#NIS2
26 stories taggedNIS2.

IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.

From Coder to Chief: How Standard Chartered's Security Boss Runs Defence at a Global Bank
The bank's top security executive explains how the job has changed, why security leaders must speak business not just tech, and what artificial intelligence means for both attackers and defenders.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Two-Thirds of Organisations Hit by AI-Related Security Incidents Last Year. The Weak Link Is the API.
A surge in AI adoption has quietly created a new kind of back door into company systems. Experts say most businesses are focused on the wrong part of the problem.

One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds
A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

Milan Startup Beelzebub Raises $3.4 Million to Build AI Traps for Hackers
The Italian cybersecurity firm's platform assumes criminals are already inside a company's network and uses artificial intelligence to lure them into decoy systems, catch them, and lock them out automatically.

A New Index Is Tracking Every Major Corporate Data Breach, and Deliberately Leaving the Dollar Totals Out
Richard Bird, a veteran cybersecurity executive, has built a public tool that logs every significant breach companies are required to report. Its unusual choice: no running loss tally.

Ransomware Hits Naval Contractor, Lidl Discloses Data Breach, and Iran Tracks US Military Phones
A week of scattered but serious disclosures: a defence shipbuilder confirms a ransomware attack, a major supermarket chain notifies customers of stolen data, and new evidence suggests Iranian operatives tracked phones belonging to US military personnel.

Europe's Cyber Threat Picture Looks Nothing Like America's. The Numbers Prove It.
Business email scams hit 81% of reported incidents in Germany and the Benelux region. Europe absorbs nearly half of all global denial-of-service attacks. A new wave of ransomware gangs is arriving. The regulatory rulebook is entirely different, too.

EU Sanctions Russian Intelligence Officers Over Years-Long Cyber Spying and Sabotage Campaign
Brussels has placed travel bans and asset freezes on individuals tied to a Russian-linked network accused of spying on European governments and attacking critical infrastructure.

European Workers Trust Their Collaboration Tools. The Numbers Tell a Different Story.
A new survey finds that most IT leaders in the UK, France, and Germany feel confident about how securely their teams share information at work. But the same survey shows files staying open too long, consumer apps slipping in through the back door, and fewer than a third of organisations using a secure channel for outside partners.

Spanish Startup 8Layers Has Raised $2.9 Million to Track Every Digital Identity Inside a Business
The Madrid company says its platform watches human accounts, software service accounts, and AI agents across cloud tools, then flags suspicious behaviour before it becomes a breach.

Microsoft Tightens Teams Meeting Controls for External AI Bots
A new admin policy requires organizer approval before automated external participants can join Teams meetings — a quiet but consequential shift in how enterprises govern AI access to sensitive calls.

Behavioral AI Pitched as Answer to Identity-Abuse Phishing, But Regulators Still Set the Bar
A vendor webinar makes the case for behavioral detection against BEC and account takeover. The compliance questions sit underneath.