ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act
ETSI published 17 draft cybersecurity standards to underpin the EU Cyber Resilience Act, giving manufacturers a concrete compliance roadmap for products with digital elements.
Original write-ups of the governance, risk, compliance, privacy, and regulatory enforcement stories that matter. Published daily, rewritten in our own words, with every claim traced back to its source.
ETSI published 17 draft cybersecurity standards to underpin the EU Cyber Resilience Act, giving manufacturers a concrete compliance roadmap for products with digital elements.
The FCC may add Chinese-made optical transceivers to its Covered List, barring new models from US data centers. A third-party risk story for every AI operator.
FinCEN levied a historic AML penalty against UBS stemming from long-running compliance failures. The case shows how sustained regulatory pressure builds toward enforcement that reshapes an institution.
Wiz found a GitHub Actions workflow injection in Snowflake's public repo that exposed internal Jira credentials. What it teaches GRC teams about CI/CD risk.
FinCEN and three other regulators hit UBS Financial Services with a combined $125M AML penalty. A masterclass in the cost of recidivism and slow remediation.
OFAC designated Shelbit, an Iranian crypto exchange processing $6 billion in volume, for facilitating sanctions evasion. The action signals expanding enforcement into digital asset intermediaries.
NIST is asking for public comment on modernizing the National Vulnerability Database to support AI-driven vulnerability management. What this means for compliance programs that rely on CVE data.
ETSI published 17 draft standards supporting the EU Cyber Resilience Act, now open for public comment. What the CRA standards pipeline means for anyone building or buying connected products.
The UK ICO issued a reprimand over a 2023 breach at the ACRO Criminal Records Office. What this says about data protection oversight of public bodies, and what GRC teams should take from it.
The US Department of Defense suspended Phase II of the Cybersecurity Maturity Model Certification. What the pause means for contractors, assessors, and anyone running a compliance roadmap.
Over 120 tech organizations back the Shared AI Findings Exchange, a framework for confidentially sharing AI security incidents and translating them into defensive guidance.
Every article links to its original reporting for attribution. Original analysis by Zabez; not affiliated with the sources.