Regulation & Policy
-
Europe sets assurance baseline for cyber providers
ENISA’s proposed certification scheme would establish common assurance requirements for managed security services, beginning with incident response and providers supporting the EU Cybersecurity Reserve.
-
Genetic data failures cost 23andMe €2.4m
Spain’s privacy regulator found that optional authentication, unrestricted data access, and delayed notification failed to protect highly sensitive genetic information.
-
Quantum migration moves into the boardroom
The NCSC says post-quantum cryptography migration needs executive sponsorship, supplier readiness, asset knowledge, and long-range resilience planning.
-
Germany builds a federal cyber control layer
CyberGovSecure will centralise cyber governance across Germany’s federal administration, with workstreams covering configuration, vulnerability management, logging, detection, and mobile device control.
-
Hospitals get new EU cyber buying guide
ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.
-
Gold Eagle seeks faster vulnerability response
The White House has launched an AI-supported vulnerability clearinghouse intended to coordinate exploit detection and remediation across federal agencies, critical infrastructure, industry, and open-source partners.
-
Ofcom moves messaging controls upstream
New Ofcom rules require mobile operators and messaging aggregators to strengthen sender verification, traffic monitoring, message blocking, and incident management across the business-messaging supply chain.
-
TikTok age controls face Ofcom investigation
Ofcom has opened an Online Safety Act investigation into whether TikTok’s age-assurance controls are sufficiently effective at identifying children and limiting their exposure to harmful content.
-
Europe’s critical entity regime enters operation
EU governments have reached the deadline for identifying organisations subject to the Critical Entities Resilience Directive, moving the regime from national preparation into supervision and operational delivery.
-
WINDTRE faces €1.7m penalty after retail breaches
Italy’s privacy regulator has fined WINDTRE after attackers exploited retail support processes and weak credential and certificate controls to access data belonging to more than 365,000 customers.







