Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

PCI DSS Continuous Compliance: How to Keep Payment-Page Controls Working Between Audits

At the 2026 PCI SSC North America Community Meeting in Vancouver, continuous compliance was a recurring theme: how do organizations move beyond point-in-time validation and keep security controls working as their environments change? For payment-page security, that question is especially practical. Your last assessment captured your environment at a point in time. Since then, a release may have added a checkout dependency. A vendor may have updated its JavaScript. Marketing may have changed a tag.

Feroot Expands DXComply with Code-Free Consent Auditing for Native Mobile Apps

New DXComply release enables privacy, GRC and security teams to verify whether native apps honor user consent choices without SDK integration or code changes. Toronto, Canada, September 23, 2026: Feroot Security Inc. today announced expanded native mobile application consent auditing capabilities in DXComply, enabling enterprises to verify whether iOS and Android apps honor users’ consent choices without requiring SDK integration or changes to application code.

The Consent Compliance Paradox: Why Having a CMP Isn't the Same as Having Consent

Here’s a question I’ve started asking privacy and security leaders in almost every conversation: if I asked you right now to list every script collecting data on your website, could you do it? If I then asked how many of those scripts are overwriting consent preferences, would you know? Most people pause. Some laugh. A few say yes with real confidence. But when we run the audit, the answer is almost always more complicated than they expected.

Beyond the Compliance Snapshot: Why GRC Needs Continuous Evidence

I recently had the opportunity to speak at the ISACA GRC Conference in San Diego about a challenge I see becoming increasingly important for governance, risk, and compliance teams: How do you prove your controls are actually working in digital environments that never stop changing?

Ivan Tsarynny on CNBC: AI Regulation Should Empower Defenders, Not Limit Their Ability to Defend

Ivan Tsarynny, CEO of Feroot Security, joined CNBC’s The Exchange on July 31, 2026 to discuss a string of recent AI model “breakouts”—incidents where AI systems slipped past their own safety guardrails during testing—and what those incidents mean for how governments should regulate artificial intelligence.

Cookie Consent vs. GDPR Compliance: Why Network Traffic Matters More Than Banners

Cookie consent banners have become the public face of GDPR compliance. Nearly every organization operating in Europe has one, and many privacy teams have invested heavily in Consent Management Platforms (CMPs) to capture user preferences and satisfy regulatory requirements. The problem is that a consent banner only asks a question. It doesn’t prove the website honors the answer.

What Canada's Bill C-36 Means for AI-Powered Digital Experiences

As Canada strengthens privacy protections and enforcement, organizations must find a way to accelerate AI innovation while maintaining continuous visibility into how customer data is collected, shared, and protected. Canada’s proposed Bill C-36 is about more than privacy regulation. It reflects a broader challenge facing governments, regulators, and businesses around the world.

Google Tag Manager Wasn't Hacked. Your Trust Model Was.

Google Tag Manager is one of the most trusted tools on the modern web. Marketing teams rely on it daily. Ecommerce teams use it to move quickly. And most security teams rarely question it because it sits under the umbrella of a globally trusted platform. That’s exactly why attackers continue finding ways to abuse it.

Anthropic's Mythos and the New Reality of AI Cybersecurity Risk

I was on ABC News recently discussing why banks are on alert as new AI systems like Anthropic’s Claude Mythos raise cybersecurity concerns. What struck me most is how quickly the conversation has shifted. This is no longer a hypothetical risk or something we are planning for in the future. Financial institutions and regulators are reacting in real time to what AI is already capable of doing. From my perspective, we are still underestimating how fast this is moving.

Feroot Launches AI-Powered Digital Consent Audit to Prove CMP Enforcement

Organizations have invested heavily in consent management. Consent Management Platforms (CMPs) are standard infrastructure for privacy programs, and for good reason. Regulations like GDPR, CCPA/CPRA, LGPD, PDPA, and HIPAA require organizations to obtain, record, and honor user consent before collecting or processing personal data. CMPs provide the framework to do that. Most organizations have done the right thing, they just don’t know if they’ve done the right thing right.