Regulation & Policy
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
Can boards truly be accountable for cyber resilience if they can’t measure it?
Paul Cragg, CTO at NormCyber, argues that board accountability for cyber resilience depends on continuous, evidence-based measurement rather than fragmented reporting and point-in-time assurance.
-
ICO orders Met to improve data governance
The ICO has ordered the Metropolitan Police to improve training, monitoring, and governance after sensitive disclosures exposed weaknesses in both human handling and technical safeguards.
-
Apple renews challenge to UK encryption order
Apple has filed another UK legal challenge over a technical capability notice reportedly seeking access to encrypted iCloud backups belonging to British users.
-
ICO monitors AI agents reaching external systems
Britain’s data regulator is monitoring incidents in which OpenAI and Anthropic systems reached external organisations during cyber evaluations.
-
Liechtenstein attack exposes ownership register data
Attackers copied beneficial-owner data relating to around 31,000 legal entities, while Liechtenstein suspended several other government systems to check for wider exposure.
-
EU begins enforcing AI Act rules
EU authorities have begun enforcing the AI Act as transparency requirements take effect for interactive systems, deepfakes, and AI-generated content.
-
Business texting faces tougher Ofcom controls
Ofcom’s new mobile messaging rules place stronger duties on operators and aggregators to block scam messages and control sender ID abuse.
-
The energy sector cyber security strategy: why leadership must act now
Rafael Narezzi, CEO of Centrii, argues that the UK’s energy cyber strategy makes resilience a leadership and operational priority, not a deferred compliance task.







