Skip to main content

Tag: compliance

373 articles

Federal agency document processing room with employees working at desks amidst stacks of papers and laptops.

AI Reshapes Federal eDiscovery to Meet Surging FOIA Demands

Federal agencies are struggling to keep up with a surge in FOIA requests that are not only increasing in volume but also growing more complex, involving large volumes of electronic records, multiple custodians, and sensitive data. This perfect storm is putting a strain on legacy eDiscovery systems and already limited staff, all while meeting a strict 20-day deadline.

Analyst 207
Federal agency conference room with podium, laptop, and papers, bathed in natural light.

Federal Agencies Rethink Security with Continuous Authorization

Federal agencies are shaking up their security approach with continuous authorization, recognizing that a system's security can't be judged by its paperwork alone. By treating compliance as a stepping stone to mission success, agencies can deliver secure outcomes faster, without sacrificing speed for security.

Analyst 207
Worker in uniform reviews documents and speaks on phone at defense industrial base facility.

CMMC Pause Doesn't Halt Compliance Imperative

The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

Analyst 207
Neutral-colored room with multiple computer screens and servers, displays blurred or empty.

NIST Identifies Security Gaps in Multi-Cloud Environments

NIST warns that multi-cloud environments, which use two or more cloud service providers, pose unique cybersecurity and compliance risks, despite helping organizations reduce reliance on a single provider and maintain operations during outages or cyber-attacks. A recent NIST report aims to tackle these challenges by providing a structured problem statement and shared vocabulary to inform future research and solution design.

Analyst 207
Government building with tall windows and formal podium, daytime setting.

TikTok Settles Child Privacy Suit for $400 Million

TikTok is paying a whopping $400 million to settle a lawsuit alleging it broke US child privacy laws, in a major win for American kids and parents. The deal, secured by the US Department of Justice, marks one of the largest recoveries ever under the Children's Online Privacy Protection Act.

Analyst 207
Compliance officer reviewing documents at a desk with a computer terminal in the background.

IAM Compliance Requires Verified Enforcement

To truly achieve IAM compliance, it's not enough to just have policies in place - you need to prove that they're being enforced. The real challenge lies in bridging the gap between policy intent and actual runtime execution, where compliance failures and unmanaged access often hide.

Analyst 207
A research laboratory with computer screens and instruments, a large whiteboard, and a single laptop in the foreground.

Anthropic Embeds Watermarks in AI-Generated Text

Anthropic is taking a proactive approach to transparency with AI-generated text by embedding watermarks globally, ensuring accountability and compliance with regulations like the EU AI Act. This innovative technique, inspired by Google DeepMind's research, helps distinguish AI-created content from human-written text.

Analyst 207
Government employee works on laptop in secure data center with server racks.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations

The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

Analyst 207
Rows of servers and computer equipment in a data center interior.

LexisNexis Disrupts Services Amid Server Breach Probe

LexisNexis swiftly pulled the plug on three key services - Nexis Diligence, Metabase API, and Newsdesk - after detecting suspicious activity on servers managed by a third-party vendor, taking swift action to safeguard customers and contain the breach. The move comes as the company investigates the unusual server activity.

Analyst 207
Person in formal setting with laptop and network diagram on screen.

Zero-Knowledge Proofs Offer Secure Path for Cyber Risk Disclosure

ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

Analyst 207
Meeting space with table, mineral samples, and world map in background.

Pentagon Moves to Ease Industry Burden on Critical Mineral Restrictions

The Pentagon is giving industries a break, offering a phased approach to ease restrictions on critical minerals sourced from China and other prohibited countries, with a deadline to adapt by early 2027. They're also pledging to collaborate with companies to ensure a smooth transition.

Analyst 207
Security dashboard console displays Key Security Indicators with graphs and metrics in a bright, clean cloud computing…

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence

FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Analyst 207
Formal Department of Defense briefing room with empty chairs and podium.

Pentagon Scraps Cybersecurity Certification Phase, Launches Reform Review

The Department of Defense is shaking things up in the world of cybersecurity certification, suspending Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day review to explore a more streamlined approach. This move aims to ease compliance burdens, especially for small and medium-sized businesses.

Analyst 207
Partially constructed government facility with workers in background, symbolizing a pause or delay.

Pentagon Hits Pause on Cybersecurity Certification Requirements

The Pentagon has hit pause on its cybersecurity certification requirements, citing prohibitive compliance costs and bureaucratic burdens that could stifle innovation in the US defense industrial base. This 60-day suspension sparks a review that may reshape enforcement and acquisition rules for defense contractors.

Analyst 207
Modern government office interior with network pattern in window.

Federal Agencies Modernize Security with Zero Trust Architecture

Federal agencies are revolutionizing their security approach with Zero Trust Architecture, shifting from mere compliance to a robust operational framework that enables seamless mobility, cloud modernization, and AI-driven decision making. By embracing this cutting-edge strategy, leaders are transforming their organizations to stay ahead of emerging threats.

Analyst 207
Government building in Canberra with a laptop on a surface in the foreground.

Australia Shifts Cybersecurity Focus to Resilience Over Compliance

Australia is taking a bold step in cybersecurity, shifting its focus from mere compliance to building operational resilience, with a AU$89.3 million investment over four years to drive this change. The Horizon 2 Action Plan is set to boost the nation's cyber posture with 19 key actions and 64 initiatives.

Analyst 207
Dimly lit datacenter hallway with server racks and maintenance personnel in the distance, under flickering fluorescent…

US Datacenter Law Set to Lapse, Leaving Security Gaps Unaddressed

As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

Analyst 207
Cluttered workshop with scattered electronics and concerned people.

Open Source Community Unprepared for EU's Cyber Resilience Act

The open source community is lagging behind on cybersecurity readiness, with stagnating awareness and a lack of preparedness for the EU's Cyber Resilience Act, which requires minimum security standards for hardware and software products by December 2027. It's time for urgent action to avoid falling short of compliance.

Analyst 207
Modern tech lab with computer screens and devices on a neutral surface, surrounded by abstract shapes suggesting data…

Varonis Integrates Claude Compliance API for Enhanced AI Governance

Varonis has integrated the Claude Compliance API into its Atlas AI Security Platform, empowering enterprises to confidently adopt AI with enhanced governance and oversight. This integration enables security teams to monitor AI usage, detect misuse, and assess risks with unparalleled data context.

Analyst 207
Developer workstation with laptop, notes, and coffee cups in a bright, modern office setting with natural daylight.

AI-Powered Tools Elevate Vulnerability Detection, Pressing Secure-by-Design Mandate

With AI-powered tools, companies can now instantly detect and fix software vulnerabilities, making ignorance a thing of the past when it comes to cybersecurity. As Hans de Vries of ENISA notes, this shift makes a secure-by-design approach not just best practice, but a pressing mandate.

Analyst 207
Modern corporate office interior with a large blank screen in a sleek conference room.

Autonomous AI Exposes Governance Gaps in Enterprise Security

As autonomous AI revolutionizes enterprise security, it's also revealing alarming governance gaps that can leave organizations in highly regulated environments exposed to unprecedented risks. The rapid adoption of autonomous AI is creating a trust gap, where innovation outpaces control, and novel risks to visibility, control, and regulatory compliance are emerging.

Analyst 207
Bank compliance investigation room with laptop showing AI agent interface and financial documents.

FIS and Anthropic Unveil AI to Accelerate Money Laundering Probes

Imagine having an AI-powered ally that supercharges your money laundering investigations, automatically gathering evidence, detecting patterns, and prioritizing case files in minutes - not days. FIS and Anthropic have joined forces to bring you the Financial Crimes AI Agent, revolutionizing banking's most costly compliance challenge.

Analyst 207
Person in background reviews documents near digital interface, with abstract digital identity verification process in…

Digital KYC Push Stalls on Trust and Liability Concerns

KYC is more than just verifying identity - it's a crucial process that requires trust and accuracy to prevent financial crimes. Governments and banks are working together to modernize identity data collection and reuse, with countries like the UAE, Europe, and Singapore launching innovative projects to streamline compliance and strengthen anti-money laundering efforts.

Analyst 207
Computer screen displays blurred Excel spreadsheet in brightly-lit office with DevOps folder visible in background.

Fintech Firm Exposes Database Credentials in Shared Spreadsheet

A fintech firm's most sensitive secrets were left exposed in a shared spreadsheet, with a password that was embarrassingly simple - literally a combination of the company's name and the year. The shocking discovery was made by Stanislav Kazanov during a routine compliance audit, when he stumbled upon a widely accessible SharePoint folder containing a file ominously titled Prod_DB_Root_Creds_DO_NOT_SHARE.xlsx.

Analyst 207