GRC Report Staff

DORA Reshapes Cyber Testing as Italy Updates TIBER-IT Guide

Italy’s financial regulators are updating the rulebook on how banks, insurers, and other financial institutions stress-test their cyber defenses, as the EU’s Digital Operational Resilience Act moves from theory to day-to-day supervision.

Trump Executive Order Seeks to Rein in State AI Laws, Drawing Pushback From States & Lawmakers

President Donald Trump recently signed a sweeping executive order aimed at curbing state-level regulation of artificial intelligence, framing the move as necessary to preserve U.S. competitiveness and prevent what the administration describes as a fragmented and burdensome regulatory landscape.

Bupa Ordered to Pay $23.3 Million After Court Finds Years of Misleading Conduct

‍Bupa has been ordered to pay $23.3 million (AUD $35 million) after the Federal Court found the health insurer misled thousands of members, and even hospitals and medical providers, about what their private health policies actually covered. The ruling caps off a years-long stretch of incorrect claims decisions that, in many cases, left members believing they had no entitlements at all when parts of their treatment were in fact covered.

OCC Publishes Early Assessment of Debanking Conduct at Top Banks

The Office of the Comptroller of the Currency (OCC) on Wednesday released findings from its ongoing review of debanking activities at the nine largest national banks under its supervision. The review is examining whether the institutions restricted access to financial services for customers based on political or religious beliefs or lawful business activities, as directed by the President’s Executive Order Guaranteeing Fair Banking for All Americans.

EFG Bank Faces $1.39 Million Penalty After Hong Kong Regulators Flag Years of Due Diligence Failures

EFG Bank is facing a $1.39 million (HK$10.85 million) penalty after Hong Kong regulators found years of weaknesses in its product due diligence, record-keeping, and reporting practices. The reprimand and fine, announced jointly by the Securities and Futures Commission (SFC) and the Hong Kong Monetary Authority (HKMA), mark another example of how closely the two regulators now coordinate when internal control failures come to light.

Coupang Leadership Shifts After Major Data Breach Unsettles South Korea

Coupang is facing one of the most consequential cybersecurity crises in South Korea’s recent history, prompting Chief Executive Park Dae-jun to resign as the company works to contain the fallout, the Wall Street Journal first reported.

Paxful Hit with $3.5 Million FinCEN Penalty After Facilitating Suspicious Transactions

FinCEN has handed down a $3.5 million civil money penalty to Paxful after the peer-to-peer crypto marketplace admitted it willfully violated the Bank Secrecy Act, enabling more than $500 million in suspicious transactions involving sanctioned jurisdictions and illicit actors.