Cybersecurity
Post-Quantum Cryptography: A Practical Guide
A key benefit of quantum computing is that it may, in the future, enable a very substantial increase in computing power. This could create significant benefits, in the life sciences and financial services sectors (see our prior posts on the potential implications for these sectors here and here). However, it also creates potential risks. In particular, it could lead to the breaking of many of the encryption methods currently used by governments and businesses alike. As commercially-viable quantum computers become an increasing reality, organisations must prioritise “quantum readiness” and specifically migration to post-quantum cryptography (“PQC”).
In this post, we set out a brief overview of the main steps that regulators and industry bodies (including the U.S. National Institute of Standards and Technology (“NIST”), the UK National Cyber Security Centre (“NCSC”), and the EU Agency for Cybersecurity (“ENISA”)) have indicated businesses should take to move towards PQC and protect their data and systems from the risks posed by quantum computing.
Continue Reading Post-Quantum Cryptography: A Practical GuideENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gap
On May 28, 2026, the European Union Agency for Cybersecurity (“ENISA”) published the third edition of its NIS360 report, an annual benchmarking tool that assesses the cybersecurity maturity of entities in the sectors set out in Annex I of the NIS2 Directive (which includes certain entities in the energy, transport, healthcare, digital…
Continue Reading ENISA’s NIS360 2026 report highlights both the criticality of the European space sector, and flags a persistent cybersecurity maturity gapWhite House Releases Executive Order on Advanced AI Innovation and Security
In a new post on Inside Privacy, our colleagues discuss the White House’s issuance of an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security.” The order reflects the Administration’s policy of advancing U.S. leadership in AI while addressing national security risks, including through measures to strengthen government and private-sector cybersecurity…
Continue Reading White House Releases Executive Order on Advanced AI Innovation and SecurityEU Tech Sovereignty Package
On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.
The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.
This blog post provides an initial, high-level overview of the four initiatives through which the Commission seeks to advance a “European way” to tech sovereignty, with potential implications for industrial ecosystems in Europe and beyond, including cloud, telecoms, automotive, aeronautics, and defense sectors.
Continue Reading EU Tech Sovereignty PackageFCC Seeks Comment on Petition to Update Ultra-Wideband (UWB) Part 15 Rules
As consumers have embraced “smart home” technology and specifically advanced locks and entryway security systems, some door lock companies have asked permission from the Federal Communications Commission (“FCC”) to use ultra-wideband technology (“UWB”) in their devices. UWB technology has unique characteristics that can be used to enhance entryway security systems by working with low-power Bluetooth…
Continue Reading FCC Seeks Comment on Petition to Update Ultra-Wideband (UWB) Part 15 RulesFCC Opens Application Window for New Cyber Trust Mark Program Lead Administrator
On January 6, 2026, the Federal Communications Commission’s Public Safety and Homeland Security Bureau (the “Bureau”) announced the application window for a new Lead Administrator for the U.S. Cyber Trust Mark Program (the “Program”). The window will be open from January 7, 2026, through January 28, 2026. The previous Lead Administrator, UL LLC (“UL…
Continue Reading FCC Opens Application Window for New Cyber Trust Mark Program Lead AdministratorFive major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill
As the UK Government has recognized, cyber incidents—such as Jaguar Land Rover, Marks and Spencer, Royal Mail and the British Library—are costing UK businesses billions annually and causing severe disruption. The Government recognizes that cybersecurity is a critical enabler of economic growth (“we cannot have growth without stability”), and that the current laws have “fallen out of date and are insufficient to tackle the cyber threats faced by the UK.” Accordingly the UK Government this week published its long-awaited Cyber Security and Resilience Bill (the “Bill”), which will amend the existing Network and Information Systems Regulations 2018 (the “NIS Regulations”), and grant new powers to regulators and the Government in relation to cybersecurity.
The NIS Regulations are the UK’s pre-Brexit implementation of Directive (EU) 2016/1148 (the “NIS Directive”), which established a “horizontal” cybersecurity regulatory framework covering essential services in five sectors (transport, energy, drinking water, health, and digital infrastructure) and some digital services (online marketplaces, online search engines, and cloud computing services). EU legislators replaced NIS Directive in 2022 with the “NIS2” Directive, which Member States were meant to transpose into national law by October of last year (although many are still late in doing so. See our post on NIS2 here for an overview of the requirements of NIS2).
The Bill is the UK’s effort at modernizing the framework originally set out in the NIS Directive. In its current form, the Bill will:
- Significantly expand the scope of the NIS Regulations—to cover, among other things, data centers and managed service providers—and impose additional substantive obligations on covered organizations.
- Increase potential fines—up to GBP 17m or 4% of the worldwide turnover of an undertaking—and extend the powers of competent authorities to share information with one another, issue guidance, and take enforcement action.
- Establish a framework for future changes to the NIS Regulations, mechanisms for competent authorities to impose specific cybersecurity requirements on covered organizations, and greater Government direction of cybersecurity matters.
Below, we set out further detail on five major changes in UK cybersecurity regulation arising from the Bill.
Continue Reading Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience BillICO Fines Capita £14 Million Over 2023 Data Breach
In a new post on the Inside Privacy blog, our colleagues discuss a recent £14 million fine imposed by the UK Information Commissioner’s Office against Capita following a data breach caused by a cyber attack.
Continue Reading ICO Fines Capita £14 Million Over 2023 Data BreachCalifornia Governor Signs Landmark AI Safety Legislation
On September 29, California Governor Gavin Newsom (D) signed into law SB 53, the Transparency in Frontier Artificial Intelligence Act (“TFAIA”), establishing public safety regulations for developers of “frontier models,” or large foundation AI models trained using massive amounts of computing power. TFAIA is the first frontier model safety legislation in the country to…
Continue Reading California Governor Signs Landmark AI Safety Legislation