Tag: compliance
-
The SOC 2 Trap: Why Compliance Belongs on the Platform, Not in a Spreadsheet
A few years ago I spent the better part of three weeks helping a platform team pull together evidence for a SOC 2 Type II audit that, honestly, should have taken maybe a sprint and a half. Nothing was actually broken. Access reviews had happened. Change management was real. Encryption was configured correctly everywhere it..…
-
Cryptohack Roundup: Trezor’s Phishing Warning
Also: ‘White-Hat’ Hackers Withdraw $320M From Liquid. Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Trezor warns customers after email provider breach, Liquid pauses network after $320 million Bitcoin withdrawal, man pleads guilty in $245 million theft and India targets 15 crypto platforms over compliance failures. First seen on govinfosecurity.com Jump…
-
The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5. Best Apple pricing: Mosyle, with a free tier that genuinely works. Best Apple depth: Jamf. Best published mid-market pricing: ManageEngine, Hexnode, and Scalefusion. Best rugged: SOTI. Deploying dedicated MDM allows organizations to enforce policy baseline compliance and device health verification within a […]…
-
Vertrauen ist keine Compliance – KI-Reife: Veeam will Unternehmen den Spiegel vorhalten
First seen on security-insider.de Jump to article: www.security-insider.de/veeam-data-ai-trust-maturity-model-ki-governance-a-a1e244c485c7bf075869c29faf3eecdf/
-
Vertrauen ist keine Compliance – KI-Reife: Veeam will Unternehmen den Spiegel vorhalten
First seen on security-insider.de Jump to article: www.security-insider.de/veeam-data-ai-trust-maturity-model-ki-governance-a-a1e244c485c7bf075869c29faf3eecdf/
-
A New AI Vulnerability Exposes the Security Gap That PQC Won’t Fix
In a previous article, we discussed why PQC compliance does not equal architectural resilience. In this post, we’ll explore why organizations must be prepared to protect identity, context, communications, and paths not merely ciphertext. What a New AI Vulnerability… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/a-new-ai-vulnerability-exposes-the-security-gap-that-pqc-wont-fix/
-
Compliance und Datenschutz – Nextcloud Files erhält französische CSPN-Sicherheitszertifizierung
Tags: complianceFirst seen on security-insider.de Jump to article: www.security-insider.de/nextcloud-files-erhaelt-franzoesische-cspn-sicherheitszertifizierung-a-8e407a439f906872dc84b30daf165129/
-
How to Create an AI Acceptable Use Policy Employees Will Follow
Lou Morentin, VP, Compliance and Privacy September 8, 2026 “Telling employees to “use AI responsibly” leaves too much open to interpretation. ” Key Takeaways An AI acceptable use policy should identify approved tools, permitted data, and situations that require additional review. Rules should reflect how employees already… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-create-an-ai-acceptable-use-policy-employees-will-follow/
-
The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose compliance requirements don’t demand enterprise wireless intrusion prevention. Best capability: HPE Aruba. Best management: Cisco Meraki and Juniper Mist. Best if you own the firewall: Fortinet, utilizing your existing FortiGate firewalls. The critical cost question in…
-
Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not. The study, carried out in July 2026…
-
How a Cyber Risk Platform Unifies Security Operations and Compliance
Key Takeaways Security operations and compliance run on separate tracks in most enterprises, and that split creates duplicated work, slower threat response, and a fragmented view of risk that no executive can act on. Enterprises struggle with cyber risk management… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-cyber-risk-platform-unifies-security-operations-and-compliance/
-
How a Cyber Risk Platform Unifies Security Operations and Compliance
Key Takeaways Security operations and compliance run on separate tracks in most enterprises, and that split creates duplicated work, slower threat response, and a fragmented view of risk that no executive can act on. Enterprises struggle with cyber risk management… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-cyber-risk-platform-unifies-security-operations-and-compliance/
-
Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance
Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance September 3, 2026 Dan Mengel BLOG 5 min. What Happened On August 31, 2026, the PCI Security Standards Council (PCI SSC) updated FAQ 1331 on its website…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/recent-update-to-faq-regarding-saq-eligibility-criteria-could-affect-your-pci-dss-compliance/
-
How Enterprise Buyers Choose Cybersecurity Vendors in the Age of Agentic AI
Enterprise cybersecurity buyers are moving beyond compliance and feature lists, demanding proof, continuous validation and security built for agentic AI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-enterprise-buyers-choose-cybersecurity-vendors-in-the-age-of-agentic-ai/
-
Security-by-Design: Was der Cyber Resilience Act für IoT-Hersteller bedeutet
Der Cyber Resilience Act verschiebt Cybersicherheit im IoT von der technischen Kür zur unternehmerischen Pflicht. Für Hersteller vernetzter Produkte bedeutet das: Security-by-Design, belastbare Meldeprozesse und kontinuierliche Transparenz werden zu zentralen Voraussetzungen für Marktzugang, Compliance und operative Resilienz. Management Summary Der CRA macht Cybersicherheit zur Marktzugangsvoraussetzung: Hersteller digitaler Produkte müssen Sicherheit künftig über den gesamten Lebenszyklus……
-
Datenresidenz und Datensouveränität im Zeitalter der KI
Datenresidenz allein reicht im KI-Zeitalter nicht mehr aus. Wer Souveränität ernst nimmt, muss Speicherort, Rechtszuständigkeit, operative Kontrolle, Verschlüsselung, Provider-Abhängigkeiten und Governance-End-to-End zusammendenken. Für IT-Entscheider wird Datensouveränität damit von einer Compliance-Frage zur strategischen Architekturentscheidung. Management Summary Datenresidenz ist nicht Datensouveränität: Der Standort eines Rechenzentrums beantwortet nicht die entscheidende Frage, wer rechtlich, technisch und operativ Zugriff auf……
-
Pistachio Expands Into Compliance With Hugin.io Acquisition
Hugin.io’s Technology Will Help Explain How Security Risk Scores Are Calculated. Pistachio acquired Norwegian startup Hugin.io’s technology to combine human risk, security posture and compliance data, aiming to produce more defensible risk scores, automate regulatory monitoring and give security teams prioritized remediation guidance. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/pistachio-expands-into-compliance-huginio-acquisition-a-32716
-
Liquibase Brings Database Change Governance to Germany’s Most Regulated Enterprises
Germany’s enterprise IT organizations, from DAX-listed manufacturers to highly regulated banks, insurers, and pharmaceutical companies, are under the same pressure driving digital transformation everywhere: deliver software and AI-powered products faster, without sacrificing the compliance and audit standards regulators demand. Application… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/liquibase-brings-database-change-governance-to-germanys-most-regulated-enterprises/
-
KI und Compliance – Kiteworks-Report: Sicherheit top, KI-Governance flop?
First seen on security-insider.de Jump to article: www.security-insider.de/kiteworks-report-sicherheit-top-ki-governance-flop-a-8f143aa6fa4d6699f00911b21d2fe72c/
-
NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/nis2-credential-compliance-before-audit/
-
LogicGate Bets on AI Agents to Automate GRC Workflows
Incoming CEO Diego Panama Says AI Can Cut Manual Configuration and Workflow Tasks. LogicGate CEO Diego Panama says AI agents can reduce manual GRC configuration and application development, but enterprises will need strong change management, testing and platform reliability as they automate workflows across security, compliance, audit and legal. First seen on govinfosecurity.com Jump to…
-
GRC Teams Scale AI Governance: Insights from the 2026 IT Risk and Compliance Benchmark
Hyperproof’s 2026 IT Risk and Compliance Benchmark Report reveals that while 97% of GRC teams leverage AI for internal productivity, only 27% have operationalized AI for external assurance. To bridge this gap, modern compliance leaders are anchoring programs in frameworks… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/grc-teams-scale-ai-governance-insights-from-the-2026-it-risk-and-compliance-benchmark/
-
PCI DSS 4.0 Deadlines: Lazarus Alliance Risk Management Audits
Organizations across regulated industries face mounting pressure to align with evolving payment security standards. As decision-makers evaluate their compliance strategies in 2026 and beyond, understanding PCI DSS 4.0 deadlines becomes essential for maintaining operational resilience and avoiding costly disruptions. Navigating PCI DSS 4.0 Deadlines in 2026 PCI DSS 4.0 introduces enhanced requirements that emphasize continuous”¦…
-
PCI DSS 4.0 Audits: Continuum GRC Cybersecurity Assessments 2026
PCI DSS 4.0 compliance audits demand a fundamental shift from periodic checkbox exercises to continuous, risk-based cybersecurity assessments. Organizations preparing for 2026 assessments must address new requirements around targeted risk analyses, multi-factor authentication expansion, and automated security monitoring that directly impact how cardholder data environments are protected and validated. Key Takeaways: PCI DSS 4.0 introduces”¦…
-
8 Causes of Enterprise Compliance Software Failure
<div cla Large enterprise compliance programs collapse more often than most governance teams realize. Software that promised automation ends up sitting idle while teams return to spreadsheets. The issue rarely comes down to bad technology. Instead, it comes down to how that technology gets implemented, adopted, and aligned with operational reality. First seen on securityboulevard.com…
-
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.AI has moved…
-
ISO 27001:2022 Transition Audits by Lazarus Alliance Experts
In 2026, decision-makers across regulated industries face mounting pressure to maintain robust information security postures amid evolving threats and compliance demands. Lazarus Alliance stands ready to guide organizations through ISO 27001 transition audits, ensuring seamless alignment with the latest standards while integrating complementary frameworks. The Strategic Importance of ISO 27001 Compliance Organizations in sectors such”¦…
-
HIPAA Risk Assessments 2026: Continuum GRC Healthcare Audits
In 2026, healthcare organizations face increasing pressure to maintain robust data protection measures under evolving regulatory landscapes. HIPAA risk assessments remain a cornerstone of compliance, helping providers identify vulnerabilities and safeguard protected health information. As cyber threats grow more sophisticated, proactive compliance assessments become essential for decision-makers seeking to minimize liability and ensure operational resilience.”¦…
-
How Much Does HITRUST Certification Cost?
HITRUST certification cost is one of the most consistently underestimated line items in HealthTech compliance budgeting, largely because it gets lumped in mentally with a HIPAA risk assessment when the two are very different scopes of work. The post How Much Does HITRUST Certification Cost? appeared first on Packet33. First seen on securityboulevard.com Jump to…
-
What Enterprise Continuous Compliance Software Misses
<div cla Key Takeaways: What Enterprise Continuous Compliance Software Misses Visibility gaps prevent your security team from detecting control failures until audits expose them months later. Weak control mapping disconnects your framework compliance from actual risk exposure, leaving critical gaps unaddressed. Executive reporting fails when dashboards show activity metrics instead of financial impact your board…

