Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
Member States, with the support of the European Commission and the EU Agency for Cybersecurity (ENISA), published the first report on the cybersecurity and resilience of the EU’s telecommunications and electricity sectors. The report points to concerns about a number of risks, including risks to supply chain security, the lack of cyber professionals and the risks posed by malicious activities from cyber criminals and state-sponsored threat actors. More specifically, the risk evaluation uncovers major technical and non-technical risks for telecommunications and electricity sectors. Supply chain vulnerabilities, ransomware, data wipers, and zero-day exploits are major pressing concerns. Electricity faces insider threats, while telecoms faces roaming and botnet attacks. Physical risks like cable sabotage are difficult to mitigate. Recommendations include improving resilience through information sharing, vulnerability monitoring, personnel vetting, enhancing cyber situational awareness, strengthening contingency planning and cross-sector collaboration, and addressing supply chain security risks through assessments and an EU framework. Given the critical infrastructure involved and evolving threats, the report urged swift implementation of these resilience measures by Member States, the Commission, and ENISA.
PRACTICE NOTES
FORTHCOMING CHANGE: On 19 June 2025, the Data (Use and Access) Bill received Royal Assent, becoming the Data (Use and Access) Act 2025 (DUAA 2025) and coming partly into force on that date. Parts 5 and 6 serve to amend aspects of data protection and ePrivacy law in the UK, including the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426. Certain provisions of DUAA 2025, concerning matters such as responding to data subject access requests and the conferring of power to make further regulations, came into force immediately on 19 June 2025. Other provisions, concerning notices from the Information Commissioner and some aspects of law enforcement processing, come into effect on 19 August 2025 (being two months from the date of Royal Assent). The majority of DUAA 2025’s provisions require further regulations (in the form of statutory instruments) to be made to bring them into force. For further information on DUAA 2025 generally, see Practice
NEWS
This week's edition of Risk & Compliance weekly highlights includes: updated guidance on reporting suspected trade sanctions breaches by the DBT and OTSI, new restrictions on ransomware that may redirect cybercriminal activities to the private sphere, updated recommendations for managing external delays in legal processes, and emerging prospects for the UK to impact how corporate misdeeds are regulated.
NEWS
This week’s edition of Life Sciences weekly highlights includes a Law360 news analysis on the Patents Court striking out Sandoz’s claim for an account of profits made from selling blood-thinning treatment Xarelto during an interim sales ban against Bayer and news that the Patents Court addressed cost and interim payments following patent litigation in a complex dispute involving diabetes treatment dapagliflozin. Also included is news that the European Economic and Social Committee (EESC) published its opinion on the proposed EU Critical Medicines Act and Medicines for Europe responded to the European Parliament’s draft report on the Act, highlighting areas of concern, the Commission opened a consultation on revised Good Manufacturing Practice (GMP) quality system guidelines, the MHRA published an update to its March 2025 government response on statutory fees following post-market surveillance legislation for medical devices and published revised guidance on clinical investigations for medical devices, MedTech Europe published a position paper on aligning EU digital legislation with sector-specific frameworks and responded to the Commission’s consultation on extending the Carbon Border Adjustment Mechanism (CBAM). Further news included is that the ABPI announced that the Voluntary Scheme for Branded Medicines Pricing, Access, and Growth (VPAG) scheme review negotiations with the UK government have ended without agreement, the EESC issued its opinion on the EU’s cybersecurity action plan for healthcare, the HRA published a report on the legal and ethical use of patient information in research, the Prescription Medicines Code of Practice Authority (PMCPA) updated guidance on Clauses 3.1 and 11 of the ABPI Code of Practice, which prohibit the promotion of medicines prior to marketing authorisation, among other stories.
NEWS
Institutional Shareholder Services (ISS) Governance has launched its 2025 Global Benchmark Policy Survey, a key part of its annual policy development process for potential ISS policy changes for 2026. The survey explores governance topics such as shareholder rights in multi-class capital structures and board governance, with a focus on director overboarding. It also seeks views on non-executive director pay and executive compensation, as well as hybrid equity incentive plans in the UK. In addition, it covers evolving governance and risk management issues related to artificial intelligence, biodiversity, cybersecurity, and human rights. The survey closes on 22 August 2025. Once responses have been analysed, ISS will open a public comment period to gather feedback on key proposed policy changes for 2026, with final updates expected later in 2025.
NEWS
This week's edition of EU Law weekly highlights includes analyses on the Court of Justice’s ruling addressing the meaning of ‘promotional offer’ under EU E-Commerce Directive, the first Unified Patent Court’s infringement decision for second medical use claims and the transparency and disclosure obligations for AI Chatbots in consumer interactions. In addition this week, the Commission launched a consultation on high-risk AI classification and obligations, introduced the EU Sanctions Helpdesk, a free service providing sanctions compliance support to European small and medium-sized enterprise, adopted the European Ocean Pact, a comprehensive strategy designed to protect marine ecosystems, the International Swaps and Derivatives Association published a position paper in response to the Commission's sustainability omnibus package, the European Data Protection Board adopted final guidelines regarding data transfers to third country authorities, the Council of the EU adopted a new cyber crisis management blueprint to guide the EU’s collective response to large-scale cybersecurity incidents or crises and adopted its position on the revision of the EU regulations on air passenger rights and airline liability.
NEWS
The Department for Science, Innovation and Technology (DSIT) and Germany's Federal Ministry for Digital Transformation and Government Modernisation (BMDS) have signed a joint statement on the safety and security of advanced artificial intelligence (AI). The statement follows the German government's approval of plans to establish an AI Safety and Security Institute (AISI). It commits DSIT and the UK AISI to engage with BMDS, Germany's Federal Ministry of the Interior and the German AISI to strengthen institutional co-operation and support mutual development. Under the statement, both countries intend to share best practice on AI evaluation to improve their collective understanding of advanced AI systems, including the implications for cybersecurity. They also plan to align research priorities and build capability through exchanges of knowledge and expertise. The co-operation supports delivery of the Strategic Science and Technology Partnership, established under the UK–Germany Friendship and Bilateral Cooperation Treaty, signed in 2025.
NEWS
The European Network of Transmission System Operators for Electricity (ENTSO-E) published a position paper on 31 August 2026 setting out seven recommendations to reinforce the EU energy security framework for electricity infrastructure. The recommendations include: (1) developing harmonised and integrated risk assessments across the energy sector; (2) establishing minimum standards for securing critical grid assets; (3) clarifying the respective roles of transmission system operators and public authorities during crises; (4) strengthening regional co-operation for offshore infrastructure protection and recovery; (5) enabling faster cross-border deployment of critical resources in emergencies; (6) introducing security-sensitive transparency rules to protect critical infrastructure information and (7) supporting investment in electricity grid protection, including through national tariff frameworks and EU funding instruments. ENTSO-E states that energy security requires an integrated approach covering security of supply, physical security and cybersecurity. The recommendations are intended to support ongoing EU discussions on strengthening energy security.
NEWS
This week's edition of Practice Compliance weekly highlights includes our new compliance forecast, OFSI’s annual frozen assets reporting notice for 2025, renewed pressure on the UK government to introduce cyber regulation reform, clarification from the ICO on myths surrounding storage and access technologies and the House of Commons’ rejection of House of Lords amendments to the Employment Rights Bill.
PRACTICE NOTES
ARCHIVED: This Practice Note has been archived and is not maintained. This document tracks the key steps of the legislative procedures on data in the EU. On 19 February 2020, the European Commission published a ‘European Strategy for data’ with the aim to create a single market for data which will make the EU more competitive globally and will enable innovative processes, products and services. This tracker focuses on non-personal data initiatives and includes: • EU Data Governance Act • EU Data Act • EU Open Data Directive • European Health Data Space • European Mobility Data Space • European Tourism Data Space • Access to vehicle data • Data collection for short-term rentals Note that this tracker does not cover the proposal for a Regulation on a framework for Financial Data Access which was published on 28 June 2023. For more information on other EU’s digital strategy initiatives such as the EU Artificial Intelligence Act, the ePrivacy Directive reform, the EU Digital Services Act, the EU Digital Markets Act, and EU cybersecurity initiatives, see Practice Notes:
PRACTICE NOTES
This Practice Note reflects regulatory requirements in relation to websites that are specific to the legal sector and, in particular, law firms regulated by the SRA. It also summarises key privacy issues under the UK General Data Protection Regulation (UK GDPR). For general regulatory requirements in relation to websites, see Practice Note: Websites—compliance requirements, which provides guidance on key legal and compliance requirements that a website operator should consider, including: • the type and functionality of the website • information disclosure requirements • consumer protection • privacy and data protection • cookies • accessibility • cybersecurity • platform-to-business • online payments • advertising, promotions and direct marketing • competition law • taxation • liability for third party content • online safety and suitability • intellectual property and respecting copyright • geographic and territorial considerations SRA requirements The main requirements are to be found in the SRA Transparency Rules. Pricing information Law firms are required to publish information on their website on the prices they charge and what these cover. This does not apply to all legal services, but only to:
PRACTICE NOTES
FORTHCOMING DEVELOPMENT: On 3 February 2025, the House of Commons Treasury Committee launched an inquiry into AI in financial services to explore how UK financial services, including pensions, can take advantage of opportunities in AI while at the same time mitigating threats to financial stability (eg cybersecurity risks) and safeguarding financial consumers, particularly vulnerable customers who may be at risk of bias. For further information, see LNB News 04/02/2025 12. What is artificial intelligence (AI)? Artificial intelligence (AI) refers to computer software and systems that are capable of demonstrating human intelligence. They can learn, plan, reason or process natural language as they go rather than only relying on pre-programmed tasks. With AI expected to transform financial services, it is in the best interests of pensions professionals, trustees, employers, providers and others involved in the running of pension schemes to consider the opportunities and risks which AI may present (both now and in the future). Any consideration of AI will inevitably require some familiarity with certain technical terms, including: • extractive AI vs generative AI—while