Regulation & Policy
-
Bank tests cloud disruption risk
The Bank of England is using CORST26 and SIMEX to examine how disruption at a major cloud provider could affect financial market infrastructure.
-
ICO complaints duty raises accountability
UK organisations must now have a data protection complaints process, adding a formal accountability layer around data handling, security concerns, and post-incident evidence.
-
Bulgaria faces surveillance export scrutiny
Human Rights Watch says Bulgarian authorities licensed exports of surveillance technology to governments with records of repression, exposing weaknesses in Europe’s cyber-surveillance controls.
-
EU warns digital gaps threaten 2030 targets
The Commission’s 2026 Digital Decade report says Europe has made progress, but structural gaps in infrastructure, skills, public services, and business digitalisation remain.
-
ENISA meeting puts AI access in focus
ENISA’s planned meeting with Anthropic comes as European cyber agencies confront access, assurance, and dependency issues around powerful AI models used in security work.
-
France moves spy analytics away from Palantir
France’s DGSI is moving sensitive analytics work from Palantir to ChapsVision, bringing sovereignty, migration risk, and security-critical procurement into practical focus.
-
FCA brings frontier AI into resilience planning
The FCA has directed firms towards CMORG guidance linking frontier AI capability with cyber security, vulnerability handling, and operational resilience in financial services.
-
Ofcom details the telecoms resilience bar
Ofcom’s updated guidance sets operational expectations for UK communications providers across network design, monitoring, incident handling, third-party operations, and backup power.
-
Europe confronts frontier AI dependency
Anthropic’s model access restrictions have placed frontier AI inside Europe’s debate over cyber capability, export controls, resilience, and digital sovereignty.
-
France sets a deadline for quantum-safe security
ANSSI’s certification shift moves post-quantum cryptography into procurement, supplier assurance, and long-term infrastructure planning for products used in sensitive environments.







