Hacker Summer Camp wrapped up last week. Black Hat USA 2026 ran August 1-6 at Mandalay Bay, DEF CON 34 followed August 6-9 at the Las Vegas Convention Center, and somewhere north of 50,000 security professionals spent the better part of two weeks in 105-degree heat talking about the things that are going to show…
August 2 came and went. If you spent the last several months building toward that deadline, here’s the update you may have missed: the EU AI Act’s high-risk AI system requirements are no longer due August 2, 2026. On May 7, 2026, EU lawmakers reached political agreement on revisions to the AI Act, pushing the…
August 2 is five days from when this publishes. That’s the date the EU AI Act’s major provisions — including the full requirements for high-risk AI systems — become applicable. If you’ve been tracking it as an upcoming deadline, it’s no longer upcoming. We covered the strategic overview in April. This post is for the…
July 1 brought another wave of state privacy law changes into effect. If your compliance calendar had these flagged, this is the time to confirm your program is actually operational — not just documented. If you didn’t have them flagged, here’s what you need to know. We covered the broader state privacy landscape in the…
If your organization has been tracking state privacy legislation as a “watch and monitor” item, that posture is overdue for a change. Twenty states now have comprehensive consumer privacy laws in effect. Three more — Connecticut, Arkansas, and Utah — have significant updates or new provisions taking effect July 1, 2026. That’s thirty days from…
For years, CISA served as a meaningful resource for organizations outside the enterprise security tier — threat intelligence sharing, incident response support, vulnerability advisories, regional coordination, and cybersecurity assessments available at no cost to critical infrastructure operators and public sector entities. That resource base has eroded significantly, and the organizations that haven’t adjusted their programs…
The Cyber Incident Reporting for Critical Infrastructure Act has been in a holding pattern since CISA missed its original October 2025 deadline. The final rule is now expected in May 2026. If you’ve been treating CIRCIA as a future problem, that window is closing fast. RSA This post isn’t about what CIRCIA says in theory.…
The conflict between the United States and Iran that began on February 28, 2026 moved into the cyber domain almost immediately. If you’ve been watching it as a geopolitical story and not a security operations story, it’s time to adjust your perspective. This isn’t abstract nation-state activity happening at the edges of critical infrastructure. On…
Every year on March 31st, the security community celebrates World Backup Day. Vendors tweet reminders. IT teams run awareness campaigns. Someone in marketing makes a clever graphic about the 3-2-1 rule. And every year, organizations that had backups still lose everything to ransomware. That’s because we’ve been celebrating the wrong thing. We’ve been celebrating the…
Forty-three thousand people. Six hundred exhibitors. Thirty-one session tracks. Hugh Jackman somehow closing out the week at the Moscone Center. That’s RSAC 2026 in a sentence — massive, loud, and relentlessly marketed at from every direction. If you attended, you’re probably still recovering from the badge lanyard tan lines and the booth swag guilt. If…