Federal CIO Outlines 16 Operating Principles for IT Leaders

Federal CIO Greg Barbaccia presents 16 operating principles for new federal IT leaders, emphasizing trust, accountability, and proactivity. With a wave of new, inexperienced CIOs, he aims to establish a culture shift in federal technology management. Reactions to the principles vary, with some seeing the message as condescending while others recognize its necessity for new leaders. Barbaccia's guidelines stress understanding missions, owning outcomes, and fostering collaboration, intending to modernize government IT practices and improve effectiveness amid significant turnover in CIO roles.

https://federalnewsnetwork.com/cio-news/2025/05/federal-cio-outlines-16-operating-principles-for-it-leaders/

EDPB Releases Guidelines on Blockchain Personal Data Processing

EDPB released guidelines on blockchain personal data processing, addressing GDPR compliance challenges due to blockchain's immutability and decentralization. It emphasizes clarified roles for nodes and advocates for minimized personal data use, encryption, or hashing to protect data, and off-chain storage for eraseability. Public consultation open until June 9, 2025, with expected consistency in final guidelines.

https://natlawreview.com/article/blocks-rights-privacy-and-blockchain-eyes-eu-data-protection-authorities

NIS2 Directive: New Rules on Cybersecurity of Network and Information Systems

NIS2 Directive enhances EU cybersecurity rules across 18 sectors, requiring member states to develop national strategies, manage risks, report incidents, and establish accountability. It expands coverage beyond energy and healthcare to include public services and digital platforms, fostering cooperation and information sharing among nations through CSIRTs and networks like EU-CyCLONe. This legislation, effective from January 2023, supersedes NIS1, aiming for heightened security amidst rising cyber threats. Member states must comply by October 2024.

https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

EU Clarifies AI Act’s Prohibited Practices With New Guidelines

EU issues guidelines clarifying prohibited AI practices under AI Act. Key prohibitions include manipulative techniques, social scoring, risk assessments for crime prediction, untargeted facial image scraping, emotion recognition in certain settings, biometric categorization of sensitive traits, and real-time biometric identification for law enforcement. Guidelines establish legal certainty, refine definitions, and highlight the interplay with existing EU laws. Safeguards for exemptions will require impact assessments on fundamental rights.

https://natlawreview.com/article/european-commissions-guidance-prohibited-ai-practices-unraveling-ai-act

Status Check: Support Is Quickly Eroding for the EU-U.S. Data Privacy Framework

Support for the EU-U.S. Data Privacy Framework (DPF) is declining. Recent deregulation and European concerns threaten its stability. Businesses must retain their DPF certification but prepare alternative data transfer methods. Key issues include the U.S. Privacy & Civil Liberties Oversight Board's weakened status and EU warnings about the DPF's adequacy. European regulators recommend “exit strategies” due to anticipated legal challenges, and advocacy groups are pushing for reduced reliance on U.S. data services. Overall, the landscape for transatlantic data transfers is becoming precarious.

https://www.thefirewall-blog.com/2025/05/status-check-support-is-quickly-eroding-for-the-eu-u-s-data-privacy-framework/

Primary Mitigations to Reduce Cyber Threats to Operational Technology

CISA and other agencies recommend key mitigations for critical infrastructure to reduce cyber threats targeting operational technology (OT) and industrial control systems (ICS):

  1. Remove OT connections to the internet.
  2. Change default passwords to strong, unique ones.
  3. Secure remote access with private network connections and strong authentication.
  4. Document and configure remote access solutions based on least privilege.
  5. Segment IT and OT networks.
  6. Maintain the capability to operate OT systems manually.

Organizations should collaborate with service providers to fix potential misconfigurations. Regular communication and established best practices are essential for enhancing cybersecurity posture.

https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology

CIOs Pay Too Much for Not Enough IT Security

CIOs face IT security challenges, overpaying for ineffective solutions as breaches increase. A survey reveals 90% experienced breaches; half feel they've overspent and underutilized security features. Complexity and inadequate tools hinder effectiveness. The industry shifts towards consolidated, integrated security to simplify procurement and enhance effectiveness, despite concerns over vendor lock-in.

https://www.ciodive.com/news/cios-pay-too-much-for-not-enough-it-security/747194/

States Are Passing AI Laws; What Do They Have in Common?

States are enacting AI laws influenced by the EU AI Act. Common features include disclosure of AI-generated content, use-case transparency, regulations for high-risk applications, and anti-discrimination measures. States like California, Colorado, and Utah lead in these regulations, emphasizing transparency and stakeholder compliance, with potential sanctions for non-compliance. Companies must align with these laws through governance programs, risk assessments, and ethical practices.

https://www.corporatecomplianceinsights.com/states-passing-ai-laws-what-do-they-have-common/

Scroll to Top