PCI DSS Requirement 12.6 Evidence Gaps Grow

Bright Defense graphic on growing PCI DSS Requirement 12.6 evidence gaps.

PCI SSC’s statement that awareness training may help satisfy PCI DSS Requirement 12.6 has put employee education back into focus for merchants and service providers preparing PCI DSS v4.0.1 assessments. The issue is no longer whether staff receive a generic annual module. Assessors now look for a formal, updated, documented security awareness program tied to…

Read More

New NYDFS  Rules Tighten Compliance For Financial Firms

Bright Defense graphic on new NYDFS rules tightening compliance for financial firms.

NYDFS has moved its cybersecurity regulation into a tougher compliance and enforcement phase, with final Second Amendment duties now active and recent settlements showing that weak incident reporting, access controls, vendor oversight, and data retention can trigger penalties. The latest official update came on May 21, 2026, when NYDFS issued threat-environment guidance for regulated entities.What…

Read More

AI Governance Gains Ground With ISO 42001

Bright Defense graphic on ISO 42001 driving the shift to formal AI governance.

Organizations are moving from informal AI policies to formal Artificial Intelligence Management Systems as ISO/IEC 42001 turns AI governance into an auditable business process. The shift accelerated after ISO published ISO/IEC 42001:2023 in December 2023, the EU AI Act entered force in 2024, and major AI and cloud vendors began publishing third-party certifications for AI…

Read More

EU Cyber Resilience Act Starts 2026 Reporting Countdown

Bright Defense graphic on the EU Cyber Resilience Act starting the 2026 vulnerability-reporting countdown.

The EU Cyber Resilience Act will force manufacturers of software and connected products to report actively exploited vulnerabilities and severe product security incidents from September 11, 2026, creating the first binding EU-wide cyber reporting duty for digital products before the broader product security rules apply on December 11, 2027. The latest official Commission update, posted…

Read More

ISO 42001 Moves From AI Standard To Vendor Requirement

Bright Defense graphic explaining ISO 42001’s shift from an AI standard to a vendor requirement.

ISO/IEC 42001 is becoming a practical vendor requirement for AI companies as enterprise buyers, cloud customers and regulated clients ask for third-party proof that AI systems are governed, monitored and documented. The standard remains voluntary, but public certifications from AWS, Anthropic, OpenAI, Snowflake, Salesforce and ServiceNow show how fast it has moved into procurement, trust-center…

Read More

ISO/IEC 27001 Programs Expand To Cover AI Governance With ISO/IEC 42001

Bright Defense graphic on ISO 27001 programs expanding into AI governance through ISO 42001, with ISO standard badges.

Organizations are extending ISO/IEC 27001 security programs to cover AI governance through ISO/IEC 42001, as AI systems create new risks that information security controls alone do not fully address. The move gives security, legal, risk and compliance teams a familiar management-system structure for AI inventories, model oversight, supplier controls, documentation and audit evidence.Why Are Organizations…

Read More

CIS v8.1 Updates For NIST CSF 2.0 And Cloud Security

Bright Defense graphic on CIS Controls v8.1 updates for NIST CSF 2.0 and cloud security, with a CIS Controls badge.

The Center for Internet Security’s CIS Controls v8.1 update turned a widely used cybersecurity baseline into a closer fit for NIST’s Cybersecurity Framework 2.0 and modern cloud environments, giving security teams a clearer route from board-level governance to technical safeguards. CIS released the update in June 2024, then followed with a NIST CSF 2.0 mapping…

Read More

ISO 27001:2022 Deadline Puts Legacy Certificates At Risk

Bright Defense graphic warning that the ISO 27001:2022 transition deadline puts legacy certificates at risk.

The ISO 27001:2022 transition deadline has left organizations with old ISO 27001:2013 certificates exposed to certificate withdrawal, lost assurance claims, and customer contract risk after the global transition period closed on October 31, 2025. The latest confirmed post-deadline accreditation development came on January 1, 2026, when Global Accreditation Cooperation Incorporated began operations and took over…

Read More

NIS2 Addresses EU Compliance Gaps

Bright Defense graphic on NIS2 addressing European Union compliance gaps.

The European Commission’s proposed NIS2 amendments would revise the EU’s flagship cybersecurity directive before many member states have fully settled their national rules, seeking to clarify scope, ransomware reporting, cross-border supervision, and the role of ENISA. The proposal, published on January 20, 2026, remains subject to approval by the European Parliament and the Council of…

Read More