/dns-the-secret-weapon-cisos-may-be-overlooking-in-the-fight-against-cyberattacks/

Meet the Deputy CISOs Who Help Shape Microsoft’s Approach to Cybersecurity

Microsoft's cybersecurity strategy includes a Cybersecurity Governance Council and Deputy Chief Information Security Officers (CISOs) focusing on risk management, compliance, and operational security. Key figures Igor Sakhnov, Mark Russinovich, and Yonatan Zunger lead initiatives in identity security, Azure security, and AI safety. They stress the importance of integrating security into innovation, assume that breaches will happen, and highlight misconceptions about perfect solutions in cybersecurity. Their leadership showcases a commitment to building resilient systems that involve collaboration across the company's tech landscape.

https://www.microsoft.com/en-us/security/blog/2025/04/08/meet-the-deputy-cisos-who-help-shape-microsofts-approach-to-cybersecurity/

2025 Cybersecurity Agenda: Upgrading Legacy Systems

TLDR: The 2025 Cybersecurity Agenda emphasizes modernizing legacy systems, particularly application servers, to enhance security, compliance, and operational resilience against sophisticated cyber threats. Most organizations rely on outdated technology, making them vulnerable, and modernization can help meet regulatory requirements, improve performance, and foster future readiness. Effective migration strategies and vendor support are crucial for successful upgrades.

https://www.forbes.com/councils/forbestechcouncil/2025/04/08/2025-cybersecurity-agenda-upgrading-legacy-systems/

News: The Hidden Risk: How Cybersecurity Impacts Operational Continuity in Automation

Cybersecurity risks threaten operational continuity in automated industries due to increasing connectivity of Industrial Control Systems (ICS). The integration of IT and operational technology enhances efficiency but exposes systems to cyber threats, as shown by events like Stuxnet and recent ransomware attacks. Vulnerabilities include outdated technologies, poor network separation, and insufficient employee training. Best practices for enhanced cybersecurity include risk assessments, network segmentation, limited user access, and regular training. Following international cybersecurity standards, such as IEC 62443 and frameworks like NIST CSF, is crucial for safeguarding industrial automation against evolving cyber threats.

https://www.automate.org/news/-81

NIS2 in Belgium: Are You Considered an ‘energy Producer’ if You Generate Power Solely for Your Own Use?

Belgium's NIS2 legislation classifies energy producers broadly. Companies generating energy solely for internal use, like solar or wind power, may still be deemed “energy producers” under NIS2 if they meet size criteria (medium or large). Thus, even minor energy generating activities can lead to compliance obligations, including incident reporting. However, proportionate oversight may be applied, recognizing lower societal impact from smaller operations.

https://www.eversheds-sutherland.com/en/slovakia/insights/nis2-in-belgium

Ask a CIO Recruiter: How AI Is Shaping the Modern CIO Role

AI is transforming CIO roles by demanding value creation and business acumen, while challenges persist due to legacy systems. Organizations seek CIOs with a mix of technical knowledge and practical AI implementation experience. Change leadership and cultural fit are crucial for success in technology-driven transformations. Aspiring CIOs should focus on collaboration and driving real business results.

https://www.informationweek.com/it-leadership/ask-the-cio-recruiter-how-ai-is-shaping-the-modern-cio-role

7 Risk Management Rules Every CIO Should Follow

7 Risk Management Rules for CIOs:
1. Establish risk appetite for alignment with IT strategy.
2. Maintain a comprehensive application inventory to mitigate risks.
3. Adopt a proactive cybersecurity culture and measures.
4. Formalize risk management in daily operations for clarity.
5. Assess risk strategies against real-world incidents.
6. Focus on system resiliency and recovery capabilities.
7. Align IT risk management with business objectives for better resource allocation.

https://www.cio.com/article/3954997/7-risk-management-rules-every-cio-should-follow.html

Can the EU’s Dual Strategy of Regulation and Investment Redefine AI Leadership?

EU's dual strategy on AI, combining regulation and investment, aims to establish global leadership and tech sovereignty. Deregulating large AI firms won't solve Europe's tech ecosystem issues; instead, robust regulation ensures trust, safety, and legal certainty, crucial for downstream companies. Europe must address structural barriers, such as fragmented markets and migration laws, instead of attributing tech dependency on regulation. A strong regulatory framework can foster innovation and public trust, positioning the EU to compete effectively with the US and China in AI development.

https://www.techpolicy.press/can-the-eus-dual-strategy-of-regulation-and-investment-redefine-ai-leadership/

Scroll to Top