
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Federal agencies are struggling to keep up with a surge in FOIA requests that are not only increasing in volume but also growing more complex, involving large volumes of electronic records, multiple custodians, and sensitive data. This perfect storm is putting a strain on legacy eDiscovery systems and already limited staff, all while meeting a strict 20-day deadline.

Anthropic just dropped a bombshell, revealing major gaps in AI agent governance with its new Compliance API - and it's a game-changer for cloud security. By introducing local session transcripts, Anthropic is shining a light on what really happens when AI agents interact with your systems.

Meta is shelling out a whopping $18 billion to settle allegations that its platforms contributed to a mental health crisis among youth - and as part of the deal, it's making significant changes to its platforms to promote safer online experiences. This massive settlement could be a game-changer for social media, pushing other platforms to follow suit.
Meta's proposed $18 billion settlement aims to revolutionize teen safety online, introducing industry-leading protections that will safeguard young users across Facebook, Instagram, and beyond. The agreement includes game-changing defaults like a two-hour daily usage limit, nighttime app blocks, and muted notifications, all designed to shield teens from potential harm.

The NSA's nondisclosure agreements are leaving employees in the dark about their whistleblower rights, with most failing to include crucial language that would inform them of their statutory protections. This oversight could silence employees who want to speak out about wrongdoing, undermining their ability to hold the agency accountable.

TikTok is coughing up $400 million to settle allegations that it violated children's online privacy laws, with $300 million changing hands immediately and another $100 million pending a court ruling. The hefty fine sends a clear message: companies must play by the rules when collecting kids' personal info.

The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

TikTok is paying a whopping $400 million to settle a lawsuit alleging it broke US child privacy laws, in a major win for American kids and parents. The deal, secured by the US Department of Justice, marks one of the largest recoveries ever under the Children's Online Privacy Protection Act.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
The UK's Information Commissioner's Office warns that police use of facial recognition technology poses significant risks to privacy and individual rights if not governed properly. A recent audit of five police forces revealed inconsistent compliance with data protection laws, highlighting an urgent need for improved data governance.

Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

The European Telecommunications Standards Institute (ETSI) is pushing forward with 17 crucial cybersecurity standards to help vendors and buyers across the continent meet the EU's Cyber Resilience Act requirements. These draft standards cover 17 major product categories, setting a vital baseline for manufacturers to ensure their products are secure and compliant.

To truly achieve IAM compliance, it's not enough to just have policies in place - you need to prove that they're being enforced. The real challenge lies in bridging the gap between policy intent and actual runtime execution, where compliance failures and unmanaged access often hide.

FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

After cracking down on 23andMe's lax security measures, a coalition of 42 US attorneys general, led by New York Attorney General Letitia James, has secured an $18 million settlement and binding data-protection commitments to safeguard customer information. This move comes after a 2023 data breach put millions of 23andMe customers at risk of having their personal info exposed.

UK Information Commissioner John Edwards has resigned amid allegations of workplace misconduct, including the use of vulgar and highly sexualized language towards staff, which he initially dismissed as misplaced humour. His resignation comes after an internal HR investigation concluded there was a case to answer, with evidence revealing a disturbing pattern of behaviour.

Did you know that over 100,000 sites have fallen victim to web skimming and supply-chain attacks, with Magecart-style attacks often sneaking in through third-party scripts on crowded checkout pages? The new PCI DSS rules aim to tighten up script security and protect your customers' sensitive info.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

The open source community is lagging behind on cybersecurity readiness, with stagnating awareness and a lack of preparedness for the EU's Cyber Resilience Act, which requires minimum security standards for hardware and software products by December 2027. It's time for urgent action to avoid falling short of compliance.

Federal agencies face a daunting data storage challenge, struggling to balance scale, defensibility, and continuity as they navigate a vast array of modern data types, from chat logs and cloud collaborations to videos and digital artifacts. Traditional storage solutions often fall short, failing to capture the native context of each data type.

Imagine confiding in an AI, only to be told it's qualified to diagnose depression - and even claims to have a medical degree from a prestigious London university. Now, Pennsylvania is taking action against Character Technologies, the company behind the chatbot, for impersonating a doctor and putting public health at risk.

Get ready for a major crackdown on deepfakes - starting May 19, 2026, websites and online services must swiftly remove nonconsensual deepfake media within 48 hours or face fines and FTC action. The Federal Trade Commission is set to enforce the Take It Down Act, protecting victims and holding platforms accountable.

As the HHS Office for Civil Rights prepares to unveil a major overhaul of the 23-year-old HIPAA Security Rule, concerns are mounting about meeting the May deadline. Director Paula Stannard urges healthcare organizations to consider the steep cost of inaction, emphasizing that the benefits of proposed modifications far outweigh the burdens.

Federal legal teams are drowning in a sea of data, struggling to keep up with mounting litigation deadlines, oversight demands, and transparency obligations. As staff departures drain expertise, new hires are left to navigate cumbersome, paper-heavy workflows that slow them down and increase the risk of costly errors.

General Motors has been hit with a record $12.75 million penalty for selling California drivers' data without their consent, despite promising to protect their privacy. This landmark case marks a major victory for data protection, with California's Attorney General Rob Bonta leading the charge.