Regulation & Policy
-
Germany builds a federal cyber control layer
CyberGovSecure will centralise cyber governance across Germany’s federal administration, with workstreams covering configuration, vulnerability management, logging, detection, and mobile device control.
-
Hospitals get new EU cyber buying guide
ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.
-
Gold Eagle seeks faster vulnerability response
The White House has launched an AI-supported vulnerability clearinghouse intended to coordinate exploit detection and remediation across federal agencies, critical infrastructure, industry, and open-source partners.
-
Ofcom moves messaging controls upstream
New Ofcom rules require mobile operators and messaging aggregators to strengthen sender verification, traffic monitoring, message blocking, and incident management across the business-messaging supply chain.
-
TikTok age controls face Ofcom investigation
Ofcom has opened an Online Safety Act investigation into whether TikTok’s age-assurance controls are sufficiently effective at identifying children and limiting their exposure to harmful content.
-
Europe’s critical entity regime enters operation
EU governments have reached the deadline for identifying organisations subject to the Critical Entities Resilience Directive, moving the regime from national preparation into supervision and operational delivery.
-
WINDTRE faces €1.7m penalty after retail breaches
Italy’s privacy regulator has fined WINDTRE after attackers exploited retail support processes and weak credential and certificate controls to access data belonging to more than 365,000 customers.
-
US indicts alleged bulletproof hosting operators
US prosecutors have unsealed charges against three Russian nationals and two companies accused of providing infrastructure used in cybercrime affecting international victims.
-
UK expands public-sector vulnerability monitoring
UK Government Security says its Vulnerability Monitoring Service now covers more than 6,000 public-sector organisations and has expanded active scanning.
-
UK adds cyber risks to national register
The UK has added cyber attacks on data, water, and police infrastructure to the National Risk Register, alongside digital resilience failure after CrowdStrike.





