Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
The European Commission has launched a consultation on a draft Communication intended to provide guidance on the interpretation and practical application of Regulation (EU) 2024/2847, the EU Cyber Resilience Act (CRA). As required under Article 26(1) of the CRA, the proposed non-binding guidance is designed to assist manufacturers, developers and other stakeholders in better understanding their obligations under the CRA and to ensure a consistent approach across the EU, with a particular focus on supporting microenterprises and small and medium-sized enterprises in meeting compliance requirements. It covers the following key areas: (1) the scope of the CRA, including free and open-source software and the definition of substantial modification; (2) support period requirements; (3) important and critical products and core functionality assessments; (4) cybersecurity risk assessment; (5) remote data processing and (6) other elements such as reporting obligations, vulnerability handling and the interplay between the CRA and other EU legislation.
NEWS
The European Commission has launched a call for evidence on the Digital Omnibus, as part of its Digital Package on Simplification, scheduled for adoption in late 2025 as a directive and a regulation. This initiative seeks to reduce administrative burdens and compliance costs while maintaining the objectives of existing legislation, addressing fragmentation, outdated rules, and inconsistent enforcement in the EU digital framework. It will introduce targeted simplification measures in five areas: the data acquis (covering the Data Governance Act, Free Flow of Non-Personal Data Regulation, and Open Data Directive); rules on cookies and other tracking technologies under the ePrivacy Directive; cybersecurity-related incident reporting obligations; the smooth application of the EU Artificial Intelligence Act; and aspects of electronic identification and trust services under the European Digital Identity Framework, including alignment with the forthcoming EU Business Wallet and application of the ‘one in, one out’ principle. Stakeholders are invited to submit their responses by 14 October 2025.
NEWS
This week's edition of Risk and Compliance weekly highlights includes new ICO guidance on using personal information to protect businesses from crime, including the use of CCTV and facial recognition technology, and analysis of fresh pressure on EU-US data transfers following a US Supreme Court ruling. We also cover sanctions developments including amendments to an OFSI General Licence on maritime mutual re-insurance wind down, joint EDPB and AMLA plans for guidance on AML information sharing and data protection, and the launch of the Cyber Resilience Pledge to strengthen organisations' cyber defences.
NEWS
This week's edition of Risk & Compliance weekly highlights includes: updated guidance from DBT and OFSI on Russian sanctions enforcement and breach assessments, a £300,000 penalty for a sanctions violation, and the UK Supreme Court’s stance on government discretion in foreign affairs sanctions policy. The ICO released new data protection guidance on secure document disclosure, while the European Commission and Parliament addressed AI compliance under the AI Act and generative AI copyright concerns.
PRACTICE NOTES
This tracker tracks the progress of the European Commission’s proposals for a Digital Omnibus, published on 19 November 2025. Background The simplification agenda The Commission adopted its 2025 Work Programme outlining key initiatives for the year ahead on 12 February 2025, including several measures to simplify existing regulatory regimes. The 2025 Work Programme built upon the longer-term framework established by the Competitiveness Compass, as published in January 2025. Alongside the 2025 Work Programme, the Commission published a Communication on Simplification and Implementation, which set out how the Commission plans to make implementation of EU rules easier in practice, and provides further detail on the Commission’s plans to simplify a number of EU legislative measures. As explained in the Communication on Simplification, one of the Commission’s key targets for the next five years is to reduce administrative costs (including reporting costs) by at least 25% for all companies, and by at least 35% for small- and medium-sized enterprises (SMEs). The simplification agenda is designed to substantially deliver on these targets. As a matter of priority, the Commission is trying to tackle what it deems as overlapping, unnecessary,
NEWS
The European Commission has appointed a Scientific Panel and an Advisory Forum to support enforcement of the EU Artificial Intelligence (AI) Act. The Scientific Panel comprises 60 independent experts with experience in frontier AI, engineering, technical auditing and industrial and societal impact. Its work will focus on general-purpose AI models, systemic risks, model classification, evaluation methodologies and cross-border market surveillance. The Advisory Forum will provide technical expertise and advice on matters relating to the EU AI Act, including standardisation and implementation challenges, with members drawn from academia, civil society and industry, including small and medium-sized enterprises. Key EU agencies, including the EU Agency for Fundamental Rights and the EU Agency for Cybersecurity, as well as standardisation bodies, will have a permanent role in the forum. Both bodies will advise the Commission's AI Office and national authorities on the application of the rules, with members serving two-year terms.
Q&As
What are CUSOs? CUSOs are entities that are owned jointly by a number of credit unions and provide shared services to them, thereby providing economies of scale benefits. What services do CUSOs provide? CUSOs enable credit unions to access sophisticated services that would otherwise be cost-prohibitive, potentially enabling credit unions to compete more effectively with each other and with other mutuals, banks and short-term, high-cost lenders. CUSO services typically include back-office operations, such as IT support, data processing, and accounting. CUSO services may potentially also include a wider range of services, such as compliance, core banking platforms and payment systems, cybersecurity, and digital banking tools. Can the same services be provided by commercial third-party suppliers? Yes. The provision of services by both credit union-owned CUSOs and third-party suppliers is subject to a number of existing rules and expectations on outsourcing, governance, risk management and business continuity that apply to credit unions when outsourcing services. These include: • in the Credit Unions Part of the  Prudential Regulation
NEWS
MedTech for Europe has published a joint statement by a coalition of technology providers, digital infrastructure companies, medical technology companies, and small and medium-sized enterprises (SME)s, urging EU Member States and policymakers not to weaken the EU Digital Omnibus proposal during Council negotiations. The organisations argue that compromise texts from the Cypriot Presidency undermine the proposal’s simplification goals by rolling back EU General Data Protection Regulation (EU GDPR) reforms, rejecting an EU-level Single-Entry Point for cyber incident reporting and retaining restrictive cookie rules. The statement calls for targeted EU GDPR clarifications, harmonised cybersecurity reporting obligations, cookie reforms aligned with technical and market realities and stronger trade secret protections under the EU Data Act, warning that failure to simplify the EU digital rulebook could damage Europe’s competitiveness, innovation and attractiveness for investment. Signatories include, among others, Computer & Communications Industry Association (CCIA Europe), DOT Europe, MedTech Europe and the Information Technology Industry Council (ITI).
NEWS
This week's edition of EU Law weekly highlights includes the European Parliament adopting a resolution that welcomes the detailed proposals from the Conference on the Future of Europe and sets the Parliament’s follow-up to the recommendations, the CJEU broadening the scope of the Zambrano caselaw, the European Parliament and Council reaching a provisional agreement on ‘daisy chain’ amendments to CRR and BRRD, the European Commission introducing an initiative for a new Cyber Resilience Act that is set to establish new cybersecurity rules for digital products and ancillary services and the ACER and CEER publishing a paper on the proposed revision of gas storage and security of supply regulation. The highlights further include the CJEU imposing EU consumer law obligation on third party suppliers, and the European Commission adopting measures relating to vertical block exemptions and vertical agreements in distribution.
NEWS
The Singapore Chamber of Maritime Arbitration (SCMA) has published its 2025 year in review, reporting 83 case references with a total claim quantum of US$208.2m and an average claim value of approximately US$2.78m, representing year-on-year increases of 112% and 135% respectively. The report highlights expanded international outreach across key maritime hubs, including new memoranda of understanding with institutions in Tianjin, Dalian, Xiamen and Brunei, continued engagement with regional maritime and legal communities, plus progress across its methanol, ammonia and cybersecurity working groups. It also notes industry engagement through seminars, workshops and the biennial SCMA Conference, and confirms that Singapore will host the International Congress of Maritime Arbitrators (ICMA) XXIII from 22–27 March 2026.
NEWS
The Home Office has launched a consultation on new legislative proposals aimed at tackling the growing threat of ransomware attacks in the UK. The consultation, which closes on 8 April 2025, outlines three key objectives which include reducing the flow of money to ransomware criminals, enhancing the ability of operational agencies to disrupt and investigate ransomware actors and improving the government's understanding of cybersecurity threats. The proposed measures include expanding the ban on ransomware payments to all public sector bodies and critical national infrastructure, implementing a payment prevention regime and introducing mandatory reporting of ransomware incidents. These proposals seek to protect UK businesses, infrastructure and public services from the devastating impacts of cybercrime, which is estimated to cost the UK economy billions of pounds annually.
NEWS
This week's edition of Risk and Compliance weekly highlights includes analysis of changes to UK money laundering due diligence rules. We also cover anti-corruption developments, including the EU’s new directive harmonising corruption offences and the SFO’s 2026–27 Business Plan. In addition, we report on growing AI-driven cyber threats highlighted by government, new cyber resilience initiatives for businesses, and the launch of refreshed horizon scanning and tracking tools for compliance professionals.