Poland's Cyber Five: proposals that could reshape health-data protection
The ministry proposes supplier certification, minimum safeguards, patient alerts and new duties for large-scale health-data processors.
Risk management, NIS2, DORA, GDPR and organisational practices that turn requirements into operating controls, ownership and measurable improvement.
The ministry proposes supplier certification, minimum safeguards, patient alerts and new duties for large-scale health-data processors.
Essential and important entities have until 3 October to apply for Poland's KSC register. Here is what to verify and what comes next.
Reporting duties for actively exploited vulnerabilities and severe product incidents are already in force through ENISA's new platform.
BCX found no evidence of live production compromise but continues to assess legacy information. It is a practical lesson in test data and retention.
The FTC is considering new platform duties for impersonation ads. It is not a final rule, but it matters to consumers, brands and advertisers now.
The EU approved a code for AI-generated content transparency. Learn what AI Act Article 50 requires from 2 August and how companies should prepare.
EASM discovers unknown domains, IPs, cloud and services. Build a repeatable process for discovery, ownership, risk prioritisation and remediation.
The amended KSC act implements NIS2 and applies from 3 April 2026. We explain who it covers, the deadlines and what you need to do.
DORA has applied since January 2025 and covers far more than banks. The five pillars, mandatory resilience testing and ICT supplier duties.
Employees use several times more applications than IT has approved. Where shadow IT comes from, what it risks and how to control it without bans.
'Appropriate technical measures' — but which exactly? GDPR Article 32 as an IT checklist: encryption, access, logs, backups and testing.
A small company doesn't need a security department to stop being an easy target. A 90-day plan: what to do in-house, what to buy, what to outsource.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.