EU Court of Justice Narrows Scope of When Pseudonymized Data Is Considered “Personal Data”

EU Court of Justice ruling narrows definition of “personal data,” stating pseudonymized data is only personal if re-identification is “reasonably likely” for the recipient. This shifts how organizations handle such data, impacting sectors like AdTech and AI training. Compliance obligations for GDPR remain based on the original controller's capabilities. Organizations can share pseudonymized data more freely, but must assess re-identification risks carefully.

https://www.armstrongteasdale.com/thought-leadership/eu-court-of-justice-narrows-scope-of-when-pseudonymized-data-is-considered-personal-data/

With Cyber on Execs’ Minds, CISOs Need ‘101’ Communication Skills

CISOs must communicate cybersecurity risks simply to executives, focusing on fundamental concepts. Protiviti's Sameer Ansari emphasizes avoiding technical jargon, instead sharing contextual stories about risks and controls to ensure understanding at the C-suite level. The rising focus on cybersecurity signs it’s a crucial business strategy, necessitating integration into executive discussions and decision-making.

https://www.itbrew.com/stories/2026/01/05/with-cyber-on-execs-minds-cisos-need-101-communication-skills

5 Myths About DDoS Attacks and Protection

5 myths about DDoS attacks:

  1. Myth 1: DDoS attacks are rare and only target large firms.
    Truth: They're frequent and affect all business sizes; 15M+ attacks occurred in 2024, often executed by low-cost DDoS-for-hire services.

  2. Myth 2: DDoS attacks only involve massive traffic floods.
    Truth: Attacks are increasingly small and targeted, with a rise in application-layer attacks noted.

  3. Myth 3: Next-gen firewalls can stop DDoS attacks.
    Truth: They can be vulnerable; combining them with specialized DDoS protection is crucial.

  4. Myth 4: Cloud-based DDoS protection is sufficient.
    Truth: Smaller attacks can bypass them; a hybrid approach is necessary for robust defense.

  5. Myth 5: AI/ML aren’t needed for DDoS protection.
    Truth: Attackers use AI to enhance attacks; defenses must incorporate AI to identify threats effectively.

To protect networks, debunking these myths is essential for implementing effective DDoS defenses.

https://www.csoonline.com/article/4110714/5-myths-about-ddos-attacks-and-protection.html

Cloud File-sharing Sites Targeted for Corporate Data Theft Attacks

A threat actor, Zestix, is selling stolen corporate data from breaches of ShareFile, Nextcloud, and OwnCloud instances. The data, obtained through info-stealing malware, includes sensitive information from various sectors, posing security and national security risks. Hudson Rock, a cybersecurity company, has identified the breaches and notified the affected platforms.

https://www.bleepingcomputer.com/news/security/cloud-file-sharing-sites-targeted-for-corporate-data-theft-attacks/

AWS Raises GPU Prices 15% on a Saturday

AWS increased GPU prices for EC2 Capacity Blocks by 15%, raising rates for major instances without prior warning on a Saturday. This shift, noted in January 2026, challenges the established expectation of decreasing cloud costs and raises concerns about future pricing trends, impacting companies reliant on machine learning workloads. Analysts speculate on a broader trend amid global resource constraints, potentially affecting other AWS services. Competitors may leverage this price hike as a marketing advantage.

https://www.theregister.com/2026/01/05/aws_price_increase/

Building End-to-end Workflows With Microsoft 365 Copilot

When integrated into critical workflows, Microsoft 365 Copilot delivers transformative results. Early adopters like J&Y Law and Babson College demonstrate how to build successful implementations by focusing on integration, data design, governance, and change management. These organizations emphasize the importance of structured data, AI literacy, and human oversight to ensure AI-generated materials are accurate and trustworthy.

https://www.computerworld.com/article/4110646/building-end-to-end-workflows-with-microsoft-365-copilot.html

10 Tough AI Questions for the 2026 Public-Sector CIO

GovTech highlights shifting priorities for public sector CIOs in 2026, with AI surpassing cybersecurity as the top focus. Key concerns include accountability in AI decisions, deepfake challenges, unauthorized AI use, quantum threats, workforce implications, securing service supply chains, operational resilience, machine identity management, AI-related budget allocations, and digital sovereignty amid geopolitical risks. Effective AI integration requires addressing these complex issues for future governance and service delivery.

https://www.govtech.com/blogs/lohrmann-on-cybersecurity/10-tough-ai-questions-for-the-2026-public-sector-cio

PCI Compliance: a Complete Guide to Its 12 Requirements

PCI DSS is a set of information security standards for organizations that process, store, or transmit cardholder data. The 12 requirements cover secure networks, data protection, vulnerability management, access control, monitoring, and information security policies. Achieving PCI DSS certification reduces data breach risk, strengthens customer trust, and protects business reputation.

https://mindsec.io/pci-compliance/

The Rise of Industrial Software

AI is industrializing software production, transforming it from a skilled craft into a cheaper, faster, and less human-dependent process. This shift raises concerns about the quality and value of software, leading to the rise of “disposable software” with minimal long-term investment. Historical precedents suggest that increased efficiency can fuel higher overall demand, resulting in overconsumption of low-quality products. However, a niche for high-quality, innovative software may persist, akin to handcrafted goods in other industries. As innovation and industrialization coalesce, the software landscape will see accelerated progress, but challenges around maintenance and oversight will emerge.

https://chrisloy.dev/post/2025/12/30/the-rise-of-industrial-software

Scroll to Top