<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Regulatory and Compliance</title><link>https://cybersecuritytracker.ai/?cats=regulatory</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>CISOs vs. Boards: Myth or Misunderstanding?</title><link>https://darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-</link><guid isPermaLink="false">cst-3196</guid><description>Boards are increasing focus on security due to rising threats, yet communication gaps remain between board members and chief information security officers (CISOs). Both groups report needing additional resources and better dialogue to close the divide.</description><pubDate>Fri, 24 Jul 2026 21:31:53 GMT</pubDate></item><item><title>Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks</title><link>https://cyberscoop.com/cisa-circia-cyber-incident-reporting-rule-feedback</link><guid isPermaLink="false">cst-3198</guid><description>Industry groups told CISA during town halls on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that they want the rule to cover fewer companies, require fewer incident reports, and demand less detailed information when reporting does occur. The rule, which Congress designed to require critical infrastructure owners to report major cyberattacks within 72 hours and ransomware payments within 24 hours, has missed multiple finalization deadlines, with CISA now targeting September for completion. Industry representatives expressed concerns about the scope affecting over 300,000 entities, the burden of reporting minor intrusion attempts, and the sensitivity of sharing security measure details.</description><pubDate>Fri, 24 Jul 2026 20:58:35 GMT</pubDate></item><item><title>US accuses American of allegedly wiping his phone using a ‘duress’ password during border search</title><link>https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search</link><guid isPermaLink="false">cst-3194</guid><description>A U.S. citizen is challenging a government claim in court that he provided border authorities with a passcode that erased his phone's data. The case raises constitutional questions about privacy protections and what individuals must disclose during border searches.</description><pubDate>Fri, 24 Jul 2026 17:53:30 GMT</pubDate></item><item><title>The SOCI Act, explained: obligations, recent reforms, and where preemptive cyber defense fits</title><link>https://silentpush.com/blog/the-soci-act-obligations</link><guid isPermaLink="false">cst-3176</guid><description>Australia's Security of Critical Infrastructure Act 2018 (SOCI Act) imposes cyber risk management, incident reporting, and asset registration requirements on organizations operating in eleven critical sectors including energy, finance, healthcare, and transport. The framework has evolved significantly over the past two years, with additional changes currently under consultation, and increasingly emphasizes proactive threat visibility and defense rather than reactive incident response.</description><pubDate>Fri, 24 Jul 2026 12:49:17 GMT</pubDate></item><item><title>FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires</title><link>https://bleepingcomputer.com/news/security/fedramp-rev5-is-ending-what-the-20x-transition-really-requires</link><guid isPermaLink="false">cst-3101</guid><description>FedRAMP 20X replaces the current Rev5 model by shifting from periodic security assessments to continuous, machine-readable evidence that validates control effectiveness. Organizations must transition to this evidence-based assurance approach to maintain compliance with the updated federal security framework.</description><pubDate>Thu, 23 Jul 2026 14:00:10 GMT</pubDate></item><item><title>EU fines Google $1 billion for search, app store antitrust violations</title><link>https://bleepingcomputer.com/news/google/eu-fines-google-1-billion-for-digital-markets-act-breaches-in-search-and-play-store</link><guid isPermaLink="false">cst-3083</guid><description>The European Commission issued a €890 million fine to Google for violating the Digital Markets Act, which regulates fair competition in digital markets. The penalty addresses breaches related to the company's search and app store practices.</description><pubDate>Thu, 23 Jul 2026 12:33:19 GMT</pubDate></item><item><title>EU Financial Institutions Leak Data Through Cookie Trackers</title><link>https://darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers</link><guid isPermaLink="false">cst-3004</guid><description>European banks inadvertently sent customer data to ad platforms through tracking pixels embedded in their websites, creating unintended data flows to third parties. The incident raises compliance and privacy concerns under European data protection regulations. Security practitioners face potential exposure across multiple financial institutions sharing similar web infrastructure patterns.</description><pubDate>Wed, 22 Jul 2026 11:30:00 GMT</pubDate></item><item><title>Microsoft to stop Exchange 2016 / 2019 security updates in October</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-esu-program-ends-in-october</link><guid isPermaLink="false">cst-2999</guid><description>Microsoft will conclude its Extended Security Update program for Exchange 2016 and 2019 in October, ending security patch availability for those versions. Organizations using these legacy systems will need to plan migrations or accept the operational risk of running unsupported software.</description><pubDate>Wed, 22 Jul 2026 10:44:52 GMT</pubDate></item><item><title>The Future of Age Verification: Your Face Never Leaves Your Device</title><link>https://bleepingcomputer.com/news/security/the-future-of-age-verification-your-face-never-leaves-your-device</link><guid isPermaLink="false">cst-2792</guid><description>Age verification laws are driving demand for privacy-preserving alternatives to traditional biometric collection. On-device age estimation processes facial data locally without transmitting or storing images, allowing organizations to meet regulatory mandates while minimizing biometric privacy exposure.</description><pubDate>Sat, 18 Jul 2026 13:15:24 GMT</pubDate></item><item><title>NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data</title><link>https://databreaches.net/2026/07/18/ny-attorney-general-james-secures-18-million-from-23andme-for-failing-to-protect-customers-genetic-data?pk_campaign=feed&amp;pk_kwd=ny-attorney-general-james-secures-18-million-from-23andme-for-failing-to-protect-customers-genetic-data</link><guid isPermaLink="false">cst-2793</guid><description>New York Attorney General Letitia James and a coalition of 42 state attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' genetic data. The enforcement action stems from inadequate security practices that exposed sensitive information. California's Attorney General has also initiated separate litigation against the company under state privacy laws.</description><pubDate>Sat, 18 Jul 2026 12:13:13 GMT</pubDate></item><item><title>Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday</title><link>https://securityweek.com/industry-reactions-to-pentagon-suspending-cmmc-phase-2-feedback-friday</link><guid isPermaLink="false">cst-2759</guid><description>The Department of Defense suspended the Cybersecurity Maturity Model Certification (CMMC) Phase 2 program, which paused third-party audits of defense contractors. Industry stakeholders acknowledged that while the audit moratorium is in effect, the legal requirement to protect controlled unclassified information (CUI) remains in force.</description><pubDate>Fri, 17 Jul 2026 11:08:04 GMT</pubDate></item><item><title>Windows Server 2022 reach end of mainstream support in 90 days</title><link>https://bleepingcomputer.com/news/microsoft/windows-server-2022-reach-end-of-mainstream-support-in-90-days</link><guid isPermaLink="false">cst-2743</guid><description>Windows Server 2022 enters the final 90 days of mainstream support and will transition to extended support in October 2026, continuing to receive security updates through 2031. Microsoft's support model ensures organizations have a multi-year window to plan upgrades or transitions to newer server versions.</description><pubDate>Fri, 17 Jul 2026 09:10:15 GMT</pubDate></item><item><title>UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms</title><link>https://therecord.media/ofcom-investigation-tiktok-age-verification</link><guid isPermaLink="false">cst-2697</guid><description>Ofcom, the UK's communications regulator, is investigating TikTok for potentially inadequate age-verification measures that may have exposed children to harmful content. The regulator emphasized that age checks are fundamental to compliance with UK online safety requirements and indicated that many services lack sufficient verification systems.</description><pubDate>Thu, 16 Jul 2026 16:15:00 GMT</pubDate></item><item><title>Windows 11 24H2 Home and Pro reach end of support in 90 days</title><link>https://bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-90-days</link><guid isPermaLink="false">cst-2668</guid><description>Microsoft announced that Windows 10 Enterprise LTSB 2016 and Windows 11 24H2 Home and Pro editions will reach end of support on May 13, 2025, concluding the 18-month support window for the 24H2 version. Organizations and individuals using these editions must plan upgrades or transitions to supported versions before updates cease.</description><pubDate>Thu, 16 Jul 2026 11:59:24 GMT</pubDate></item><item><title>Reading between the lines of a cyber insurance policy</title><link>https://helpnetsecurity.com/2026/07/16/cyber-insurance-coverage-gap</link><guid isPermaLink="false">cst-2646</guid><description>The global cyber insurance market reached approximately $16 billion in premiums in 2024, with coverage now widespread across regulated industries, though payouts have become less predictable. The Global Federation of Insurance Associations identified a significant protection gap of roughly $900 billion, indicating a substantial mismatch between actual cyber exposures and available coverage.</description><pubDate>Thu, 16 Jul 2026 06:00:55 GMT</pubDate></item><item><title>23andMe reaches $18 million settlement with states for massive breach</title><link>https://therecord.media/genetic-testing-settlement-data-breach</link><guid isPermaLink="false">cst-2620</guid><description>Forty-two state attorneys general negotiated an $18 million settlement with 23andMe following a data breach caused by inadequate cybersecurity measures. The settlement addresses regulatory enforcement action against the genetic testing company for its security practices.</description><pubDate>Wed, 15 Jul 2026 17:45:00 GMT</pubDate></item><item><title>Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits</title><link>https://darkreading.com/cyber-risk/nigeria-cybersecurity-efforts-cybercriminals-profits</link><guid isPermaLink="false">cst-2556</guid><description>Nigeria enacted new cybersecurity regulations requiring organizations to disclose cyberattacks, aligning with global trends toward mandatory breach notification. The policy aims to increase transparency and awareness of security incidents across the country's business and government sectors.</description><pubDate>Wed, 15 Jul 2026 08:00:00 GMT</pubDate></item><item><title>Manage Vendor Risk in a Few Practical Steps</title><link>https://darkreading.com/cyber-risk/manage-vendor-risk-in-a-few-practical-steps</link><guid isPermaLink="false">cst-2520</guid><description>A brief piece outlines that managing vendor risk requires understanding risk tolerance, gaining visibility into exposures, and obtaining board-level oversight through disciplined governance approaches.</description><pubDate>Tue, 14 Jul 2026 17:44:55 GMT</pubDate></item><item><title>Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules</title><link>https://securityweek.com/pentagon-suspends-cmmc-phase-2-as-it-rethinks-contractor-cybersecurity-rules</link><guid isPermaLink="false">cst-2456</guid><description>The Pentagon has suspended the second phase of the Cybersecurity Maturity Model Certification (CMMC) program and established a task force to conduct a comprehensive review of contractor cybersecurity requirements. The decision indicates the defense department is reconsidering its approach to the certification framework.</description><pubDate>Tue, 14 Jul 2026 06:37:50 GMT</pubDate></item><item><title>EU leaders eye social media ban for children under age 13</title><link>https://therecord.media/eu-proposed-social-media-ban-kids-under-13</link><guid isPermaLink="false">cst-2446</guid><description>European Commission President Ursula von der Leyen indicates that EU leaders are moving toward establishing a minimum age requirement for social media access, potentially around 13 years old, though final decisions remain with parents and member states. The statement reflects growing consensus among European policymakers that age-based restrictions on social media use warrant coordinated action.</description><pubDate>Mon, 13 Jul 2026 20:50:00 GMT</pubDate></item><item><title>Europe revives law allowing big tech to scan for CSAM</title><link>https://therecord.media/chat-control-2-csam-scans-european-parliament-passage</link><guid isPermaLink="false">cst-2351</guid><description>The European Parliament approved Chat Control 2.0, legislation that authorizes major technology companies including Google, Meta, and Microsoft to scan user messages for child sexual abuse material (CSAM). The law enables automated detection systems to identify and report such content to authorities.</description><pubDate>Fri, 10 Jul 2026 19:30:00 GMT</pubDate></item><item><title>Most data brokers won’t tell you what happened to your deletion request</title><link>https://helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests</link><guid isPermaLink="false">cst-2302</guid><description>UC Irvine researchers tested deletion requests with California's data broker registry to understand compliance. The study found that most data brokers fail to provide confirmation or transparency about what happened to consumer deletion and sales-stop requests.</description><pubDate>Fri, 10 Jul 2026 06:30:46 GMT</pubDate></item><item><title>A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway</title><link>https://wired.com/story/a-majority-of-european-lawmakers-voted-against-letting-big-tech-read-our-messages-theyre-going-to-anyway</link><guid isPermaLink="false">cst-2264</guid><description>European lawmakers rejected a proposal to restrict tech companies' scanning of private messages for child abuse material, but companies intend to proceed with these surveillance practices anyway. The Chat Control bill enables automated scanning of personal communications across text, email, and social media platforms.</description><pubDate>Thu, 09 Jul 2026 13:55:08 GMT</pubDate></item><item><title>EU takes member states to court over unimplemented cybersecurity law</title><link>https://therecord.media/eu-cyber-filing-ireland-spain-france-netherlands-nis2</link><guid isPermaLink="false">cst-2244</guid><description>The European Union has initiated legal action against Ireland, Spain, France, and the Netherlands for failing to transpose the NIS2 Directive into national law more than 20 months past the deadline. The directive establishes cybersecurity requirements for critical infrastructure operators across EU member states.</description><pubDate>Thu, 09 Jul 2026 13:10:02 GMT</pubDate></item><item><title>Cyber Essentials Pathways: from proof of concept to cyber confidence</title><link>https://ncsc.gov.uk/blogs/cyber-essentials-pathways-from-proof-of-concept-to-cyber-confidence</link><guid isPermaLink="false">cst-2234</guid><description>A new pathway to Cyber Essentials Plus certification has been introduced that maintains scheme integrity while offering an alternative route to the standard certification process.</description><pubDate>Thu, 09 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Cash App owner to pay $45 million to settle allegations of lax security</title><link>https://therecord.media/cash-app-owner-to-pay-45-million-security-allegations</link><guid isPermaLink="false">cst-2197</guid><description>Block, Inc., owner of Cash App, has agreed to pay $45 million to settle allegations from state attorneys general that it misrepresented the security protections offered to users. The settlement addresses claims that the company falsely promised Cash App users would receive bank-equivalent security safeguards.</description><pubDate>Wed, 08 Jul 2026 20:14:00 GMT</pubDate></item><item><title>Why Bangladesh’s new data protection law may fail to protect your data</title><link>https://databreaches.net/2026/07/08/why-bangladeshs-new-data-protection-law-may-fail-to-protect-your-data?pk_campaign=feed&amp;pk_kwd=why-bangladeshs-new-data-protection-law-may-fail-to-protect-your-data</link><guid isPermaLink="false">cst-2180</guid><description>Bangladesh's major retail chain Shwapno suffered a breach in August 2025 exposing personal data of 4 million customers, including names, phone numbers, and purchase histories. The company did not disclose the incident to affected customers for seven months, raising questions about the effectiveness of Bangladesh's data protection law in enforcing notification and transparency requirements.</description><pubDate>Wed, 08 Jul 2026 15:23:34 GMT</pubDate></item><item><title>Former UK privacy chief preparing legal action against woman who reported him, minister says</title><link>https://therecord.media/former-uk-privacy-chief-preparing-legal-action-against-woman-who-reported-him</link><guid isPermaLink="false">cst-2175</guid><description>The UK Secretary of State for Science, Innovation and Technology expressed strong disapproval of an independent investigation that found sexual harassment and bullying at the Information Commissioner's Office (ICO). The former privacy chief is reportedly preparing legal action against a woman who reported the allegations.</description><pubDate>Wed, 08 Jul 2026 14:20:00 GMT</pubDate></item><item><title>Risky Bulletin: All new cars to include a camera aimed at the driver's face</title><link>https://risky.biz/risky-bulletin-all-new-cars-to-include-a-camera-aimed-at-the-drivers-face</link><guid isPermaLink="false">cst-2134</guid><description>The European Union has mandated that all new cars include an infrared camera monitoring the driver's face to detect distracted driving, with the same requirement set to take effect in the US next year. The camera tracks head position and eye movements to alert drivers when their attention drifts from the road. Privacy advocates have raised concerns about the continuous facial surveillance capability.</description><pubDate>Wed, 08 Jul 2026 05:33:30 GMT</pubDate></item><item><title>The Shift Toward Business-Aligned Risk Management</title><link>https://securityweek.com/the-shift-toward-business-aligned-risk-management</link><guid isPermaLink="false">cst-488</guid><description>Organizations are moving toward risk management practices that connect security controls to business outcomes rather than treating security as an isolated technical function. This approach emphasizes continuous monitoring and assessment of risk throughout its lifecycle, enabling better alignment between security investments and actual organizational impact.</description><pubDate>Mon, 06 Jul 2026 15:20:42 GMT</pubDate></item><item><title>Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs</title><link>https://darkreading.com/cybersecurity-analytics/aussies-face-reduced-cybercrime-risk-pressure-shifts-smbs</link><guid isPermaLink="false">cst-76</guid><description>Australian institutions have strengthened cybersecurity safeguards and regulatory frameworks, shifting the burden of cyber protection and risk mitigation toward small and medium-sized businesses (SMBs). This consolidation of defenses at larger organizations means SMBs now face proportionally greater exposure to cyber threats without equivalent resources or regulatory support.</description><pubDate>Thu, 02 Jul 2026 23:01:00 GMT</pubDate></item><item><title>Supreme Court decision threatens EU-US data transfer agreement</title><link>https://therecord.media/supreme-court-decision-threatens-eu-us-data-sharing</link><guid isPermaLink="false">cst-128</guid><description>Max Schrems, founder of privacy advocacy group noyb, has informed European officials of his intention to sue to invalidate the EU-U.S. Data Privacy Framework (DPF), which governs the transfer of personal data from the EU to U.S. companies. This legal challenge reflects ongoing concerns about the adequacy of U.S. data protection standards and enforcement mechanisms under the agreement. The outcome could disrupt data flows between the regions if the framework is invalidated.</description><pubDate>Thu, 02 Jul 2026 16:50:00 GMT</pubDate></item><item><title>Google loses final appeal to overturn €4.1 billion EU fine</title><link>https://bleepingcomputer.com/news/legal/google-loses-final-appeal-to-overturn-41-billion-eu-fine</link><guid isPermaLink="false">cst-9</guid><description>Google's final appeal against a €4.1 billion European Union antitrust fine has been dismissed by the Court of Justice of the European Union. The fine, originally issued in 2018, penalized the company for using Android to promote its Chrome browser and search service. The dismissal marks the end of Google's legal challenge to the penalty.</description><pubDate>Thu, 02 Jul 2026 15:18:51 GMT</pubDate></item><item><title>In major privacy win, Supreme Court rules geofence warrants are protected by privacy rights</title><link>https://techcrunch.com/2026/06/29/in-major-privacy-win-supreme-court-rules-geofence-warrants-are-protected-by-privacy-rights</link><guid isPermaLink="false">cst-465</guid><description>The Supreme Court has ruled that geofence warrants are subject to privacy protections under the Constitution, limiting their use by law enforcement. The decision represents a significant privacy win against what civil liberties advocates had characterized as an unconstitutional surveillance method.</description><pubDate>Mon, 29 Jun 2026 16:05:23 GMT</pubDate></item><item><title>How to Spot a Client in the DoD Industrial Base That Handles CUI</title><link>https://huntress.com/blog/how-to-identify-dod-cui-clients</link><guid isPermaLink="false">cst-663</guid><description>The article provides guidance for managed service providers and managed security service providers to identify whether their clients are Department of Defense contractors that handle Controlled Unclassified Information (CUI). This helps service providers understand their clients' regulatory obligations and security requirements.</description><pubDate>Thu, 25 Jun 2026 14:00:00 GMT</pubDate></item><item><title>Do CISOs Need a Code of Ethics?</title><link>https://darkreading.com/cybersecurity-operations/ciso-code-of-ethics</link><guid isPermaLink="false">cst-113</guid><description>Industry expert Robert Hansen argues that chief information security officers should adopt a formal code of ethics to address conflicts of interest, self-dealing, and other practices that could compromise enterprise and national security. A code of ethics could establish professional standards for CISOs navigating vendor relationships, investment decisions, and other activities where personal interests might diverge from organizational security objectives.</description><pubDate>Wed, 24 Jun 2026 19:10:17 GMT</pubDate></item><item><title>NIS2 is raising the bar. Here’s how to turn readiness into resilience.</title><link>https://rapid7.com/blog/post/so-nis2-compliance-turn-readiness-into-resilience</link><guid isPermaLink="false">cst-373</guid><description>The NIS2 directive imposes stricter requirements on covered organizations including structured risk management, governance accountability, supply chain oversight, and accelerated incident reporting timelines (24 hours for early warning, 72 hours for notification). Beyond compliance interpretation, organizations must operationalize these requirements across their business through clearer ownership, incident response processes, and supply chain monitoring to achieve true resilience rather than checkbox compliance.</description><pubDate>Mon, 15 Jun 2026 17:29:15 GMT</pubDate></item><item><title>Does Your Security Programme Align With NIS2 Requirements?</title><link>https://rapid7.com/blog/post/so-aligning-security-programmes-with-nis2-requirements</link><guid isPermaLink="false">cst-374</guid><description>The NIS2 Directive significantly expands EU cybersecurity regulation, applying to more sectors and requiring organizations to demonstrate that controls work continuously rather than maintain policies. Key requirements include risk management measures, incident reporting within strict timelines (24 hours for early warning, 72 hours for full notification), and executive accountability, shifting the focus from periodic compliance to continuous operational readiness.</description><pubDate>Mon, 15 Jun 2026 17:24:20 GMT</pubDate></item><item><title>Risky Bulletin: In the age of AI, CISA changes federal patching rules</title><link>https://risky.biz/risky-bulletin-in-the-age-of-ai-cisa-changes-federal-patching-rules</link><guid isPermaLink="false">cst-174</guid><description>CISA issued a new binding operational directive updating federal civilian agency patching requirements, prioritizing vulnerabilities based on risk factors including active exploitation, ease of automation, and broad system access. The directive cites AI-automated attacks as motivation for the rule change and shortened patching deadlines.</description><pubDate>Fri, 12 Jun 2026 04:57:27 GMT</pubDate></item><item><title>Why Huntress Doesn’t Need FedRAMP</title><link>https://huntress.com/blog/fedramp-alternative-for-defense-contractors</link><guid isPermaLink="false">cst-677</guid><description>Huntress has implemented Sensitive Data Mode to provide logical data separation, allowing defense contractors to achieve CMMC (Cybersecurity Maturity Model Certification) compliance without requiring FedRAMP authorization. This approach offers a more cost-effective and faster alternative to using FedRAMP-authorized cloud services for contractors handling sensitive defense data.</description><pubDate>Fri, 05 Jun 2026 14:00:00 GMT</pubDate></item><item><title>Before Your MSP Chases CMMC, Take an Honest Look at Your Operations</title><link>https://huntress.com/blog/cmmc-msp-readiness-check</link><guid isPermaLink="false">cst-681</guid><description>The article advises managed service providers (MSPs) to conduct thorough internal audits of their operations before pursuing Cybersecurity Maturity Model Certification (CMMC) compliance for Department of Defense contracts. CMMC should be approached as a comprehensive operating model rather than a checklist, with particular attention to access controls and data handling practices. MSPs need to ensure their internal processes can withstand the scrutiny required for defense work.</description><pubDate>Wed, 27 May 2026 14:00:00 GMT</pubDate></item><item><title>13 Cybersecurity Frameworks for 2026 and How to Choose What's Best for You</title><link>https://huntress.com/blog/cybersecurity-frameworks</link><guid isPermaLink="false">cst-692</guid><description>This article provides an overview of 13 cybersecurity frameworks and guidance for organizations to select the appropriate framework based on their specific needs and use cases. The piece aims to help security leaders understand different framework options available in 2026.</description><pubDate>Thu, 14 May 2026 18:00:00 GMT</pubDate></item><item><title>CMMC Final Rule: A Guide for DoD Subcontractors</title><link>https://huntress.com/blog/cmmc-final-rule-guide-for-dod-subcontractors</link><guid isPermaLink="false">cst-694</guid><description>The Department of Defense (DoD) has finalized the Cybersecurity Maturity Model Certification (CMMC) rule, establishing a November 2026 deadline for DoD subcontractors to achieve Level 2 compliance. Security vendors are offering tools and monitoring services to help organizations meet these requirements.</description><pubDate>Thu, 14 May 2026 04:00:00 GMT</pubDate></item><item><title>How Public Sector Organizations Protect Their Communities Without Breaking the Budget</title><link>https://halcyon.ai/blog/how-public-sector-organizations-protect-their-communities-without-breaking-the-budget</link><guid isPermaLink="false">cst-2003</guid><description>The article discusses cost-effective security strategies that public sector organizations can implement to protect their communities and constituents. It examines budget constraints and practical approaches for maintaining adequate security posture within financial limitations.</description><pubDate>Thu, 30 Apr 2026 19:57:21 GMT</pubDate></item><item><title>Risky Bulletin: UK NCSC blasts SOC metrics</title><link>https://risky.biz/risky-bulletin-uk-ncsc-blasts-soc-metrics</link><guid isPermaLink="false">cst-198</guid><description>The UK National Cyber Security Centre (NCSC) has cautioned organizations against using performance metrics that prioritize speed or volume to evaluate security operations center (SOC) effectiveness. According to NCSC officials, such metrics incentivize careless work and rushing through security alerts rather than thorough threat investigation. The agency argues that SOC value derives from analytical insight and threat detection quality, not operational efficiency measures used for other IT functions.</description><pubDate>Wed, 29 Apr 2026 02:24:26 GMT</pubDate></item><item><title>Risky Bulletin: NIST gives up enriching most CVEs</title><link>https://risky.biz/risky-bulletin-nist-gives-up-enriching-most-cves</link><guid isPermaLink="false">cst-204</guid><description>The National Institute of Standards and Technology (NIST) announced a shift in its National Vulnerability Database (NVD) policy to enrich only a subset of vulnerabilities due to capacity constraints. Going forward, NIST will prioritize enrichment for vulnerabilities deemed critical to the safe operation of U.S. government and private sector networks, rather than attempting to enhance all reported flaws.</description><pubDate>Fri, 17 Apr 2026 04:11:35 GMT</pubDate></item><item><title>Srsly Risky Biz: It Is Time to Ban Sale of Precise Geolocation</title><link>https://risky.biz/srsly-risky-biz-it-is-time-to-ban-sale-of-precise-geolocation</link><guid isPermaLink="false">cst-205</guid><description>Citizen Lab released a report documenting Webloc, a geolocation data platform sold by Penlink that claims access to records from up to 500 million mobile devices globally, including location coordinates and device identifiers sourced from mobile apps and advertising networks. The analysis raises concerns about national security and privacy risks from the widespread commercial availability of precise geolocation data in the United States. Security researchers argue that stronger regulatory controls are needed to restrict collection and sale of such data.</description><pubDate>Thu, 16 Apr 2026 05:03:57 GMT</pubDate></item><item><title>The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response</title><link>https://wiz.io/blog/fedramp-incident-response</link><guid isPermaLink="false">cst-1337</guid><description>This article discusses how Wiz for U.S. Government addresses FedRAMP Revision 5 incident response controls and detection benchmarks through cloud detection and response capabilities. The piece concludes a series on Agile FedRAMP compliance by focusing on reactive risk management within cloud environments.</description><pubDate>Fri, 06 Mar 2026 12:00:01 GMT</pubDate></item><item><title>Wiz Achieves CPSTIC Certification in Spain</title><link>https://wiz.io/blog/wiz-cpstic-certification</link><guid isPermaLink="false">cst-1338</guid><description>Wiz has achieved CPSTIC certification in Spain, a credential that signals compliance with cloud security standards for the country's public sector. This certification positions the company to support government and public administration organizations in their cloud modernization efforts.</description><pubDate>Tue, 03 Mar 2026 20:46:57 GMT</pubDate></item><item><title>CIRCIA’s Next Chapter: Five Things I’ll Be Listening for in CISA’s Town Halls</title><link>https://halcyon.ai/blog/circias-next-chapter-five-things-ill-be-listening-for-in-cisas-town-halls</link><guid isPermaLink="false">cst-2025</guid><description>The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) is emerging as a potentially significant regulatory framework for the cybersecurity sector. The article discusses what to expect from upcoming CISA (Cybersecurity and Infrastructure Security Agency) town halls regarding CIRCIA's implementation.</description><pubDate>Tue, 03 Mar 2026 15:34:49 GMT</pubDate></item></channel></rss>