GRC Report Staff

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.

DOJ, EPA Reach Proposed $125 Million Agreement to Advance Lower Passaic River Cleanup

The Justice Department and Environmental Protection Agency have reached a proposed agreement requiring Environmental Resource Holdings to perform an estimated $125 million in work intended to move the long-running cleanup of New Jersey’s Lower Passaic River toward construction.

Canada’s Privacy Commissioner Sets New Expectations for Third-Party Privacy Due Diligence

Privacy Commissioner of Canada, Philippe Dufresne, released new guidance for organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), laying out how businesses should assess the privacy practices of prospective third-party service providers. The guidance applies when an outside product, service, or technology will involve the collection, use, or disclosure of personal information, whether the provider is processing information directly, supplying technology that handles it, or working somewhere further down the chain.

Deloitte Finds Cyber Confidence Is Outpacing Readiness

Deloitte’s latest global cybersecurity survey begins with a number most CISOs would probably be pleased to see. Eighty-five percent of respondents say they are somewhat or very confident in their organization’s cybersecurity strategy.

Dompé U.S. to Pay $32 Million Over Medicare Co-Pay Kickbacks

Dompé has agreed to pay $32 million to resolve allegations that it used patient assistance foundations to cover Medicare beneficiaries’ co-pays for Oxervate, its prescription drug, turning what appeared to be charitable assistance into what federal authorities alleged were unlawful inducements to purchase the company’s product.

Ofcom Opens Enforcement Push on Illegal Intimate Images & AI Deepfakes

Online platforms operating under the UK’s online safety regime have until the end of September to show they can stop illegal intimate images from spreading. Ofcom is no longer waiting for the deadline to find out whether they are ready.

HelmGuard Raises $7.3 Million to Build Continuous Risk Assurance With AI Agents

HelmGuard has raised $7.3 million in seed funding to expand its AI-driven approach to governance, risk and compliance, as the company looks to replace some of the questionnaires and periodic document reviews that still underpin corporate risk assurance with agents capable of examining evidence directly.