News & insights
The latest news, insights, and updates on information & cyber security, privacy, and AI governance from Taylor Baines.
Get the latest threats, vulnerabilities, and legal, standards, and AI updates in your inbox every Monday.
Get our weekly insights by emailLaw enforcement takes control of LockBit ransomware operation
The UK’s National Crime Agency leads Operation Cronos, seizing LockBit’s infrastructure and leak site and turning it against the gang.
Deepfake video call tricks finance worker into paying out around US$25m
Hong Kong police reveal that a finance worker paid out HK$200m after a video call in which every other participant was a deepfake.
FINMA’s operational resilience circular comes into force
FINMA Circular 2023/1 on operational risks and resilience now applies to Swiss banks and securities firms.
OSFI’s Guideline B-13 on technology and cyber risk takes effect
Canada’s federally regulated financial institutions must now meet OSFI’s expectations for technology and cyber risk management.
SEC cybersecurity incident disclosure rules take effect
US-listed companies must now disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.
ISO/IEC 42001:2023 published: the first AI management system standard
ISO has published ISO/IEC 42001, the world’s first certifiable management system standard for artificial intelligence.
OpenAI board removes chief executive Sam Altman
OpenAI’s board abruptly fired Sam Altman, saying he had not been consistently candid; he was reinstated days later after staff revolted.
Countries sign Bletchley Declaration at first global AI Safety Summit
The UK hosted the first global AI Safety Summit at Bletchley Park, where 28 countries and the EU signed a declaration on frontier AI risks.
Amended New York DFS cybersecurity regulation takes effect
Major amendments to New York’s cybersecurity regulation for financial services strengthen governance, MFA and incident reporting.
Online Safety Act and Economic Crime and Corporate Transparency Act become law
Two major UK Acts receive Royal Assent: the Online Safety Act 2023 and the Economic Crime and Corporate Transparency Act 2023.
UK–US data bridge comes into force
UK organisations can now transfer personal data to US organisations certified under the UK Extension to the EU–US Data Privacy Framework.
23andMe user data stolen after credential stuffing attack
Hackers used reused passwords to access 23andMe accounts and scraped ancestry data on about 6.9 million people.