Refine By
Clear all filter
About 703 results for "cybersecurity"
NEWS
This week's edition of EU Law weekly highlights includes analysis of the impact of the Directive on combating violence against women and domestic violence on regulating gender-based violence online and the enforcement of EU’s bans on unacceptable AI uses under the EU AI Act. In addition, the Dutch Data Protection Authority fined Uber €290m for breaches of the EU’s General Data Protection Regulation, EU and China commenced discussions under the Cross-Border Data Flow Communication Mechanism, and the European Banking Authority updated the 13 systemic importance indicators for Global Systematically Important Institutions.
NEWS
This week's edition of Practice Compliance weekly highlights includes: OFSI’s updated sanctions FAQs, FATF’s report on terrorist financing enforcement gaps, EU changes to the AML high-risk jurisdictions list, the ICO’s consultation on cookies and tracking technologies, and the FCA’s finalised guidance on PEPs.
PRACTICE NOTES
The UK rail network is the oldest in the world with over 1.7 billion people currently using the railways as a means of transport and over 17 billion tonne kilometres of freight being transported by rail every year. Following the privatisation of British Rail in the 1990s, the UK’s rail infrastructure sector has developed into a multifaceted regime combining public ownership with private sector delivery. Network Rail owns and operates the mainline network, regulated by the Office of Rail and Road (ORR) and guided by strategic policy from the Department for Transport (DfT). In May 2021 the UK Government published the Williams-Shapps Plan for Rail, which is intended to be the basis of extensive reform of the British railway. A new body, Great British Railways Transition Team, has been created to establish interim arrangements and support the creation of Great British Railways (GBR) that would be the ‘single guiding-mind’ for the railway. The functions of Network Rail would be absorbed by GBR. Rail infrastructure therefore remains an area of investment and growth.
NEWS
This week's edition of Practice Compliance weekly highlights includes the EU’s 21st package of sanctions against Russia, the Court of Appeal’s refusal of permission to appeal in R v Osmond, a case involving tipping off and analysis of proposed reforms to the transparency in supply chains regime under section 54 of the Modern Slavery Act 2015. We also cover concerns raised by the Serious Fraud Office about Güralp Systems’ bribery controls, new NCSC guidance on responding to and recovering from highly disruptive cyber attacks and the Legal Services Board’s final findings on conduct of litigation guidance.
NEWS
The London Court of International Arbitration (LCIA) has launched a consultation on the next editions of its Arbitration Rules and Mediation Rules, seeking input from the international arbitration and mediation community. The LCIA notes that since the last revision in 2020, user needs have evolved, technology has become more integrated into legal practice, arbitration laws have been reformed and the geopolitical environment has undergone significant change. The forthcoming revisions will focus on practical provisions that improve cost management, reduce procedural complexity and equip tribunals with enhanced tools to deliver efficient and enforceable outcomes. The consultation focuses on several key themes: (1) expedited and fast-track procedures; (2) updates to emergency arbitrator provisions; (3) third-party funding disclosure and tribunal powers; (4) costs reform, including optional ad valorem schedules; (5) AI disclosure and safeguards and (6) digital-ready proceedings, cybersecurity and data protection. Stage 1 of the consultation closes on 11 May 2026. Draft versions of the revised rules will be published for a second round of consultation later in 2026.
NEWS
This week's edition of Practice Compliance weekly highlights includes amendments to an OFSI General Licence on maritime mutual re-insurance wind down, joint EDPB and AMLA plans for guidance on AML information sharing and data protection, and analysis of fresh pressure on EU-US data transfers following a US Supreme Court ruling. We also cover new ICO guidance on using personal information to protect businesses from crime, the launch of the Cyber Resilience Pledge, and consultations from the DBT on workplace monitoring technologies and the SRA on first-tier complaint handling requirements.
NEWS
This week's edition of Risk & Compliance weekly highlights includes: the latest sanctions news, publication of the National Economic Crime Centre (NECC) annual report for 2023–2024, a MoU for collaboration on cyber security improvement, signed by the NCA and ICO, and new EHRC guidance for employers supporting disabled staff with hybrid working.
NEWS
The European Commission has published its 2025 State of the Digital Decade report, urging renewed action on digital transformation and technological sovereignty. The report evaluates the EU's progress toward its 2030 digital transformation targets by examining four areas: digital infrastructure, business digitalisation, digital skills, and public service digitalisation. It reveals that while some progress has been made, the rollout of connectivity infrastructure such as fibre and 5G stand-alone networks remains slow. There is an increasing uptake of AI, cloud, and big data by companies, yet more rapid progress is essential. Furthermore, only just over half of Europeans have basic digital skills, and there is a shortage of advanced ICT specialists, a situation worsened by a significant gender imbalance which restricts progress in key sectors like cybersecurity and AI. Although the digitalisation of public services has made headway, a considerable portion of governmental digital infrastructure continues to rely on providers from outside the EU. Persistent challenges such as fragmented markets, complex regulations and strategic dependence call for greater public and private investment, reforms to better integrate the single market, and eased administrative burdens. These measures could potentially boost the EU's gross domestic product by an estimated 1.8% by 2030. Member States are set to review the recommendations and discuss the future course of action, with further assessments scheduled for 2026 to ensure that targets remain in line with the evolving digital landscape and the EU's broader ambitions.
NEWS
Ofgem has launched a call for input on draft special licence conditions for long-duration electricity storage (LDES) projects under the cap-and-floor scheme, seeking stakeholder views ahead of a statutory consultation expected in summer 2026. The proposed conditions would be implemented through modifications to the standard electricity generation licence and are intended to establish the operational framework for LDES projects awarded support under the regime. The draft addresses areas including revenue calculation methodologies, availability requirements, treatment of construction cost overruns, financial resilience provisions, and governance of the cap-and-floor financial models. Ofgem states that it is particularly seeking views on key policy areas such as the approach to setting floor levels, the treatment of market-related costs and optimiser fees, availability requirements for storage assets, and controls on structured transactions and revenue maximisation. Ofgem is also seeking evidence on developing policy issues, including obligations during system stress events, cybersecurity expectations, governance of algorithmic optimisation, and the potential consumer impacts of repetitive re-trading in electricity markets. The call for input closes on 20 April 2026.
NEWS
The National Cyber Security Centre (NCSC) has published a paper on adversarial machine learning (AML) attacks that outlines attack classes exploiting ML-specific vulnerabilities, model behaviours and information leakage across the model lifecycle, including development, training and deployment, and highlights risks associated with large model sizes, open-source components and an expanded attack surface. The paper groups AML techniques into categories such as model characterisation, model inversion, training data poisoning, malicious model training, model input manipulation, model artefact manipulation and model hardware attacks, and explains how these techniques may enable malicious actors to achieve objectives including reconnaissance, performance degradation, resource exhaustion, output attribution, embedding hidden behaviours, evading detection, data extraction and unauthorised access. It distinguishes AML attacks from traditional cybersecurity threats while noting that ML systems remain susceptible to both and emphasises the need for robust security aims to protect confidentiality, integrity and performance. The paper aims to raise awareness, support threat modelling, establish a common language for ML security and highlight research gaps to improve collaboration and the development of defences against evolving AML attacks.
NEWS
The European Insurance and Occupational Pensions Authority (EIOPA) has published the advice of the Insurance and Reinsurance Stakeholder Group (IRSG) on artificial intelligence (AI) governance and risk management in response to EIOPA’s Opinion. The advice emphasises that, although most AI systems used in the insurance sector are not classified as high-risk under EU Regulation (EU) 2024/1689 (the AI Act), advanced applications in core functions such as underwriting, pricing, and claims management may present risks that warrant targeted oversight. A risk‐based and proportionate approach is recommended given that the regulatory instruments—the Solvency II Directive (Directive 2009/138/EC), the Insurance Distribution Directive (Directive (EU) 2016/97), Regulation (EU) 2016/679 (the General Data Protection Regulation or GDPR), Regulation (EU) 2022/2554 (the Digital Operational Resilience Act or DORA), and the AI Act—collectively establish a supervisory framework. The advice also draws a distinction between insurers that develop AI systems and those that deploy third‐party solutions and calls for tailored measures in the areas of data governance, documentation, transparency, explainability, human oversight, and cybersecurity to correspond with the actual risk and impact involved.
NEWS
The Department for Science, Innovation and Technology (DSIT) Minister of State, Ian Murray MP, has informed the House of Commons that UK Biobank had reported the online advertisement for sale of datasets purporting to contain participant data on a Chinese e-commerce platform. One dataset appearing to cover all 500,000 volunteers, although the data did not include names, addresses or contact details and no purchases are believed to have occurred. In response, the government worked with UK Biobank, the vendor and Chinese authorities to remove the listings, revoked access from the research institutions identified as the source, and required a pause on further data access until stronger technical safeguards are implemented. UK Biobank has referred itself to the Information Commissioner’s Office and will investigate the cause, notify participants, and conduct a rapid review of its data security arrangements. The Minister emphasised the importance of the Biobank’s research role, described the incident as a misuse of data and a breach of trust, and confirmed that further government guidance on research data controls and cybersecurity will be issued.