Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cyber Resilience Act: What MSPs Need to Know About the New European Guidance

The European Commission has published its first official guidance to help businesses implement the Cyber Resilience Act (CRA)—the EU regulation establishing cybersecurity requirements for products with digital elements. The timeline is critical: reporting obligations for actively exploited vulnerabilities and severe incidents take effect on September 11, 2026, while the core CRA requirements will become mandatory from December 11, 2027.

What is GRC transformation? A practical definition for enterprise CISOs

GRC transformation is the organizational change from running governance, risk, and compliance as periodic, check-the-box paperwork to running it as continuous, AI-native cyber risk assurance measured in business outcomes. It is not a tooling upgrade. It is a change in what you are asked to prove. The old question was whether the work got done by audit time. The new question is whether risk is understood and the controls meant to manage it are working right now.

How to Evaluate and Choose the Best Compliance Software in 2026

Choosing compliance software in 2026? Every platform on your shortlist says the same three things: automation, AI, and audit-ready. What none of them show you in a demo is whether the tool keeps you ready all year or leaves you scrambling every audit season. This video walks through five criteria that separate the two, and the exact question to ask a vendor on each one.

NIS2 and GDPR Compliance: How European Companies Can Reduce Duplicate Compliance Efforts

NIS2 and GDPR cannot be merged into one legal obligation, but much of the compliance work behind them can be consolidated. Organisations can use one control framework, shared asset and risk information, common supplier assessments and a single incident record while maintaining separate legal registers and notification workflows. The key is to consolidate evidence and operational processes — not the obligations themselves.

Who Signs the CMMC Affirmation for Your Company?

CMMC is increasingly important for any company that is even tertiary to the Department of Defense and the defense industrial base. Prime contractors are prime targets, but even two, three, four, or more steps down the chain, CMMC may be mandatory. It's all about protecting information, after all. This means a lot of businesses are looking seriously at CMMC, and a lot of high-level executives are being asked to put their names on things they might not understand at a glance.

ISO 42001 Evidence: What Auditors Ask For

ISO 42001 is the management system standard for artificial intelligence. It sits on the backbone of ISO 27001 but with a different focus: do you have a system for governing AI, and can you prove that system runs, with evidence? Core to the standard is an Artificial Intelligence Management System (AIMS), a structured set of policies, processes, and controls an organization uses to govern AI.

Introducing Acronis Cyber Compliance: Continuous compliance built for MSPs

There is no shortage of guidance available to MSPs on how they should secure customer environments. Security frameworks, industry standards, regulatory requirements and insurance obligations all provide recommendations on the controls organizations should have in place. Yet despite this abundance of guidance, cyber incidents remain common and continue to increase. At the same time, requirements are becoming more complex.

Why security questionnaires can't measure vendor risk

“Friends don’t send friends security questionnaires. “If you hang around me long enough, you will hear me say it. It gets a laugh, but the point underneath it is serious. Are security questionnaires enough to manage third-party risk? No. A questionnaire tells you what a vendor is willing to claim on a given day. It does not tell you whether the control behind that claim is working. Those are two very different things, and most third-party risk programs are still built on the first one.

Every New Compliance Framework Restarts the Same Fire Drill. It Doesn't Have To.

Every compliance audit starts the same way: Someone flags a deadline, the team scrambles to pull evidence, map controls, and prove that the policies running in production actually match what the framework requires. They make it through. They exhale. Six months later, a new framework arrives, and the fire drill starts all over again. Most teams walk away from an audit believing they are compliant.