compliance

CIO Risk Management: Lessons From Southern Glazer’s CIO

CIOs face diverse technology risks, not limited to cybersecurity. Key insights from Steve Bronson of Southern Glazer's include managing operational fragility, talent gaps, AI uncertainties, and vendor dependencies. He emphasizes the importance of governance, adopting T-shaped teams for talent development, maintaining flexibility through microservices, and building redundant systems in supply chains. Risks should be viewed holistically, prioritizing non-cyber threats based on their likelihood and potential impact while effectively communicating these risks to executives through an outcomes-focused approach.

https://www.techtarget.com/searchcio/feature/CIO-risk-management-Lessons-from-Southern-Glazers-CIO

5 Innovations Desperately Needed for EUDR Compliance

EUDR compliance poses challenges, especially for small businesses, as the EU Deforestation Regulation aims to eliminate deforestation in global supply chains. Key innovations needed include public policy improvements, collaborative corporate practices, innovative financial services, action from civil society, and harmonized technological solutions. While major firms are preparing for the regulation, smaller players require support to meet compliance requirements. Ultimately, harmonized tech and collective efforts will be crucial for transitioning to sustainable, deforestation-free supply chains.

https://www.foodnavigator.com/Article/2026/03/03/innovations-for-eudr-compliance/

Day 80: Data Protection – Building Enterprise-Grade Privacy and Security

A comprehensive data protection system is being implemented, focusing on encryption, data classification, privacy controls, and GDPR compliance. The system utilizes AES-256-GCM encryption, a data classification system with four sensitivity levels, and a privacy control framework with granular consent management. Additionally, it incorporates data masking strategies and automated GDPR compliance workflows to ensure data security and privacy at scale.

https://fullstackinfra.substack.com/p/day-80-data-protection-building-enterprise?source=queue

Security Obligations Under GDPR Still Apply, Even if Data Is Anonymous in the Hands of an Attacker

UK Court of Appeal ruled in DSG Retail v. Information Commissioner that GDPR security obligations remain for controllers even if data is anonymous to attackers. The decision emphasizes the broad nature of “personal data” and the need for controllers to protect against unauthorized access, regardless of how data may appear to a third party. This ruling challenges prior interpretations that could diminish data protection responsibilities. It suggests that GDPR accountability may extend beyond the direct data handling by the controller.

https://iapp.org/news/a/security-obligations-under-gdpr-still-apply-even-if-data-is-anonymous-in-the-hands-of-an-attacker

Secure or Just Certified? Why the Audit Report Is Not the End of Your Security Story

Compliance is just the starting point for true cybersecurity; it establishes a baseline, not an ultimate protection. Effective security requires a deeper understanding of vulnerabilities beyond compliance checklists. Organizations must rigorously manage supplier risks, as breaches can occur through third-party access. Additionally, navigating overlapping regulations like PCI DSS and GDPR requires adaptability. Security relies on culture and awareness, not just technology. Organizations should focus on resilience, viewing compliance as one layer in a broader, proactive strategy. True protection goes beyond audits to preventing breaches.

https://www.intelligentciso.com/2026/02/20/secure-or-just-certified-why-the-audit-report-is-not-the-end-of-your-security-story/

When AI Agents Pay: Who Owns the Compliance Liability?

AI agents in commerce raise complex compliance issues regarding transactional liability. With their adoption accelerating, traditional regulatory frameworks (such as PCI DSS, AML, and DORA) may struggle to keep pace, as compliance is hard to assign when AIs initiate payments. Financial institutions must proactively assess their compliance strategies for AI interactions to avoid future liability risks, particularly around transaction monitoring, script security, and operational resilience. Immediate steps include mapping integrations and recalibrating AML systems. Delayed action may lead to regulatory crises as compliance standards evolve.

https://www.finextra.com/blogposting/30917/when-ai-agents-pay-who-owns-the-compliance-liability

From Innovation to Regulation: How Internal Audit Must Respond to the EU AI Act

The EU AI Act, a global standard for AI regulation, requires organizations worldwide to address AI risks through governance, controls, and accountability. Internal auditors must adapt to this shift, auditing AI governance, risk classification, data quality, human oversight, and third-party AI risk to ensure compliance.

https://www.wolterskluwer.com/en/expert-insights/innovation-regulation-how-internal-audit-must-respond-eu-ai-act

With CISOs Stretched Thin, Re-envisioning Enterprise Risk May Be the Only Fix

CISOs face unmanageable workloads as their responsibilities expand without corresponding resources, leading to burnout and ineffective leadership. Experts suggest reassessing the role by redistributing responsibilities and granting appropriate authority. This structural change aims to alleviate pressure and enable CISOs to focus on cyber risk management effectively, rather than being overwhelmed by a multitude of unrelated tasks.

https://www.csoonline.com/article/4128992/with-cisos-stretched-thin-re-envisioning-enterprise-risk-may-be-the-only-fix.html

Breaking Down NIS2: the Five Main Requirements of the Updated NIS Directive

NIS2, an update of the EU's cyber security framework, aims to enhance resilience against evolving threats across more sectors, covering essential and important entities. It introduces five key compliance requirements: risk management, incident reporting, cyber security practices, third-party risk management, and workforce security training. NIS2 is an ongoing process, not a one-time compliance task. The directive sets a baseline for accountability and resilience in cyber security across the EU.

https://www.financierworldwide.com/breaking-down-nis2-the-five-main-requirements-of-the-updated-nis-directive

TPRM Governance: How Companies Strategically Manage Third-party Risks

KPMG discusses third-party risk management (TPRM) governance as essential for navigating challenges like geopolitical tensions, cyber threats, and regulatory pressures. Effective TPRM evolves from mere compliance into a strategic tool for resilience and business value. Companies struggle with outdated structures and fragmented approaches, necessitating clear governance to define roles, responsibilities, and risk categories. Successful TPRM requires centralized oversight for transparency, with roles well-defined to ensure consistent risk management. Future insights will address technological advancements in TPRM.

https://kpmg.com/de/en/services/audit/regulatory-advisory/tprm-governance-how-companies-strategically-manage-third-party-risks.html

Scroll to Top