Frameworks tracked in the briefing.
Every framework the briefing maps stories to in plain English. Open a card to see today’s news tagged with the rules your team owns.
HIPAA
US health-data privacy and security law. The Security Rule sets administrative, physical, and technical safeguards for ePHI; the Breach Notification Rule triggers HHS, media, and affected-individual reporting past the 500-record threshold; and the Privacy Rule governs uses and disclosures. Covered entities and business associates are both bound, with BAA chains extending accountability downstream. Attention spikes on ransomware affecting unencrypted ePHI and on a failed risk analysis under 45 CFR 164.308(a)(1)(ii)(A).
PCI-DSS
Payment Card Industry Data Security Standard, currently v4.0. Governs cardholder data inside the cardholder data environment, from point-of-sale to back-office processing. Merchants, processors, acquirers, and QSAs are all in scope, and v4.0 added explicit requirements on script integrity, web redirect hygiene, e-commerce 3DS, and targeted risk analyses. Attention is triggered by skimmer deployment, payment-script tampering, tokenization gaps, and any data-flow change that brings new systems into the CDE.
NIST CSF
NIST Cybersecurity Framework, currently 2.0 with the new Govern function. A voluntary framework that nonetheless becomes de-facto compliance language across many regulators and contract reviewers. Any organization that adopts it is on the hook for the control catalogue (Identify, Protect, Detect, Respond, Recover, plus Govern), and most revised regs (SEC cyber disclosure, NYDFS, HHS HPH proposed rule) now map directly into its subcategories. Attention lands on control gaps in PR.AC access control, DE.CM continuous monitoring, and RS.RP response planning.
GDPR
EU Regulation 2016/679 on personal data protection. Applies extraterritorially to any organization processing EU residents’ data and is enforced by national data-protection authorities with fines that scale to 4% of global turnover. Attention is triggered by cross-border transfer violations (Articles 44/46), deceptive-design consent flows, processor-chain gaps, and breach notifications that miss the 72-hour clock once the controller becomes aware.
NIS2
EU Directive (EU) 2022/2555 on the cybersecurity of essential and important entities, in force across the EU from October 2024. Adds supply-chain duties (Annex I) and management-body accountability (Article 20), with a 24-hour early warning, 72-hour incident notification, and final report cadence to the national CSIRT. Attention is triggered by the sector scope reassignments that followed national transposition, by management cyber hygiene training failures, and by supply-chain incidents at anchor vendors.
DORA
EU Digital Operational Resilience Act for financial services. Drives ICT risk management, a maintained register of ICT third-party contracts, major-incident reporting to the competent authority, and threat-led penetration testing every three years for designated entities. Attention is triggered by gaps in the third-party register, by identified ICT concentration risk, by unresolved major-incident reporting deadlines, and by a failed TLPT cycle.
SEC 8-K
SEC Form 8-K Item 1.05, the US material-cyber-incident disclosure rule for public companies. A four-business-day clock runs from materiality determination, not from incident detection, and the disclosure must describe the nature, scope, timing, and material impact of the incident along with remediation status. Attention is triggered by materiality-scope debates after a partial restoration, by incomplete remediation disclosures, by unnamed executive accountability for the response, and by the parallel discovery of related incidents that may in retrospect be material.