If you make or sell digital products in the EU, you must now report all exploited vulnerabilities and โsevereโ incidents that impact their security within 24 hours of becoming aware of them. These rules apply to every sector that produces products with a digital element โ from baby monitors to smart watches and apps.
Cybersecurity
KPMG report urges CCOs to collaborate and invest to boost operational resilience
Enhanced operational resilience is key to improving responses to interconnected cyber, third-party and regulatory risks, according to KPMGโs 2026 chief ethics and compliance officer survey.
OSF Healthcare pays $552,250 for HIPAA violations from ransomware breach
Illinois-based OSF Healthcare System has agreed to pay $552,250 to resolve potential HIPAA violations tied to a 2021 ransomware attack.hea
New code for AI Act compliance will be ‘de facto’ standard, say experts
The European Union has issued updated guidance to help companies better understandโas well as comply withโthe transparency requirements that underpin the blocโs groundbreaking legislation aimed at ensuring safe AI use.
International agents take down major site where criminals traded stolen corporate info
A major online site used by cybercriminals to buy and sell information stolen from corporations and individuals worldwide has been shut down by an international enforcement action, the Department of Justice announced.
An appreciation of CWโs data and research journalist, Aly McDevitt
One of the best things about writing for Compliance Week is reading the fabulous work by my colleagues. For me, CW data and research journalist Aly McDevitt has always stood out as someone whose work in reporting on and writing theย Compliance Weekย case studies is work I have greatly admired.
False Claims Act enforcement themes for 2026
The U.S. Department of Justice touted a record $6.8 billion in False Claims Act (FCA) recoveries in fiscal year 2025, much of that total stems from prior yearsโ cases and does not necessarily reflect the administrationโs current enforcement direction.
Hidden supply-web risks in MSPs and MSSP contracts
Governance failures embedded in standard agreements are amplifying organizationsโ exposure to cyber incidents by failing to account for modern supply-chain realities,ย where third- and fourth-party vendors, cloud platforms, subcontractors create a cascading risk far beyond the contracting entity.
The illusion of control: How shrinking teams and AI are redefining cyber risk
Over recent years, cybersecurity executives have been tasked with an almost impossibleย Challenge: reduce headcount, accelerate transformation, integrate artificial intelligence,ย meet regulatory obligations, and still maintain resilience.
Compliance must prepare for post-quantum cryptography requirements in contracts
While companies focus on the risks, opportunities, and regulations emerging around AI, the next tech challenge is already on the horizon. Quantum computers are here โ and so are the associated crime risks, plus some encryption protections.ย


