A planned intelligence services law would require the BSI to report previously unknown security vulnerabilities to the BND — a practice that cybersecurity experts view critically.
NIS2 requires critical infrastructures and large digital service providers to implement comprehensive security management with strict deadlines and liability risks for executives.
The CISO is evolving from a technology specialist into a strategic business executive with personal liability, paralleling the CFO’s evolution over the past two decades.
Enterprises with 50 or more employees must establish information security management systems under NIS2, report incidents to authorities, and provide documented evidence of their measures.
The Northern Thuringia region shows a high percentage of companies that have not yet met NIS2 requirements – the Chamber of Industry and Commerce warns of impending consequences.
The NIS2 Directive penalizes risk management violations with fines up to €10 million and requires organizations to implement documented, structured cybersecurity risk management.
With the expiration of the NIS2 implementation deadline, penalty provisions enter into force that impose multi-million euro fines for non-compliant companies.
Anthropic splits Claude Fable 5 into a public version (with safeguards) and a restrictive version (Claude Mythos 5 without security layers) for verified cybersecurity experts.
The NIST backlog results from strategic deficits and duplicate structures with CISA, with both agencies operating parallel vulnerability enrichment programs since May 2024 and wasting approximately $200,000 in funds.