compliance

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side

Anthropic’s AI system Mythos significantly accelerates vulnerability discovery, posing challenges for many organizations that lack the operational infrastructure to efficiently triage, prioritize, and remediate the increased volume of findings. The article highlights that while Mythos improves detection speed, most security teams struggle with closing the discovery-to-remediation gap, emphasizing the need for centralized management, risk-based prioritization, and closed-loop remediation workflows to effectively address vulnerabilities identified by advanced AI tools.

https://thehackernews.com/2026/04/mythos-changed-math-on-vulnerability.html

How the EU’s NIS2 Directive Is Changing How CIOs Think About Digital Infrastructure

The EU’s NIS2 directive is prompting CIOs to rethink digital infrastructure by extending risk accountability beyond individual organizations to encompass the entire ecosystem of interconnected providers, including cloud platforms and network operators. This shift emphasizes designing resilient systems that can continue operating despite failures in any part of the network, moving resilience from a compliance exercise to a strategic priority focused on infrastructure architecture and connectivity.

https://www.cio.com/article/4162091/how-the-eus-nis2-directive-is-changing-how-cios-think-about-digital-infrastructure.html

EU AI Act Shock: Emotion Recognition Is Now Illegal at Work. So Why Is Your Vendor Still Selling It?

The EU AI Act, effective since February 2025, has made emotion recognition AI in the workplace illegal across the European Union, imposing fines up to €35 million or 7% of global turnover for violations. Despite this, many vendors continue to sell and deploy such technology unlawfully, risking significant penalties, while the law strictly prohibits AI systems that infer employee emotions from biometric data but allows text-only sentiment analysis. Organizations using UC, CX, or employee experience software in Europe are urged to urgently verify vendor compliance and disable prohibited features to avoid imminent enforcement actions.

https://www.uctoday.com/workplace-management/eu-ai-act-shock-emotion-recognition-is-now-illegal-at-work-so-why-is-your-vendor-still-selling-it/

The EU’s AI Act: Do You Have the Knowledge to Comply?

The article highlights a critical compliance challenge posed by the EU AI Act, effective from August 2, 2026, for enterprises using AI-driven marketing automation workflows. It warns that while strategic AI governance often exists at the leadership level, many operational AI systems—like customer scoring models and data enrichment flows—are undocumented and lack clear ownership, putting organizations at risk of non-compliance under the Act’s transparency, documentation, and human oversight requirements.

https://www.business-reporter.co.uk/ai–automation/the-eus-ai-act-do-you-have-the-knowledge-to-comply

EU AI Act Compliance: a Technical Audit Guide for the 2026 Deadline

With the August 2026 deadline for the EU AI Act approaching, IT leaders must shift from policy to practical compliance by mapping AI tools across APIs, legacy systems, and model integrations to ensure auditable governance. Organisations need to build comprehensive API inventories, implement continuous monitoring systems, categorise AI endpoints by risk, and rigorously audit high-risk legacy systems for transparency, human oversight, and bias mitigation to meet the stringent regulatory requirements and avoid significant fines and reputational damage.

https://www.raconteur.net/global-business/eu-ai-act-compliance-a-technical-audit-guide-for-the-2026-deadline

New Compliance Guide Available: ISO/IEC 27001:2022 on AWS

AWS has released a new compliance guide titled “ISO/IEC 27001:2022 on AWS,” which offers practical guidance for organizations implementing an Information Security Management System (ISMS) using AWS services. The guide helps align cloud environments with the ISO/IEC 27001:2022 standard, detailing how to integrate AWS security controls, manage governance and risks, and prepare for certification audits by leveraging AWS security, monitoring, and automation capabilities.

https://aws.amazon.com/blogs/security/new-compliance-guide-available-iso-iec-270012022-on-aws-compliance-guide/

14 Risk Oversight Principles You Haven’t Heard Before

Protiviti’s Jim DeLoach presents 14 lesser-known principles of risk oversight aimed at enhancing enterprise risk management (ERM) effectiveness, emphasizing continuous improvement in risk reporting, integration of risk processes into business operations, and adapting to digital transformation. He stresses the importance of balancing risk and opportunity, fostering collaboration across organizational levels, making timely decisions with imperfect information, and cultivating a culture of open risk discussions, all to better prepare organizations for uncertainty and align risk management with strategic goals.

https://www.corporatecomplianceinsights.com/14-risk-oversight-principles-you-have-not-heard-before/

Back to Basics: 14 Risk Oversight Rules You Know (But May Be Ignoring)

Jim DeLoach outlines 14 fundamental risk oversight principles that remain crucial despite advances in digital tools, emphasizing that risk management must be aligned with strategy and adapt continuously to a rapidly changing environment. He highlights the importance of understanding calculated risks, vigilance against cognitive biases, preparation for contingencies, and maintaining strong culture and communication to effectively manage critical enterprise risks and ensure organizational resilience.

https://www.corporatecomplianceinsights.com/risk-oversight-rules-you-know/

Ten Things to Ask Your IT Team About NIS2 Compliance

The article discusses the key areas organizations must address to ensure compliance with the EU's NIS2 directive, which mandates robust cybersecurity governance and resilience. It highlights ten critical focus points including risk analysis, incident handling, business continuity, supply chain security, and the importance of continuous evidence gathering and proper IT tools. The article emphasizes that leadership must proactively oversee cybersecurity measures to meet strict regulatory requirements and maintain business continuity in the face of threats.

https://www.kaseya.com/blog/nis2-compliance/

Cisa Urges Endpoint Management System Hardening After Cyberattack Against US Organization

The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert following a cyberattack on U.S.-based medical technology firm Stryker Corporation targeting their Microsoft environment. CISA urges organizations to harden endpoint management system configurations by implementing Microsoft’s best practices for securing Microsoft Intune, including least privilege administrative roles, phishing-resistant multi-factor authentication, and multi-admin approval policies, to protect against similar malicious activities.

https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization

Scroll to Top