Compliance & Regulations

Security awareness tips, industry news, and product updates.

New York financial district offices representing NYDFS-regulated entities subject to Part 500 training requirements
Phishing & Social EngineeringCompliance & Regulations

NYDFS Vishing Advisory: Part 500 Training Expectations

NYDFS has told regulated financial entities, in writing, to train staff against help-desk vishing attacks. Combined with the fully effective Part 500 amendment and a record enforcement run, targeted social-engineering training is now a supervisory expectation in New York.

Rachel Andersen·8/24/2026·5 min read
Executives in a boardroom discussing the management cybersecurity training duty under Section 38 BSIG
Security Awareness TipsCompliance & Regulations

Section 38 BSIG: German Managers Must Train on Cyber Risk

Germany's new BSIG makes cybersecurity training a personal, non-delegable duty for the management of regulated entities, backed by personal liability for oversight failures. The BSI has now spelled out what the training must cover and recommends an annual cadence.

Thomas Eriksson·8/22/2026·5 min read
Employees in a workplace training session building the AI literacy skills required by the EU AI Act
Security Awareness TipsCompliance & Regulations

EU AI Literacy Duty: Enforcement Arrives in August 2026

Every other EU AI Act headline in 2026 has been about delay, but the Article 4 AI-literacy duty was never postponed. It has applied since February 2025, and from early August 2026 national authorities gain the powers to enforce it. Here is how to build a defensible program.

Sarah Mitchell·8/20/2026·6 min read
German office building representing NIS2-regulated entities facing the BSI enforcement phase
Compliance & RegulationsFor MSPs & Partners

Germany NIS2: Grace Deadline Expired, Enforcement Begins

The BSI's final grace deadline for NIS2 registration expired on 31 July 2026 with thousands of in-scope German entities still unregistered. Germany's NIS2 regime now enters its enforcement phase, and registration failures alone can draw fines of up to EUR 500,000.

David Kowalski·8/16/2026·5 min read
A manager configuring access permissions for team members on a laptop
Compliance & RegulationsProduct Updates

Custom Roles and Granular Permissions in empowsec Explained

empowsec lets company admins build custom roles with granular permissions, renders a dashboard with only the tabs each user may see, and gives reseller teams an equivalent permission system - so nobody needs full admin access just to do one job.

David Kowalski·8/15/2026·7 min read
HR and IT team reviewing an automated training enrollment plan
Compliance & RegulationsProduct Updates

Automated Recurring Training Enrollment for Compliance

Compliance frameworks expect regular, evidenced security training - but manual re-enrollment does not scale. empowsec automation rules enroll new hires automatically and re-run courses every 3, 6, 12 or 24 months, hands-off.

Rachel Andersen·8/14/2026·5 min read
Professional reviewing artificial intelligence transparency requirements on a screen in a European office
Compliance & RegulationsThreat Intelligence

EU AI Act August 2026: What Changed and What Was Delayed

The Digital Omnibus postponed the AI Act's high-risk regime, but the Article 50 transparency duties applied on schedule from 2 August 2026. Chatbot disclosure, deepfake labeling, and emotion-recognition notices are now enforceable, and security teams have work to do.

Elena Vasquez·8/11/2026·6 min read
Reviewing audit logs and compliance records
Compliance & RegulationsProduct Updates

empowsec Audit Logs, Impersonation, and GDPR Deletion

empowsec maintains comprehensive audit logs, records every impersonation session, and provides a compliant account deletion workflow - giving organizations the accountability, traceability, and GDPR evidence they need.

Natalie Hoffmann·8/4/2026·8 min read
Configuring single sign-on for empowsec
Compliance & RegulationsProduct Updates

Single Sign-On for empowsec: SAML, OIDC, and OAuth Explained

empowsec supports single sign-on via SAML 2.0, OIDC, and OAuth, with per-domain configuration, attribute mapping, auto-provisioning on first login, and cross-domain authentication for white-label deployments - centralizing access and reducing password risk.

David Kowalski·7/15/2026·9 min read
Financial services professionals reviewing digital operational resilience requirements in a meeting
Compliance & Regulations

DORA: Security Awareness and Training Requirements

DORA is best known for ICT risk and incident reporting, but it also makes security awareness training a compulsory module for staff and management. Here is what financial entities must do, and how to evidence it.

Sarah Mitchell·7/8/2026·6 min read
« Previous12Next »