GRC Report Staff

LastPass Fined £1.2 Million After UK Data Breach Exposes 1.6 Million Users

The UK Information Commissioner’s Office (ICO) has fined password manager provider LastPass £1.2 million following a 2022 data breach that exposed the personal information of up to 1.6 million UK users, concluding that the company failed to implement sufficiently robust security measures despite offering a service designed to improve online security.

ISSB Updates Climate Disclosure Standard to Address Early Implementation Challenges

The International Sustainability Standards Board released targeted amendments to its IFRS S2 Climate-related Disclosures standard, responding to practical challenges companies have encountered as they begin putting the new climate rules into practice.

Swiss Competition Authority Probes Apple’s NFC Access Terms on iPhones

Swiss competition authorities have opened an investigation into Apple’s control over near-field communication technology on iPhones, examining whether the company’s terms for granting access to the NFC interface raise concerns under Swiss antitrust law.

FCA Slaps Nationwide With £44 Million Fine After Prolonged AML Failures

Nationwide Building Society has been hit with a £44 million fine after the UK’s financial watchdog found that long-standing weaknesses in its financial crime controls left it exposed to money laundering risks for years.

DORA Reshapes Cyber Testing as Italy Updates TIBER-IT Guide

Italy’s financial regulators are updating the rulebook on how banks, insurers, and other financial institutions stress-test their cyber defenses, as the EU’s Digital Operational Resilience Act moves from theory to day-to-day supervision.

Trump Executive Order Seeks to Rein in State AI Laws, Drawing Pushback From States & Lawmakers

President Donald Trump recently signed a sweeping executive order aimed at curbing state-level regulation of artificial intelligence, framing the move as necessary to preserve U.S. competitiveness and prevent what the administration describes as a fragmented and burdensome regulatory landscape.

Bupa Ordered to Pay $23.3 Million After Court Finds Years of Misleading Conduct

‍Bupa has been ordered to pay $23.3 million (AUD $35 million) after the Federal Court found the health insurer misled thousands of members, and even hospitals and medical providers, about what their private health policies actually covered. The ruling caps off a years-long stretch of incorrect claims decisions that, in many cases, left members believing they had no entitlements at all when parts of their treatment were in fact covered.