Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

IT Security & Privacy

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health New Zealand to strengthen their handling of patient data, nine months after a cyberattack exposed weaknesses in the systems meant to protect some of the country’s most sensitive personal information. Commissioner Michael Webster issued separate compliance notices to the two organizations on September 23, following the first phase of his investigation into the December 2025 Manage My Health cyber incident. The inquiry found that, at the time of the attack, both organizations had failed to comply with security requirements under Rule 5 of the Health Information Privacy Code.

KPMG Survey Finds Cyberattacks Rising as CISOs Grapple With AI & Complexity

Cyberattacks increased at 83% of large U.S. organizations over the past year, according to a recent KPMG survey, even as companies poured more money into artificial intelligence and expanded the responsibilities of the executives charged with keeping their systems secure.

Irish DPC Fines Google €403 Million Over Location Data Processing

Ireland’s Data Protection Commission has fined Google €403 million over its processing of location data, concluding an investigation that began in 2020 and reached back to the first day the GDPR took effect.

CISA Turns to Cyber Decoys to Catch Attackers Inside Critical Infrastructure Networks

An attacker who has stolen legitimate credentials and learned to use the tools already sitting inside a network can be remarkably difficult to spot. There may be no conspicuous malware announcing the intrusion, no obviously malicious account and, for a time, little to distinguish the attacker from someone who belongs there. CISA wants critical infrastructure operators to give such intruders something they cannot safely touch.

Revolut Disclosed Customer Data After Fraudulent Government Requests

Revolut handed sensitive customer records to an unauthorized third party after receiving fraudulent information requests that came from the legitimate email domain of a government agency, the British fintech confirmed to TechCrunch.

EU Cyber Resilience Act Reporting Requirements Take Effect

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.

Italian Privacy Regulator Fines BBVA €5.5 Million Over Unwanted Marketing Messages

Italy’s Data Protection Authority has fined Banco Bilbao Vizcaya Argentaria Italia (BBVA) more than €5.5 million after finding that the bank continued sending promotional messages to a customer who had objected to receiving them, an enforcement action that exposed wider problems in how the bank managed privacy requests across its systems.