Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

IT Security & Privacy

South Korea Fines GS Retail $9.5 Million After Breaches Expose Data of More Than 1.6 Million People

South Korea’s Personal Information Protection Commission has imposed an approximately $9.47 million (KRW 12.836 billion) administrative monetary penalty on GS Retail, finding that the company failed to put adequate protections in place against cyberattacks and, after discovering the first breach, failed to respond adequately enough to prevent what followed.

Honeywell Aerospace to Pay $2 Million to Settle Cybersecurity False Claims Act Allegations

Honeywell Aerospace has agreed to pay more than $2 million to settle allegations that a business unit failed to meet cybersecurity requirements attached to a U.S. Department of Defense contract, turning what might otherwise have remained a problem of technical compliance into a False Claims Act case.

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Case

TikTok and its parent company ByteDance have agreed to pay $400 million to settle a U.S. government lawsuit alleging the platform collected personal information from millions of children without their parents' consent, according to BBC reporting, closing a case that began two years ago and adding another substantial figure to the growing cost of getting children's privacy wrong.

Ofcom Sets Out Enforcement Approach as UK Online Safety Regime Takes Hold

Ofcom has set out how it plans to enforce the UK’s Online Safety Act across more than 100,000 companies, detailing an approach that can begin with guidance and direct regulatory pressure but escalate to investigations, fines and, in certain cases, measures that disrupt a company’s business.

Cyberattack Exposes Data of 8.7 Million Customers at Three Major UK Airports

Manchester Airports Group said criminal hackers accessed data belonging to about 8.7 million customers in a cyberattack affecting systems used across Manchester, London Stansted and East Midlands airports, one of the largest breaches of customer information disclosed by a UK airport operator.

CISA Red Team Tests Expose a Divide in How Security Teams Respond to Intrusions

At one critical infrastructure organization, CISA’s red team got in and kept going. It compromised multiple workstations, elevated its privileges over the domain and began moving laterally into other systems and resources. The security operations center never detected it.

Uber Faces €825 Million Fine Over Automated Driver Deactivations in French-Dutch GDPR Case

Uber’s software could cut a driver off from the platform for suspected fraud or poor customer ratings. What it did not necessarily do first was ask a person. That has now cost the company €824.99 million.