Tag: Trends and Insights
-

Norway’s BankID outage shows what DORA-grade third-party risk management actually requires
Read more: Norway’s BankID outage shows what DORA-grade third-party risk management actually requiresFor 2 days, millions of Norwegians couldn’t sign a contract, complete a house sale or access a health record because a single supplier’s infrastructure failed for the second time in 5 years. What happens when an entire country’s digital ID depends on a single supplier? On the morning of 3 September 2026, a real estate agent in…
-

The CareCloud data breach: a third-party risk warning for healthcare compliance teams
Read more: The CareCloud data breach: a third-party risk warning for healthcare compliance teamsKey takeaways Introduction: the changing face of a healthcare data hack In early August 2026, patients of various US healthcare providers began opening data breach notifications from a company many had never heard of: CareCloud, the cloud-based electronic health record and billing platform their doctor’s office quietly ran in the background. The letter said their…
-

Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enough
Read more: Lombard Odier’s money-laundering conviction shows why flagging a compliance risk isn’t enoughKey takeaways Introduction: failure to go beyond filing a risk report leads to an AML conviction In 2012, a Geneva private bank, Lombard Odier, noticed unusual activity connected to one relationship manager’s client accounts and reported their suspicions to Switzerland’s Money Laundering Reporting Office. 14 years of legal process, and one collapsed prosecution against the alleged ringleader, later, Switzerland’s Federal Criminal Court…
-

Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chart
Read more: Coca-Cola’s Fairlife ransomware attack: why risk doesn’t respect the org chartKey takeaways How Fairlife’s cyberattack became a group governance issue On July 16, 2026, Coca-Cola disclosed that Fairlife, its dairy business, had detected unauthorized access to a section of its network, including production-linked systems. Production at Fairlife’s 4 US factories stopped. Canadian production continued. Product on shelves stayed safe. A ransomware-as-a-service group calling itself Anubis claimed responsibility, saying it had taken 1 terabyte of data and threatening to leak it. According to…
-

The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhere
Read more: The EU delayed its AI Act deadline: what the Digital Omnibus means for AI governance everywhereKey takeaways Introduction: the AI compliance deadline GRC teams have been racing toward just moved For eighteen months, “2 August 2026” has been a fixed point on the calendar for compliance, risk and AI governance teams across Europe, and well beyond. This was the date the EU AI Act’s toughest obligations, covering high-risk AI systems, were due to bite: conformity assessments, technical…
-

When the US government switched off AI: what the Anthropic shutdown means for your GRC program
Read more: When the US government switched off AI: what the Anthropic shutdown means for your GRC programKey takeaways Introduction: for many businesses the lights went out when the US government enforced AI restrictions Picture this: it’s the morning of 13 June 2026 and the compliance team at a mid-sized, European financial services business opens their AI-assisted regulatory monitoring tool – the one they recently rolled out, that surfaces horizon risk items and flags policy changes across five jurisdictions. It is offline, with no warning email, no estimated time of restoration and, critically, no fallback. …
-

8 risk and compliance leaders to follow and learn from on LinkedIn
Read more: 8 risk and compliance leaders to follow and learn from on LinkedInWe’re shining a spotlight on the people shaping the future of governance, risk and compliance. LinkedIn is one of the best places to find real conversations about risk leadership, compliance culture, internal audit, AI governance, operational resilience and the future of GRC. In this blog, we’ve curated 8 GRC leaders worth following on LinkedIn. Their work spans: From established analysts and community…
-

The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from this
Read more: The Novo Nordisk breach shows cyber extortion now targets far more than personal data – what risk and compliance leaders can learn from thisKey takeaways What happened at Novo Nordisk? Reuters reported that cyber extortion group FulcrumSec claimed it spent more than 2 months inside Novo Nordisk’s network and stole more than 700,000 files, equal to roughly 1.3 terabytes of data. The group also claimed Novo Nordisk refused to pay a $25m extortion demand. Reuters said it could not immediately verify the authenticity of the data…
-

World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?
Read more: World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?Key takeaways Introduction: What happened at the 2026 World Cup? Days before the World Cup began, a supplier issue at one of the tournament’s highest-profile venues was narrowly avoided. Reuters reported that a union representing around 2,000 food and beverage workers at SoFi Stadium reached a tentative agreement with Legends Hospitality only days before the tournament. AP described the agreement as averting a…
-

Recent Bank of England warning and why AI-driven cyber threats are now a top concern for banking regulators globally
Read more: Recent Bank of England warning and why AI-driven cyber threats are now a top concern for banking regulators globallyKey takeaways Introduction: Is AI changing the cyber threat environment faster than organizations can respond? AI is not only a technology that organizations need to govern internally. It is also reshaping the external cyber threat environment. Used well, AI can help teams detect vulnerabilities, strengthen defenses and respond to incidents more quickly. However, the same capabilities can create new attack…