Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Governance for Public Bodies, and Who Shares the Obligation

A public body running a high-risk AI system owes a fundamental rights impact assessment under Article 27 before first use, with the results notified to a market surveillance authority. The obligation is real and it is not yet in force. ‍ Regulation (EU) 2026/1744, in force since July 2026, deferred the section of the Act containing Article 27 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products.

Vulnerability Management: A Complete Guide to the Process and Lifecycle

If your vulnerability management program runs on a fixed scan-and-patch cadence, whether monthly, quarterly, or tied to a compliance deadline, you are measuring your response time against an attacker timeline that continues to accelerate. Vulnerability management remains a foundational security discipline. It identifies real, exploitable flaws and gives teams a structured way to prioritize and remediate them.

CISO Risk Intel Brief: Tokens, Policy, and the Edge Under Siege

The week’s material risk is not a single CVE. It is the identity and policy control plane. In seven days, CISA confirmed active exploitation against Cisco Identity Services Engine, Check Point VPN and management servers, F5 BIG-IP Access Policy Manager when used as an OAuth authorization server, and Arista’s on-prem VeloCloud Orchestrator. These products issue tokens, enforce network policy, or orchestrate SD-WAN.

What is NZISM? Guide to New Zealand's Information Security Manual

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Top 15 AI TRiSM Solutions By Category

AI TRiSM solutions address distinct risks across the AI lifecycle, from governance and evaluation to runtime security, agent authorization, and guardrails. In this comparison, the top 15 solutions fall into five complementary categories: These categories are complementary, not interchangeable. The right stack depends on where an organization needs to govern AI, monitor behavior, block threats, control agent privileges, or constrain AI interactions.

The Rising Threat of Deepfakes: Why Organizations Must Rethink Trust

For decades, we believed that if could hear someone’s voice on a phone call or see them on a video call, they were who they said they were. What if that’s no longer true? This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats.

The Consent Compliance Paradox: Why Having a CMP Isn't the Same as Having Consent

Here’s a question I’ve started asking privacy and security leaders in almost every conversation: if I asked you right now to list every script collecting data on your website, could you do it? If I then asked how many of those scripts are overwriting consent preferences, would you know? Most people pause. Some laugh. A few say yes with real confidence. But when we run the audit, the answer is almost always more complicated than they expected.

Feroot Expands DXComply with Code-Free Consent Auditing for Native Mobile Apps

New DXComply release enables privacy, GRC and security teams to verify whether native apps honor user consent choices without SDK integration or code changes. Toronto, Canada, September 23, 2026: Feroot Security Inc. today announced expanded native mobile application consent auditing capabilities in DXComply, enabling enterprises to verify whether iOS and Android apps honor users’ consent choices without requiring SDK integration or changes to application code.

Why Critical Infrastructure Needs Zero-Trust Security

Malicious cyber activity targeted remote monitoring and control technology at over 30 community water systems across Minnesota in late July 2026, and water cyber attacks were subsequently reported across at least 12 states. However, the underlying OT security weaknesses are not exclusive to the water sector.

AI Has Entered the SOC. Governance Has to Catch Up.

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems. For CISOs, the bigger question is whether governance reaches all the way into the security workflows where AI is beginning to act. Beth Dannemiller, Senior Director, Product Marketing For the last several years, CISOs have been asked a familiar question by boards: What are we doing with AI? That question is changing.