#policy
77 stories taggedpolicy · page 5 of 6.

Chris Inglis on the Snowden Era: What NSA Got Wrong, and What CISOs Should Still Be Asking
The former NSA Deputy Director reflects on institutional failures, insider threat detection, and why 'enculturation' may matter more than access controls.

Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.

Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.
Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?

RSnake's Case for a CISO Code of Ethics
Robert Hansen argues that kickbacks, no-show jobs, and shelfware deals aren't just embarrassing — they're a national security problem.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

Macron Pushes Wealthy Democracies Toward a Unified AI Regulatory Front
The French president wants the G7 crowd to stop freelancing on AI governance and start coordinating. Whether that translates into anything enforceable is a different question entirely.

Feds Pull the Plug on CFAKE and SOCFAKE in First TAKE IT DOWN Act Domain Grab
DOJ seizes two deepfake nude sites that pulled tens of millions of visits a month, marking the first public test of the new federal statute.

Voluntary AI Security Rules: The Industry Already Knows What That Means
Trump's AI cybersecurity executive order drew polite applause from vendors and quiet skepticism from practitioners. The gap between those two reactions is where the real story lives.

Executive Order Mandates AI Security Vetting
Federal directive requires AI models to undergo national security risk assessments before release.

The Pentagon Wants Battlefield AI. Not Everyone With Stars on Their Collar Agrees.
The White House sees AI as a defining American military edge. Some of the generals and admirals who would actually deploy it aren't so sure.

India Sets a 12-Hour Clock on Exploited Vulnerabilities. Can Enterprises Actually Do It?
CERT-In's new AI-threat framework resets expectations around patch velocity — but the real test is whether organizations even know what's exposed.

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach
AG Rob Bonta is going after Chrome Holding Co. — the shell 23andMe rebranded into after its bankruptcy — arguing the company failed to adequately protect the genetic and personal data of millions of users.

What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity
A fresh read of 2024–2025 10-K Section 1.C filings shows NIST CSF dominance, audit committee capture, and a suspicious abundance of 'no material impact' disclosures.

CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours
India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.
A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators — despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.