News

Security awareness tips, industry news, and product updates.

Software engineer reviewing code on screen ahead of the EU Cyber Resilience Act reporting deadline
Compliance & RegulationsThreat Intelligence

CRA Vulnerability Reporting: 8 Days to September 11

In eight days, the EU Cyber Resilience Act reaches its first hard deadline: manufacturers of products with digital elements must report actively exploited vulnerabilities within 24 hours of awareness. The reporting platform is ready. The question is whether your people are.

Daniel Okafor·9/3/2026·5 min read
Security awareness team planning an October campaign calendar on a whiteboard in September
Security Awareness TipsCompliance & Regulations

Cybersecurity Awareness Month 2026: Your September Prep

October's Cybersecurity Awareness Month is won or lost in September. A practical four-week preparation plan covering goals, a baseline phishing simulation, the content calendar, executive sponsorship and how you will measure success.

Sarah Mitchell·9/2/2026·5 min read
Hospital staff working at computer workstations subject to HIPAA Security Rule requirements
Security Awareness TipsCompliance & Regulations

HIPAA Security Rule Update Slips to 2027: Now What?

HHS has pushed final action on the proposed HIPAA Security Rule overhaul to July 2027, and more than 100 hospital systems want it withdrawn entirely. But the current rule remains actively enforced, including its security awareness training requirement. Relaxing now is the wrong lesson.

Natalie Hoffmann·9/1/2026·5 min read
Group of new employees arriving at the office together at the start of September
Phishing & Social EngineeringSecurity Awareness Tips

New Hires, September Starts: The 90-Day Phishing Window

September brings the year's biggest wave of new starters - and attackers time their CEO impersonation campaigns to match. Why the first 90 days are the most phishable window of any tenure, and how to protect the whole incoming cohort.

Daniel Okafor·8/31/2026·5 min read
Developer reading API documentation on a screen
For MSPs & PartnersProduct Updates

Inside the empowsec Developer Docs: Your API Launchpad

The empowsec developer documentation portal at /docs walks Reseller and Company API integrations from first key to production - with guides, endpoint references, webhook docs, error codes, and a changelog.

Marcus Chen·8/30/2026·7 min read
Engineer working in a defense manufacturing facility preparing for CMMC Level 2 assessment
Compliance & RegulationsFor MSPs & Partners

CMMC Phase 2 Countdown: Level 2 Audits From November

On November 10, 2026, CMMC Phase 2 begins: DoD contracts involving CUI can require third-party Level 2 certification instead of self-assessment. With roughly 80,000 companies needing certification and only about 80 authorized assessors, the countdown is very real.

Elena Vasquez·8/30/2026·5 min read
Finance and security leaders reviewing budget charts during an annual planning meeting
Security Awareness TipsFor MSPs & Partners

Security Budgets 2027: Making the Case for Human Risk

Security budget growth has slowed to a five-year low, and every line item now needs hard numbers behind it. Here is the ROI evidence CISOs and MSPs can use to defend - and grow - the human risk budget this planning season.

James Thornton·8/29/2026·5 min read
The Houses of Parliament in Westminster, where the UK Cyber Security and Resilience Bill is being debated
Compliance & RegulationsFor MSPs & Partners

UK Cyber Resilience Bill Puts MSPs Under Regulation

For the first time, UK managed service providers face statutory security duties and a two-stage incident reporting regime. The Cyber Security and Resilience Bill has cleared the Commons and is progressing through the Lords. Here is what MSPs should be doing now.

Lisa Brennan·8/28/2026·6 min read
Small business owner working confidently at a computer in a modern office
Security Awareness TipsFor MSPs & Partners

SMB Cyber Readiness 2026: The Dangerous Confidence Gap

New global research shows 45% of SMBs suffered a cyber-incident in the past year, yet 75% feel confident in their resilience - and confidence actually rises among repeat victims. What the confidence paradox means for MSPs selling security awareness.

Thomas Eriksson·8/27/2026·6 min read
European financial district skyline representing the EU financial sector reporting ICT incidents under DORA
Compliance & RegulationsThreat Intelligence

DORA Year One: What 3,383 Major ICT Incidents Reveal

The European Supervisory Authorities have published the first annual report on major ICT incidents under DORA: 3,383 reports in 2025, most from the credit and payments sectors. Here is what the numbers show, and why the 4-hour reporting clock depends on people as much as process.

Marcus Chen·8/26/2026·6 min read
University students walking across campus with laptops and backpacks at the start of the semester
Phishing & Social EngineeringThreat Intelligence

Back-to-School Phishing Wave Hits the Education Sector

Every back-to-school season brings a surge of phishing aimed at schools, universities and students - and the lures land in corporate inboxes too. What the latest data shows and how to prepare your workforce before the wave peaks.

Lisa Brennan·8/25/2026·6 min read