News & insights
The latest news, insights, and updates on information & cyber security, privacy, and AI governance from Taylor Baines.
Get the latest threats, vulnerabilities, and legal, standards, and AI updates in your inbox every Monday.
Get our weekly insights by emailSouth Africa’s financial sector cyber resilience standard takes effect
Joint Standard 2 of 2024 now applies to South African financial institutions, setting principle-based cybersecurity and cyber resilience requirements.
US TAKE IT DOWN Act signed into law
The US has criminalised publishing non-consensual intimate imagery, including AI deepfakes, and given platforms one year to set up removal processes.
Japan enacts Active Cyber Defense Act
Japan enacts its Active Cyber Defense Act, requiring critical infrastructure operators to report incidents and share information.
Software Security Code of Practice published
A new UK code sets baseline security expectations for software vendors.
TikTok fined EUR 530m over transfers of European user data to China
Ireland’s Data Protection Commission fines TikTok EUR 530 million over transfers of EEA users’ data to China and a lack of transparency.
Cyber Essentials update: the Willow question set
Updated Cyber Essentials requirements and the new Willow question set apply to assessments from today.
Cyber attack on Marks & Spencer halts online orders for weeks
A cyber attack on Marks & Spencer, followed by attacks on Co-op and Harrods, leads to weeks of disruption and four arrests by the NCA.
US DOJ Data Security Program comes into force
New US rules restricting access to bulk sensitive personal data by countries of concern take effect, with further obligations from October 2025.
Cyber Governance Code of Practice published for boards
The UK Government has published a Cyber Governance Code of Practice setting out what boards and directors should do to govern cyber risk.
Switzerland makes cyber attack reporting mandatory for critical infrastructure
Swiss critical infrastructure operators must now report cyber attacks to the National Cyber Security Centre within 24 hours.
PCI DSS v4.0 future-dated requirements become mandatory
The future-dated requirements in PCI DSS v4.0 become mandatory, including targeted risk analyses, wider MFA and payment page script controls.
UK operational resilience deadline arrives
UK financial firms must now be able to remain within impact tolerances for their important business services.