What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
NIS-2 Implementation in Germany: What Management Boards Need to Know in 2026
Germany's NIS2UmsuCG tightens BSIG duties for essential and important entities, with personal management liability, a staggered incident-reporting clock, and a vastly expanded sector catalogue. An overview for boards and managing directors.
ISO/IEC 27001:2022, Transition From 2013 and What Must Happen by October 2026
The transition window to ISO/IEC 27001:2022 has closed. Certifications still running on the 2013 version lost their validity on 31 October 2025. A structured look at the new controls, themes, and the non-negotiable re-certification on the current standard.
EU AI Act: Compliance Obligations for Enterprises From August 2026
On 2 August 2026, the main application date of Regulation (EU) 2024/1689 kicks in. Any organisation that develops, distributes or deploys high-risk AI needs a risk-management system under Art. 9, data governance under Art. 10 and human oversight under Art. 14, and AI-literacy training for every employee working with AI.