Compliance & Regulations

Security awareness tips, industry news, and product updates.

Software engineer reviewing code on screen ahead of the EU Cyber Resilience Act reporting deadline
Compliance & RegulationsThreat Intelligence

CRA Vulnerability Reporting: 8 Days to September 11

In eight days, the EU Cyber Resilience Act reaches its first hard deadline: manufacturers of products with digital elements must report actively exploited vulnerabilities within 24 hours of awareness. The reporting platform is ready. The question is whether your people are.

Daniel Okafor·9/3/2026·5 min read
Security awareness team planning an October campaign calendar on a whiteboard in September
Security Awareness TipsCompliance & Regulations

Cybersecurity Awareness Month 2026: Your September Prep

October's Cybersecurity Awareness Month is won or lost in September. A practical four-week preparation plan covering goals, a baseline phishing simulation, the content calendar, executive sponsorship and how you will measure success.

Sarah Mitchell·9/2/2026·5 min read
Hospital staff working at computer workstations subject to HIPAA Security Rule requirements
Security Awareness TipsCompliance & Regulations

HIPAA Security Rule Update Slips to 2027: Now What?

HHS has pushed final action on the proposed HIPAA Security Rule overhaul to July 2027, and more than 100 hospital systems want it withdrawn entirely. But the current rule remains actively enforced, including its security awareness training requirement. Relaxing now is the wrong lesson.

Natalie Hoffmann·9/1/2026·5 min read
Engineer working in a defense manufacturing facility preparing for CMMC Level 2 assessment
Compliance & RegulationsFor MSPs & Partners

CMMC Phase 2 Countdown: Level 2 Audits From November

On November 10, 2026, CMMC Phase 2 begins: DoD contracts involving CUI can require third-party Level 2 certification instead of self-assessment. With roughly 80,000 companies needing certification and only about 80 authorized assessors, the countdown is very real.

Elena Vasquez·8/30/2026·5 min read
The Houses of Parliament in Westminster, where the UK Cyber Security and Resilience Bill is being debated
Compliance & RegulationsFor MSPs & Partners

UK Cyber Resilience Bill Puts MSPs Under Regulation

For the first time, UK managed service providers face statutory security duties and a two-stage incident reporting regime. The Cyber Security and Resilience Bill has cleared the Commons and is progressing through the Lords. Here is what MSPs should be doing now.

Lisa Brennan·8/28/2026·6 min read
European financial district skyline representing the EU financial sector reporting ICT incidents under DORA
Compliance & RegulationsThreat Intelligence

DORA Year One: What 3,383 Major ICT Incidents Reveal

The European Supervisory Authorities have published the first annual report on major ICT incidents under DORA: 3,383 reports in 2025, most from the credit and payments sectors. Here is what the numbers show, and why the 4-hour reporting clock depends on people as much as process.

Marcus Chen·8/26/2026·6 min read
New York financial district offices representing NYDFS-regulated entities subject to Part 500 training requirements
Phishing & Social EngineeringCompliance & Regulations

NYDFS Vishing Advisory: Part 500 Training Expectations

NYDFS has told regulated financial entities, in writing, to train staff against help-desk vishing attacks. Combined with the fully effective Part 500 amendment and a record enforcement run, targeted social-engineering training is now a supervisory expectation in New York.

Rachel Andersen·8/24/2026·5 min read
Executives in a boardroom discussing the management cybersecurity training duty under Section 38 BSIG
Security Awareness TipsCompliance & Regulations

Section 38 BSIG: German Managers Must Train on Cyber Risk

Germany's new BSIG makes cybersecurity training a personal, non-delegable duty for the management of regulated entities, backed by personal liability for oversight failures. The BSI has now spelled out what the training must cover and recommends an annual cadence.

Thomas Eriksson·8/22/2026·5 min read
Employees in a workplace training session building the AI literacy skills required by the EU AI Act
Security Awareness TipsCompliance & Regulations

EU AI Literacy Duty: Enforcement Arrives in August 2026

Every other EU AI Act headline in 2026 has been about delay, but the Article 4 AI-literacy duty was never postponed. It has applied since February 2025, and from early August 2026 national authorities gain the powers to enforce it. Here is how to build a defensible program.

Sarah Mitchell·8/20/2026·6 min read
German office building representing NIS2-regulated entities facing the BSI enforcement phase
Compliance & RegulationsFor MSPs & Partners

Germany NIS2: Grace Deadline Expired, Enforcement Begins

The BSI's final grace deadline for NIS2 registration expired on 31 July 2026 with thousands of in-scope German entities still unregistered. Germany's NIS2 regime now enters its enforcement phase, and registration failures alone can draw fines of up to EUR 500,000.

David Kowalski·8/16/2026·5 min read
A manager configuring access permissions for team members on a laptop
Compliance & RegulationsProduct Updates

Custom Roles and Granular Permissions in empowsec Explained

empowsec lets company admins build custom roles with granular permissions, renders a dashboard with only the tabs each user may see, and gives reseller teams an equivalent permission system - so nobody needs full admin access just to do one job.

David Kowalski·8/15/2026·7 min read
« Previous123Next »