Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

IT Security & Privacy

EU Cyber Resilience Act Reporting Requirements Take Effect

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

Italy’s Data Protection Authority has fined Banco Bilbao Vizcaya Argentaria Italia (BBVA) more than €5.5 million after finding that the bank continued sending promotional messages to a customer who had objected to receiving them, an enforcement action that exposed wider problems in how the bank managed privacy requests across its systems.

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.

Deloitte Finds Cyber Confidence Is Outpacing Readiness

Deloitte’s latest global cybersecurity survey begins with a number most CISOs would probably be pleased to see. Eighty-five percent of respondents say they are somewhat or very confident in their organization’s cybersecurity strategy.

Ofcom Opens Enforcement Push on Illegal Intimate Images & AI Deepfakes

Online platforms operating under the UK’s online safety regime have until the end of September to show they can stop illegal intimate images from spreading. Ofcom is no longer waiting for the deadline to find out whether they are ready.

Global Standard Setters Take Aim at Cyber & Third-Party Risks in Financial Market Infrastructure

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) on Tuesday published two consultative documents aimed at financial market infrastructures, or FMIs, pairing a practical cyber resilience toolkit with a discussion paper examining the risks created by FMIs’ growing reliance on third-party service providers.

South Korea Fines GS Retail $9.5 Million After Breaches Expose Data of More Than 1.6 Million People

South Korea’s Personal Information Protection Commission has imposed an approximately $9.47 million (KRW 12.836 billion) administrative monetary penalty on GS Retail, finding that the company failed to put adequate protections in place against cyberattacks and, after discovering the first breach, failed to respond adequately enough to prevent what followed.