News & insights
The latest news, insights, and updates on information & cyber security, privacy, and AI governance from Taylor Baines.
Welcome to our new website
Our new website is live, with clearer service information, a dedicated AI governance page, and a much bigger news and insights section.
Cyber Resilience Act: vulnerability and incident reporting begins
Manufacturers must now report actively exploited vulnerabilities and severe incidents under the EU Cyber Resilience Act.
EU e-Evidence Regulation now applies
EU authorities can now issue European Production and Preservation Orders directly to service providers.
California data brokers must begin processing DROP deletion requests
Registered California data brokers must now retrieve and act on consumer deletion requests submitted through the state’s DROP platform.
ISO/IEC 27017:2026 cloud security standard published
ISO and IEC publish the second edition of ISO/IEC 27017, updating cloud security controls to align with ISO/IEC 27002:2022.
EU AI Omnibus in force: high-risk obligations deferred
Amendments to the EU AI Act defer high-risk obligations and soften the AI literacy duty.
Supporting Eurostar with Belgian CyberFundamentals and NIS2
Our work with Eurostar now extends to the Belgian CyberFundamentals framework and NIS2.
New rule makes organisations liable for senior managers’ offences
Section 250 of the Crime and Policing Act 2026 extends corporate criminal liability to any offence committed by a senior manager.
Cyber Security and Resilience Bill passes the House of Commons
The Bill expanding the UK NIS regime has completed its Commons stages and moves to the House of Lords.
Canada’s Critical Cyber Systems Protection Act receives Royal Assent
Canada’s Critical Cyber Systems Protection Act creates mandatory cyber security programmes and incident reporting for federally regulated critical sectors.
HKMA operational resilience deadline arrives
Hong Kong authorised institutions must now be operationally resilient, meeting the HKMA’s OR-2 requirements.
TAKE IT DOWN Act platform removal duties take effect in the US
Covered platforms must now remove reported non-consensual intimate imagery, including AI deepfakes, within 48 hours of a valid request.