Regulation & Policy
-
Financial resilience rests on shared suppliers
The FCA says 27% of incidents reported by firms in 2025 were tied to third parties, with cyber involved in more than a third of those cases.
-
Cyber sanctions widen across Europe
Eight European partner countries have aligned with EU cyber sanctions targeting individuals and entities linked to attacks against the Union and its partners.
-
Product security gets an SME playbook
ENISA’s secure-by-design and secure-by-default playbook gives smaller manufacturers practical steps for building product security into engineering and release work.
-
Cloud providers enter UK finance resilience regime
UK financial regulators are now directly overseeing the first critical third parties, bringing major cloud providers inside a system-wide operational resilience framework.
-
Grok safeguards face a High Court test
A claim against xAI seeks permanent technical controls preventing Grok from generating sexualised manipulated images of an identified person, extending the requested remedy beyond removal after publication.
-
EV charging enters Germany’s cyber security programme
Germany’s BSI is developing requirements for connected charging infrastructure, where backend services, remote maintenance, payments, and grid integration turn product weaknesses into operational risk.
-
Spyware claim clears UK immunity hurdle
A divided Supreme Court has ruled that foreign-state hacking of a computer in Britain can constitute an act in the UK, allowing a civil spyware claim against Bahrain to proceed.
-
September reporting deadline comes into focus under CRA guidance
European Commission guidance clarifies product scope, support periods, open source treatment, risk assessments, and reporting duties before the Cyber Resilience Act’s first operational deadline.
-
UK cyber brief survives Whitehall restructure
Baroness Liz Lloyd has received joint appointments across two reorganised departments, preserving ministerial continuity as the UK expands cyber regulation and infrastructure oversight.
-
TeamViewer disclosure delay draws €240,000 fine
Germany’s financial regulator has fined TeamViewer after finding that its 2024 cyberattack should have been disclosed to the market without delay.










