#policy
77 stories taggedpolicy · page 2 of 6.

Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Cybersecurity Groups Draft 'SAFE' Rules for Sharing AI Incident Data
A coalition of more than 120 companies, including Nvidia, Cisco and Amazon, is asking for public feedback on a proposed framework that would let organisations quietly report AI security failures and share what they learned with everyone else.

New York Hands $9 Million to 153 Water Utilities to Plug Cyber Gaps
The grants come as hackers step up attacks on water and wastewater systems across multiple US states. Here is what the money buys, and what it means for the people who drink the water.

Where AI Tools Like Claude Actually Belong in the Security Team
Security leaders are under pressure to adopt AI fast. Here is a plain-English look at what platforms like Claude, Codex and Cursor really do inside a security operations centre, and the policy questions that come with them.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

CISA Rewrites the Rules for Software Ingredients Lists. Critics Say It's Not Enough.
A 17-nation coalition has updated the global standard for tracking what goes into software. The framework is broader than its 2021 predecessor, but security experts argue it sidesteps the hardest questions.

When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath
Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.

Why Asking the Right Questions Matters More Than Expanding Compliance Frameworks
Effective compliance programs focus on essential questions rather than broad frameworks.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

Schools Are Handing Deepfake Criminals a Photo Album
Australia's eSafety regulator is warning schools to stop posting student and teacher photos online after a surge in AI-generated deepfakes built from official school feeds.

US House passes kids' online safety bill, but critics say the cure may be worse than the disease
The KIDS Act cleared the House 267-117 on Monday. It demands new parental controls and bans targeted ads at children, but digital rights groups warn that age-verification rules could quietly strip privacy from every adult online too.

US and allies rewrite the software 'ingredients list' rulebook for 2026
CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

Russia Charges Telegram's Pavel Durov With Aiding Terrorism
The FSB says Telegram refused to take down channels it flagged. Durov, living abroad, calls the case political theatre.

US and Australia Publish Joint Playbook for Cutting Critical Infrastructure Off From Cyber Attack
New guidance tells power plants, water utilities, and other essential services how to keep running even when their networks are under attack or must be disconnected entirely.

Gold Coast teacher charged after using AI to generate explicit images of students and staff
A 73-year-old former teacher at a Queensland private school faces four criminal charges after police found AI-generated child exploitation material on his school-issued laptop, following a nine-month investigation.