news
PCI DSS Requirement 12.6 Evidence Gaps Grow
PCI SSC’s statement that awareness training may help satisfy PCI DSS Requirement 12.6 has put employee education back into focus for merchants and service providers preparing PCI DSS v4.0.1 assessments. The issue is no longer whether staff receive a generic annual module. Assessors now look for a formal, updated, documented security awareness program tied to…
Read MoreNew NYDFS Rules Tighten Compliance For Financial Firms
NYDFS has moved its cybersecurity regulation into a tougher compliance and enforcement phase, with final Second Amendment duties now active and recent settlements showing that weak incident reporting, access controls, vendor oversight, and data retention can trigger penalties. The latest official update came on May 21, 2026, when NYDFS issued threat-environment guidance for regulated entities.What…
Read MoreAI Governance Gains Ground With ISO 42001
Organizations are moving from informal AI policies to formal Artificial Intelligence Management Systems as ISO/IEC 42001 turns AI governance into an auditable business process. The shift accelerated after ISO published ISO/IEC 42001:2023 in December 2023, the EU AI Act entered force in 2024, and major AI and cloud vendors began publishing third-party certifications for AI…
Read MoreEU Cyber Resilience Act Starts 2026 Reporting Countdown
The EU Cyber Resilience Act will force manufacturers of software and connected products to report actively exploited vulnerabilities and severe product security incidents from September 11, 2026, creating the first binding EU-wide cyber reporting duty for digital products before the broader product security rules apply on December 11, 2027. The latest official Commission update, posted…
Read MoreISO 42001 Moves From AI Standard To Vendor Requirement
ISO/IEC 42001 is becoming a practical vendor requirement for AI companies as enterprise buyers, cloud customers and regulated clients ask for third-party proof that AI systems are governed, monitored and documented. The standard remains voluntary, but public certifications from AWS, Anthropic, OpenAI, Snowflake, Salesforce and ServiceNow show how fast it has moved into procurement, trust-center…
Read MoreISO/IEC 27001 Programs Expand To Cover AI Governance With ISO/IEC 42001
Organizations are extending ISO/IEC 27001 security programs to cover AI governance through ISO/IEC 42001, as AI systems create new risks that information security controls alone do not fully address. The move gives security, legal, risk and compliance teams a familiar management-system structure for AI inventories, model oversight, supplier controls, documentation and audit evidence.Why Are Organizations…
Read MoreCIS v8.1 Updates For NIST CSF 2.0 And Cloud Security
The Center for Internet Security’s CIS Controls v8.1 update turned a widely used cybersecurity baseline into a closer fit for NIST’s Cybersecurity Framework 2.0 and modern cloud environments, giving security teams a clearer route from board-level governance to technical safeguards. CIS released the update in June 2024, then followed with a NIST CSF 2.0 mapping…
Read MoreISO 27001:2022 Deadline Puts Legacy Certificates At Risk
The ISO 27001:2022 transition deadline has left organizations with old ISO 27001:2013 certificates exposed to certificate withdrawal, lost assurance claims, and customer contract risk after the global transition period closed on October 31, 2025. The latest confirmed post-deadline accreditation development came on January 1, 2026, when Global Accreditation Cooperation Incorporated began operations and took over…
Read MoreNIS2 Addresses EU Compliance Gaps
The European Commission’s proposed NIS2 amendments would revise the EU’s flagship cybersecurity directive before many member states have fully settled their national rules, seeking to clarify scope, ransomware reporting, cross-border supervision, and the role of ENISA. The proposal, published on January 20, 2026, remains subject to approval by the European Parliament and the Council of…
Read MoreSOC 2 Audit Quality Faces New Pressure As Vendor Risk Grows
SOC 2 audit quality is facing sharper scrutiny as companies rely more heavily on vendor reports to judge cybersecurity risk, while AICPA-linked guidance warns that fast, automated, and poorly scoped examinations can weaken trust in the control reports buyers use for due diligence. The latest confirmed update came in May 2026, when the AICPA Peer…
Read More