Recent changes
Friday, March 13, 2026
Data Broker Registration Fee Regulations
The California Privacy Protection Agency (CPPA) is now responsible for the state's data broker registry, effective January 1, 2024. Data brokers must pay an annual registration fee, which the CPPA may adjust. Final regulations for the fee structure have been published for 2024, 2025, and 2026 registrations.
Accessible Deletion Mechanism for Data Brokers
The California Privacy Protection Agency has finalized regulations establishing an Accessible Deletion Mechanism (DROP) for data brokers, effective January 1, 2026. This system allows consumers to request the deletion of their personal information from registered data brokers through a single request to the agency.
ENISA Report: EU Public Administrations Targeted by DDoS Attacks
ENISA has released a report detailing that EU public administrations are increasingly targeted by cyberattacks, primarily DDoS attacks, with central governments being the most affected. The report analyzes 586 incidents from 2024 and highlights the sector's developing cybersecurity resilience under the NIS2 Directive.
ENISA Report: Cybersecurity Investments and NIS2 Challenges
ENISA's 6th NIS Investments report reveals a shift in cybersecurity spending from personnel to technology and services across 1080 EU organizations. The report highlights persistent talent shortages and challenges in implementing the NIS2 Directive, despite compliance being a key investment driver.
ENISA Cybersecurity Exercise Methodology Guidance
ENISA has released a new cybersecurity exercise methodology to guide organizations in planning and executing effective cybersecurity exercises. The methodology provides a framework for simulating cyber crises, training response capabilities, and building resilience against cyber threats.
ENISA Seeks Feedback on Software Supply Chain Security Guidance
ENISA has launched public consultations on draft guidance for software supply chain security. Feedback is sought on an SBOM Landscape Analysis and a Technical Advisory for Secure Use of Package Managers, with a deadline of January 23, 2026.
ENISA Updates International Cybersecurity Strategy
ENISA has updated its International Strategy to enhance engagement with international partners and align with the EU's cybersecurity policies. The revised strategy focuses on cooperation with countries sharing EU values and includes specific working arrangements with Ukraine and the US, support for EU candidate countries, and operationalizing the EU Cybersecurity Reserve for third countries.
Joint Advisory on SD-WAN Appliance Exploitation
The NSA, CISA, and international cybersecurity agencies have issued a joint advisory regarding the exploitation of Cisco SD-WAN appliances. Threat actors are exploiting a specific vulnerability (CVE-2026-20127) to gain root access and establish persistence. The advisory includes a threat hunt guide and mitigation recommendations.
NIST CSF 2.0 Cybersecurity Risk Management Guidance
The National Institute of Standards and Technology (NIST) has released version 2.0 of its Cybersecurity Framework (CSF). This updated guidance provides a comprehensive taxonomy for organizations of all sizes and sectors to manage cybersecurity risks, offering a flexible approach to assessing and communicating cybersecurity efforts.
NIST Cybersecurity Framework 2.0 Implementation Resources
The National Institute of Standards and Technology (NIST) has released quick start guides and implementation resources for the Cybersecurity Framework (CSF) 2.0. These resources aim to help organizations of all sizes, including small businesses, understand and implement the updated framework.
Last 7 days
Most active sources
Browse Categories
Activity
Get daily alerts
Morning digest delivered to your inbox. Free.
Free. Unsubscribe anytime.
59 monitored sources
Regs.gov: Privacy and Civil Liberties Oversight Board
Regs.gov: Cybersecurity and Infrastructure Security Agency
Regs.gov: Information Security Oversight Office
Regs.gov: Office of the National Cyber Director
Get Data Privacy & Cybersecurity alerts
Daily digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get Data Privacy & Cybersecurity alerts
We'll email you when new data privacy & cybersecurity changes are detected.