All Intelligence

Policy

Security policy changes, regulatory updates, and compliance-relevant developments.

117 items

informationalPolicyActive

UK Cyber Policy Continuity Under Labour: Strategic Retention of Lloyd Signals Institutional Stability

The UK's new Prime Minister Keir Starmer has retained Liz Lloyd in a cyber policy role despite dissolving her previous ministry, indicating continuity in national cyber governance rather than substantive policy change. This retention of a key Starmer ally in a reduced capacity suggests cyber remains a government priority whilst undergoing organisational restructuring.

informationalPolicyActive

CISA 2015 Information-Sharing Framework Extended by a Decade in Congressional Defence Bill

The US House of Representatives has approved a 10-year renewal of the Cybersecurity Information Sharing Act (CISA 2015) as part of the fiscal 2027 National Defence Authorisation Act. This extends protections for voluntary threat intelligence sharing between private sector organisations and government agencies.

US private sector organisations, CISA, US federal cybersecurity programmes
highPolicyActive

OT vulnerability disclosure dilemma: balancing safety against transparency in legacy industrial systems

SecurityWeek examines the structural tension in operational technology security where legacy systems, safety dependencies, and critical infrastructure protection create barriers to standard vulnerability disclosure practices. The piece highlights how OT environments differ fundamentally from IT, complicating the security research and patching ecosystem.

OT systems broadly, legacy industrial control systems
highPolicyEmerging

US-Canada surveillance legislation dispute highlights encryption backdoor risks in Five Eyes alliance

Senator Ron Wyden opposes Canada's proposed lawful access legislation, arguing it would repurpose US technology infrastructure for surveillance and set a dangerous precedent. The dispute reflects ongoing tensions within the Five Eyes alliance over encryption backdoors and government access capabilities.

US technology infrastructure providers, Canadian telecommunications operators
informationalPolicyEmerging

Gold Eagle: US government centralises AI-driven vulnerability coordination across critical infrastructure

The Trump administration has launched Gold Eagle, a clearinghouse programme that uses artificial intelligence to help industry and government detect, prioritise and remediate cybersecurity vulnerabilities at scale. This represents a significant policy shift toward centralised vulnerability intelligence sharing.

Critical infrastructure operators, US government agencies, Private sector industry participants
highPolicyActive

US prosecutes Russian bulletproof hosting operators: infrastructure enablers face indictment

The US Department of Justice has unsealed charges against alleged operators of Media Land and ML Cloud, St. Petersburg-based companies accused of providing hosting infrastructure and technical support specifically to cybercriminals. This represents a significant enforcement action targeting the operational backbone of organised cybercrime.

Cybercriminals using bulletproof hosting services
informationalPolicyEmerging

EU age-gating proposal targets social media access for under-13s: regulatory shift with implementation challenges

The European Commission is proposing a regulatory framework to restrict social media access for children under 13, representing a significant policy shift toward age verification and platform accountability. This marks a move beyond current self-regulatory approaches but faces substantial technical and enforcement barriers.

Meta, TikTok, Snapchat +3
informationalPolicyResolved

U.S. Supreme Court mandates warrant requirement for geofence data, reshaping law enforcement digital surveillance

The U.S. Supreme Court ruled that police must obtain a warrant before accessing geofence location data from cellphones, extending Fourth Amendment protections to digital tracking. This represents a significant legal victory for privacy advocates and establishes new constraints on law enforcement digital surveillance practices.

Law enforcement agencies, Technology companies storing location data, Mobile carriers
highPolicyActive

Bulgarian Export Licensing Enabled Surveillance Tool Sales to Authoritarian Regimes

Human Rights Watch obtained Bulgarian export records showing the government approved surveillance technology exports by firm Circles to law enforcement and intelligence agencies in countries with documented human rights abuse records between 2018 and 2023. This represents a systemic compliance failure in export controls for dual-use surveillance capabilities.

Circles (surveillance firm), Bulgarian government export licensing authority
highPolicyResolved

Insider threat severity: imprisoned former IT employee's sustained sabotage campaign exposes school district access controls failure

A former Iowa school district IT employee received a 21-month prison sentence for conducting a prolonged cyberattack against the district after employment termination, causing operational disruption, account deletion, and significant financial damage. The case underscores systemic failures in access revocation and post-employment security procedures.

Iowa school district
highPolicyContained

Maine's breach notification portal hijacked by fake disclosures, exposing governance gaps in public security infrastructure

Maine's public data breach notification portal was taken offline after attackers published fraudulent breach disclosures on the state website, highlighting inadequate access controls and verification procedures in government reporting systems that citizens rely on for authentic security information.

Maine state government data breach notification portal
informationalPolicyEmerging

EU Tech Sovereignty Push: Regulatory Framework to Reduce US and Chinese Semiconductor Dependency

The EU has announced a legislative package comprising Chips Act 2.0, Cloud and AI Development Act, open-source strategy, and energy digitalisation roadmap aimed at reducing technological reliance on US and Chinese suppliers. This represents a strategic shift toward supply-chain resilience and domestic capability development.

Semiconductor industry, Cloud service providers, AI vendors +1
informationalPolicyActive

White House AI Executive Order Signals Federal Governance Framework with Security-First Data Access Controls

The White House has issued a pared-back executive order on AI that establishes confidentiality, cybersecurity, and intellectual property safeguards for federal access to AI models. This represents a policy shift toward managed risk rather than comprehensive regulation, with direct implications for how government agencies will interact with commercial and internal AI systems.

U.S. federal government agencies, AI model providers
highPolicyActive

NVD Backlog Crisis Doubles in One Year: NIST's Vulnerability Database Losing Credibility

NIST's National Vulnerability Database has fallen critically behind in processing new vulnerabilities, with unprocessed items doubling from 13,000 to 27,000 between February 2024 and end of 2025, according to an inspector general report. This operational failure directly undermines the NVD's utility as the primary source of truth for vulnerability data across the security industry.

National Vulnerability Database (NVD), NIST, Security industry dependency on NVD
mediumPolicyActive

FTC enforcement action reveals widespread non-compliance with Take It Down Act among major platforms

The FTC has issued warning letters to 12 major technology firms for allegedly failing to comply with the Take It Down Act, which requires platforms to provide accessible removal mechanisms for nonconsensual intimate imagery and process deletion requests within 48 hours. This represents the first significant enforcement action under the statute and signals regulatory intent to hold platforms accountable for abuse prevention infrastructure.

12 major technology companies (specific names not provided in source)
highPolicyResolved

Systemic gap in romance scam victim support reveals coordination failure across institutions

Romance scam victims face fragmented support systems with limited coordination between law enforcement, financial institutions, and government agencies, leaving victims isolated and vulnerable to repeated exploitation. This policy gap demands institutional reform to create unified victim assistance pathways.

Law enforcement agencies, Financial institutions, Government support services
criticalPolicyResolved

Non-human Identity Sprawl: The Unmonitored Credential Crisis Behind 68% of Cloud Breaches

Unmanaged service accounts, API keys, and orphaned credentials represent the largest attack surface in cloud environments, with compromised non-human identities responsible for nearly 7 in 10 cloud breaches in 2024. Organisations typically lack visibility into 40-50 automated credentials per employee that persist after project termination or staff departure.

Enterprise cloud deployments across AWS, Azure, GCP
informationalPolicyResolved

AI pricing escalation: OpenAI's $100 Pro tier signals intensifying LLM market consolidation and potential security implications for enterprise adoption

OpenAI has launched a $100 monthly Pro subscription tier matching Anthropic's Claude pricing, reflecting competitive pressure in the generative AI market. This pricing escalation may influence how organisations evaluate AI tool security postures and dependency risks.

OpenAI, Anthropic, Enterprise organisations adopting generative AI
highPolicyResolved

Google's 2029 PQC Migration Deadline: Crypto-Agility Crisis Looming for Enterprise Infrastructure

Google has committed to migrating its infrastructure to post-quantum cryptography by 2029, signalling that the cryptographically-relevant quantum computer threat window is closing faster than many organisations anticipated. This accelerates industry pressure to inventory and remediate legacy systems before quantum capabilities render current encryption obsolete.

Google, Enterprise organisations dependent on Google Cloud, Organisations using TLS/PKI infrastructure
criticalPolicyResolved

Microsoft Exchange Online servicewide outage reveals continued reliability concerns in critical communication infrastructure

Microsoft Exchange Online experienced a widespread outage blocking mailbox and calendar access for customers globally. This incident underscores the operational risks of cloud-based email dependencies and the cascading business impact when a single provider experiences infrastructure failures.

Microsoft Exchange Online, Microsoft 365 subscribers
informationalPolicyResolved

Android 17 Accessibility API Restrictions: Proactive Defense Against Malware Abuse of System Privileges

Google is implementing API restrictions in Android 17 to prevent non-accessibility apps from abusing the accessibility services API, a common malware technique for achieving privileged operations without proper permissions. This is a preventive security hardening measure rather than a response to active exploitation.

Android 17, Android Advanced Protection Mode (AAPM)