News & insights
The latest news, insights, and updates on information & cyber security, privacy, and AI governance from Taylor Baines.
Get the latest threats, vulnerabilities, and legal, standards, and AI updates in your inbox every Monday.
Get our weekly insights by emailNCSC updates the Cyber Assessment Framework to version 3.2
CAF v3.2 refreshes guidance on remote access, privileged operations, user access and system monitoring.
Chile’s cybersecurity framework law is published
Chile’s Cybersecurity Framework Law 21.663 is published, creating a National Cybersecurity Agency and incident reporting duties.
TISAX assessments move to VDA ISA 6.0
TISAX assessments commissioned from 1 April 2024 must use version 6.0 of the VDA Information Security Assessment catalogue.
Japan requires JIS T 81001-5-1 for medical devices
Japan now requires medical device manufacturers to follow JIS T 81001-5-1 for secure software development.
RBI Master Direction on IT governance takes effect
The Reserve Bank of India’s Master Direction on IT governance, risk, controls and assurance practices is now in effect.
Washington’s My Health My Data Act takes effect
Washington’s consumer health data law takes effect, requiring consent for collecting and sharing health data and allowing private lawsuits.
Backdoor found in xz Utils compression library used across Linux
A Microsoft engineer spots a deliberately planted backdoor in the xz Utils library, narrowly preventing a major open source supply-chain compromise.
The Pensions Regulator’s General Code comes into force
TPR’s new General Code of Practice, including expectations on cyber controls, is now in force.
Deadline passes for old EU SCCs in UK transfers
UK organisations can no longer rely on the pre-2021 EU Standard Contractual Clauses for restricted transfers.
NIST Cybersecurity Framework 2.0 released
NIST has released CSF 2.0, adding a new Govern function and broadening the framework to all organisations.
ISO/IEC 27001 and ISO 22301 amended to address climate change
ISO has amended its management system standards, including ISO/IEC 27001 and ISO 22301, to require consideration of climate change.
Ransomware attack on Change Healthcare disrupts US healthcare payments
A ransomware attack on UnitedHealth’s Change Healthcare cripples claims and prescription processing across the US and exposes data on about 193 million people.