Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

IT Security & Privacy

TikTok Drops Appeals and Accepts £12.7 Million UK Children’s Privacy Fine

TikTok has agreed to pay a £12.7 million fine imposed by the Information Commissioner’s Office in 2023 after the company dropped two appeals against the UK’s data protection regulator, bringing one long-running children’s privacy case to an end and allowing another to move forward.. TikTok has separately abandoned its challenge to an information notice seeking documents and details about how it processes teenagers’ personal information through its recommender systems. The first case reaches back to TikTok’s handling of children under 13, who were not supposed to be on the platform in the first place.

New Zealand Privacy Commissioner Orders Security Fixes After Manage My Health Cyberattack

New Zealand’s Privacy Commissioner has ordered Manage My Health and Health New Zealand to strengthen their handling of patient data, nine months after a cyberattack exposed weaknesses in the systems meant to protect some of the country’s most sensitive personal information. Commissioner Michael Webster issued separate compliance notices to the two organizations on September 23, following the first phase of his investigation into the December 2025 Manage My Health cyber incident. The inquiry found that, at the time of the attack, both organizations had failed to comply with security requirements under Rule 5 of the Health Information Privacy Code.

KPMG Survey Finds Cyberattacks Rising as CISOs Grapple With AI & Complexity

Cyberattacks increased at 83% of large U.S. organizations over the past year, according to a recent KPMG survey, even as companies poured more money into artificial intelligence and expanded the responsibilities of the executives charged with keeping their systems secure.

Irish DPC Fines Google €403 Million Over Location Data Processing

Ireland’s Data Protection Commission has fined Google €403 million over its processing of location data, concluding an investigation that began in 2020 and reached back to the first day the GDPR took effect.

CISA Turns to Cyber Decoys to Catch Attackers Inside Critical Infrastructure Networks

An attacker who has stolen legitimate credentials and learned to use the tools already sitting inside a network can be remarkably difficult to spot. There may be no conspicuous malware announcing the intrusion, no obviously malicious account and, for a time, little to distinguish the attacker from someone who belongs there. CISA wants critical infrastructure operators to give such intruders something they cannot safely touch.

Revolut Disclosed Customer Data After Fraudulent Government Requests

Revolut handed sensitive customer records to an unauthorized third party after receiving fraudulent information requests that came from the legitimate email domain of a government agency, the British fintech confirmed to TechCrunch.

EU Cyber Resilience Act Reporting Requirements Take Effect

For manufacturers selling connected products and software in the European Union, one of the Cyber Resilience Act’s first deadlines has arrived. Beginning September 11, manufacturers must report actively exploited vulnerabilities and severe incidents that affect the security of their products. The requirement reaches across the enormous category the EU calls “products with digital elements,” covering hardware and software from baby monitors and smartwatches to applications and computer programs.