The Digital Omnibus postponed high-risk rules, not training. What the AI Act requires on AI literacy for staff, and since when it is supervised.
The Digital Omnibus postponed high-risk rules, not training. What the AI Act requires on AI literacy for staff, and since when it is supervised.
DORA has applied since January 2025 and there is no official register of covered entities. Who DORA applies to, who falls outside, and what it asks of people.
Spain’s National Security Framework (ENS) treats staff awareness and training as auditable security measures. What mp.per.3 and mp.per.4 require and how to evidence them.
Control 6.3 of ISO 27001:2022 turns awareness into an auditable control. What it requires, what changed since 2013, and how you prove it in an audit.
Germany launched IT spotlight inspections over AI risks in the financial sector. Regulation looks at the system. Attackers look at the people.
Blocking ChatGPT doesn’t stop Shadow AI. How to design the channels so generative AI use happens where your organization has visibility.
In today’s context, talking about regulatory compliance is no longer an exclusive matter for the legal or compliance department. Organizations, regardless of the sector they belong to, are increasingly exposed […]
Our CEO, Mauro Graziosi, was recently interviewed by the prestigious magazine Forbes in an article that covers a key topic for the future of cybersecurity: “People are the first line […]