The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]
Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]
The European Commission’s DG CONNECT disclosed nine documents in response to an access-to-documents request, but all were already publicly available resources. No Data Protection Impact Assessment (DPIA), internal privacy-by-design documentation, threat models, or controller-role assessments were released. DG CONNECT stated it does not hold a DPIA, arguing that responsibility lies with the future publisher of […]
AI has evolved from a technology initiative into a board-level strategic and enterprise risk that demands continuous oversight, not periodic reviews. Boards must establish clear governance, accountability, and AI risk appetite while ensuring innovation is balanced with responsible use. Traditional cybersecurity alone is no longer sufficient, organizations must protect AI-driven decision-making, data, identities, and autonomous […]
AI agents are rapidly moving from experiments to core business systems, but governance is struggling to keep pace. 65% of organizations experienced at least one AI agent-related security incident in the past year, making incidents a mainstream operational reality. The biggest impact was exposure or mishandling of sensitive data (61%), followed by operational disruption (43%) […]
Once seen as a prestigious tech leadership role, the CISO position is now plagued by burnout, overwhelming stress, and rising legal accountability. Many CISOs, like George Gerchow, are stepping back or leaving entirely, citing lack of authority, resources, and structural power. Regulatory burdens, personal liability, and constant pressure without clear support are driving high turnover […]
Workshop Data Protectie Volwassenheid Hoe volwassen is de gegevensbescherming en privacy echt binnen uw organisatie? Deze workshop geeft u inzicht in het volwassenheidsniveau van uw AVG compliance en legt op zakelijke wijze uit welke risico’s u loopt Spreker(s) Hans Kortekaas Richauna Ortega Pieter Houwen Omschrijving Met de ingang van de AVG in 2018 zijn er […]
Municipalities will: – Share more structural incidents with each other and with other sectors via the Information Security Service (IBD); – Share an annual incident overview with the IBD, so that a complete insight into threats, trends and developments exists; – Update and adopt their digital incident response plan every year; – Help each other […]

