regulation

Passwords, MFA and AD Accounts: Hardening Your Environment for NIS2

NIS2 mandates stricter cybersecurity for more sectors, emphasizing identity and access management (IAM). Key challenges include hardening Active Directory (AD) to secure authentication and authorization while ensuring compliance through robust password policies and multi-factor authentication (MFA). Organizations must adopt proactive measures, continuously monitor their systems, and maintain auditable identity processes. Failure to do so risks privilege escalation and network compromises. Recommendations for compliance include implementing fine-grained password policies, using passphrases, enforcing phishing-resistant MFA, and managing dormant accounts diligently. Ultimately, NIS2 provides a framework for organizations to enhance their cyber defenses and compliance efforts.

https://www.infosecurity-magazine.com/blogs/hardening-your-environment-for/

Top 10 Proposed Changes in the EU’s Digital Omnibus

EU's Digital Omnibus proposes reforms to modernize regulations such as the GDPR, NIS2, Data Act, and AI Act. Key changes include redefining personal data, expanding lawful processing bases for AI, refining data subject access rules, and altering cookie consent requirements. It aims to simplify reporting in cybersecurity and adjust deadlines for high-risk AI obligations. The legislative process may modify these proposals.

https://www.hoganlovells.com/en/publications/top-10-proposed-changes-in-the-eus-digital-omnibus

VAMP and MMP Bring the Heat to Merchant Risk

Payments industry faces heightened accountability amid rising fraud, driven by Visa's VAMP and Mastercard's MMP. These programs demand stricter monitoring and early risk detection of merchants' activities. With fraud at record levels and advanced tactics like AI being used to deceive, companies must adapt merchant risk programs through AI systems and continuous monitoring to comply and innovate effectively.

https://www.mytotalretail.com/article/compliance-countdown-vamp-and-mmp-bring-the-heat-to-merchant-risk/

It Might Not Be Sexy but MSPs Need to Talk About Certification

MSPs must prioritize certification for trust and compliance due to increasing regulations and industry demands. Standards like ISO 27001 and Cyber Essentials Plus are essential for reducing breaches and enhancing customer confidence, and upcoming cybersecurity controls are mandatory for top UK MSPs. As sectors relying on MSPs tighten security requirements, certifications are crucial for competitive advantage. Digital transformation, particularly AI, complicates compliance, necessitating investment in tools and expertise. MSPs that integrate certification into services will differentiate themselves and succeed as compliance becomes vital for business growth.

https://www.iteuropa.com/news/it-might-not-be-sexy-msps-need-talk-about-certification

European Commission Proposes Significant Reforms to GDPR, AI Act

TLDR: The European Commission proposed significant reforms to the GDPR and AI Act to simplify digital regulations due to the rapid growth of AI and competitiveness concerns. Key changes include allowing organizations to process personal data for AI with legitimate interests, streamlining cookie consent, establishing a single breach notification portal, and extending compliance timelines for high-risk AI regulations. Proposed amendments aim to balance economic growth while maintaining privacy rights, but they face mixed reactions, with concerns about reducing protections for users. The reforms will undergo negotiations in the European Parliament and may take several months to finalize.

https://iapp.org/news/a/european-commission-proposes-significant-reforms-to-gdpr-ai-act

Europe Is Scaling Back Its Landmark Privacy and AI Laws

Europe is reducing protections in its privacy and AI laws due to pressure from Big Tech and the US government. The EU plans to simplify GDPR regulations, moderate AI rules, and make it easier for companies to use personal data for AI training, aiming to foster innovation and economic growth. This includes reducing cookie pop-ups and centralizing AI oversight while facing criticism for potentially weakening user safeguards. The proposal will undergo scrutiny in the European Parliament and among member states, likely leading to significant debate and modification.

https://www.theverge.com/news/823750/european-union-ai-act-gdpr-changes

Deforestation: Council Ready to Start Talks With Parliament on a Targeted Revision of the Regulation

Council adopted a negotiating mandate to revise the EU deforestation regulation, aiming to simplify implementation and postpone deadlines. New application dates are 30 December 2026 for large operators and 30 June 2027 for smaller ones. A review will assess impacts on operators, especially smaller ones, and negotiations with Parliament will proceed for final agreement.

https://www.consilium.europa.eu/en/press/press-releases/2025/11/19/deforestation-council-ready-to-start-talks-with-parliament-on-a-targeted-revision-of-the-regulation/

Scroll to Top