Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The EU Cyber Resilience Act Has Global Implications - Who Needs to Prepare and How?

The European Union has made great strides to enhance cybersecurity over the past few years, with a comprehensive framework of core legislative acts designed to protect critical infrastructure. The EU Cyber Resilience Act, originally published as Regulation (EU) 2024/2847 on 20 November 2024, and entered into force on 10 December 2024, shifts the burden of proof so that manufacturers must now show their software is secure, not just claim it.

Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached

Computers are not safe. Even the best hardware and software products have the potential to conceal as-yet unknown vulnerabilities. And they aren’t all made that well. Many are shuffled into the world without a plan to detect, remediate, and notify users of those vulnerabilities. The EU’s Cyber Resilience Act aims to improve that situation.

December 2026 Is Closer Than You Think: What the UK's Defence Cyber Directive Means for Your Organisation

The UK’s Ministry of Defence has sent a clear message to organisations within the Defence supply chain. By 31 December 2026, all Defence industry partners are expected to achieve Defence Cyber Certification (DCC) Level 0, including Cyber Essentials for all applicable business-critical systems within scope. This represents a significant step in strengthening cyber resilience across the Defence ecosystem and raising the baseline for cyber security throughout the UK’s supply chain.

Cross-Border Data Transfer Under India's DPDPA

Businesses operating across countries routinely move personal data between India and overseas systems. Customer information may be stored by a global cloud provider, employee records may be accessed by an international headquarters, or an Indian business may use SaaS platforms whose infrastructure is located outside the country.

Data Retention Policy Under the DPDP Act: How Long You Can Keep Data and When to Delete It

How long should an organization keep personal data? Under the DPDP Act, the answer is not simply one year, three years, or any other fixed period. The right retention period depends on why the data was collected, whether that purpose still exists, and whether another law requires the organization to keep it.