#compliance
22 stories taggedcompliance.

Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It
Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

Xpander Raises $7.5 Million to Help Companies Control Their AI Agents
A startup says it can give organisations a single control panel for the AI software agents running across their business. Investors just backed that idea with $7.5 million.

IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.

Almost Half of Companies Say AI Governance Problems Are Holding Their AI Back
A new survey puts a number on what many bosses already sense: unclear rules for how staff can use AI tools is quietly breaking AI projects from the inside.

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk
A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means, and why it matters to everyone.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

California's Delete Act: A New Era for Data Privacy Rights
California's groundbreaking Delete Act platform lets residents erase their data from scores of brokers. Companies must adapt to a new compliance challenge.

Why Asking the Right Questions Matters More Than Expanding Compliance Frameworks
Effective compliance programs focus on essential questions rather than broad frameworks.

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.
The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.

AI Is Moving Faster Than the Rules Meant to Control It
Artificial intelligence is reshaping how organisations defend themselves online, but the policies and oversight structures meant to govern that AI are struggling to keep pace.

Farage's £5m Crypto Gift Was Flagged to the UK's National Crime Agency Over Money-Laundering Fears
Bankers who processed the payment raised a formal suspicion report. Now the Reform UK leader faces scrutiny from two directions at once.

Seven Cyber Risk Assessment Mistakes That Give Security Leaders False Confidence
Experts say many organisations tick boxes, skip awkward corners of their networks, and confuse passing an audit with being secure. Here is what actually goes wrong.

CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running
Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is stuck in the middle of all three.

Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.
Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?

PCI DSS 4.0.1 Drags Checkout Scripts Into Scope, and Most Merchants Aren't Ready
Independent QSA assessment puts Reflectiz against the new client-side rules. The verdict: the script soup running on your payment page is now an auditable surface.