#compliance
18 stories taggedcompliance.

The EU's New 24-Hour Bug Reporting Rule Starts September 11. Most Vendors Aren't Ready.
A new European law forces software makers to disclose actively exploited flaws within a day. The hard part isn't the paperwork, it's knowing what you shipped.

HelmGuard Raises $7.3 Million to Automate Corporate Risk Checks With AI
A UK startup says it can compress weeks of security and compliance paperwork into hours using AI software agents. Investors handed it $7.3 million to find out.

Your Annual Security Audit Is Already Out of Date by the Time It's Done
A one-time snapshot of your defences tells you how things looked on a single day. Continuous monitoring tells you whether the locks are actually on right now.

US Coast Guard Opens Dedicated Cybersecurity Office for America's Ports and Waterways
A new federal office will write the rules on digital security for the network of ports, ships, and waterways that keeps American trade moving. It arrives after a government watchdog said the Coast Guard's cyber approach had serious gaps.

Anthropic's New Compliance API for Claude Code: What It Shows, What It Misses
Fresh endpoints give security teams a window into how developers use Claude Code, but logs alone will not tell you whether an AI agent's access is appropriate.

Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It
Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.

Almost Half of Companies Say AI Governance Problems Are Holding Their AI Back
A new survey puts a number on what many bosses already sense: unclear rules for how staff can use AI tools is quietly breaking AI projects from the inside.

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means and why it matters.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

California's Delete Act: A New Era for Data Privacy Rights
California's groundbreaking Delete Act platform lets residents erase their data from scores of brokers. Companies must adapt to a new compliance challenge.

Why Asking the Right Questions Matters More Than Expanding Compliance Frameworks
The compliance programs that hold up aren't the largest ones. They're built on a short list of answerable questions.

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.
The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.

AI Is Moving Faster Than the Rules Meant to Control It
The newest AI security tools can act on a network without human approval. The governance frameworks meant to keep that in check weren't written for this.

Farage's £5m Crypto Gift Was Flagged to the UK's National Crime Agency Over Money-Laundering Fears
Bankers who processed the payment raised a formal suspicion report. Now the Reform UK leader faces scrutiny from two directions at once.