List your product on Stack Search

Get in front of thousands of GRC decision-makers

IT Security & Privacy

Ofcom Sets Out Enforcement Approach as UK Online Safety Regime Takes Hold

Ofcom has set out how it plans to enforce the UK’s Online Safety Act across more than 100,000 companies, detailing an approach that can begin with guidance and direct regulatory pressure but escalate to investigations, fines and, in certain cases, measures that disrupt a company’s business.

Cyberattack Exposes Data of 8.7 Million Customers at Three Major UK Airports

Manchester Airports Group said criminal hackers accessed data belonging to about 8.7 million customers in a cyberattack affecting systems used across Manchester, London Stansted and East Midlands airports, one of the largest breaches of customer information disclosed by a UK airport operator.

CISA Red Team Tests Expose a Divide in How Security Teams Respond to Intrusions

At one critical infrastructure organization, CISA’s red team got in and kept going. It compromised multiple workstations, elevated its privileges over the domain and began moving laterally into other systems and resources. The security operations center never detected it.

Uber Faces €825 Million Fine Over Automated Driver Deactivations in French-Dutch GDPR Case

Uber’s software could cut a driver off from the platform for suspected fraud or poor customer ratings. What it did not necessarily do first was ask a person. That has now cost the company €824.99 million.

South Korea Rethinks Privacy Rules as AI Strains the Logic of Consent

The Personal Information Protection Commission has opened a public consultation on an overhaul of the country’s privacy protection framework, a review prompted in part by the widening distance between rules built around consent and forms of data processing that have become considerably harder to explain, much less reduce to a series of yes-or-no decisions.

Pokémon Center Customer Data Exposed in CEVA Logistics Cyberattack

Pokémon Center is notifying customers in the United Kingdom and Germany that personal and order information may have been exposed in a cyberattack on CEVA Logistics, the third-party provider it uses to fulfill and ship orders in those markets.

Privacy Has a Hoarding Problem

For a long time, deleting data could feel strangely reckless. Storage was cheap, and information was potentially valuable. The cost of keeping another year of customer records, internal correspondence, transaction histories or old documents was difficult to see, while the cost of deleting the wrong thing was easy to imagine. So companies kept it. Some of it was retained for legal or operational reasons, some because nobody was quite sure whether it could safely be destroyed, and some because of the most durable retention policy in corporate life: we might need it someday.