A new ENISA-focused discussion puts the Software Bill of Materials in a different light: not as paperwork, but as a control that can shape supply-chain visibility, governance, and regulatory readiness.
The EU cybersecurity agency is being positioned deeper into the CVE workflow, a coordination change that matters even more if frontier AI keeps accelerating disclosure pressure.
A newly posted victim name can sharpen urgency for defenders, yet the verified record here is limited to a public claim naming Prenisac.
A sparse extortion post names Prenisac, adds a hash, and leaves the target website as N/D, limiting certainty while still demanding verification.
New EU guidance is pushing the Cyber Resilience Act from legal principle to engineering practice, with product inventories, lifecycle support, and vulnerability reporting moving to the center of compliance.
ENISA’s healthcare procurement guidance turns a quiet paperwork step into a security decision that can shape the resilience of clinics, hospitals, and their suppliers.
ENISA's draft consultation on managed security services could shape how the EU measures trust, quality, and readiness in a market that often sells assurance more than proof.
ENISA’s new healthcare procurement guidance turns purchasing into a cyber control point, while a €6 million contribution agreement signals longer-term EU backing for the sector.
A 2026 reporting deadline under the Cyber Resilience Act turns product security into an operational race, not a distant compliance exercise.
ISACs show how cybersecurity becomes stronger when organizations share intelligence inside a trusted sector boundary rather than in isolation.
The European Commission’s new action plan treats AI security as an operational resilience problem, not just a policy debate, with critical infrastructure at the center of the frame.
The EU is stitching AI governance, product security, and critical-infrastructure resilience into one policy stack, and that has practical consequences for vendors and defenders alike.
Brussels is moving toward a controlled testing regime for advanced AI models, pairing secure evaluation with structured access and institutional oversight.
From 11 September 2026, the Cyber Resilience Act introduces a mandatory reporting path for exploited vulnerabilities and incidents, and the centralized design raises its own security questions.
ENISA’s Cyber Europe 2026 exercise tested how rail and maritime systems might hold together when cross-border disruption, coordination, and recovery matter as much as technical defense.
New adoption signals point to rising SBOM investment, but the harder problem is turning inventories into live, machine-readable security data before regulatory deadlines bite.
A proposed overhaul would give ENISA a more operational role, with early warnings, vulnerability tracking, and a budget increase that signals a tougher EU cyber posture.
EU ministers are set to review a proposed cyber package centered on ENISA, NIS2 simplification, and supply-chain security, with the real challenge lying in whether governance can become clearer without becoming weaker.
ENISA’s latest NIS360 assessment shows uneven cyber maturity across NIS2 sectors, with some infrastructures moving ahead while others remain stuck in a mismatch between importance and resilience.
ENISA’s latest NIS360 assessment points to gradual gains in cybersecurity maturity across high-criticality sectors, while leaving enough unevenness to keep systemic risk on the table.