Praeferre/Blog
Praeferre Blog

Practical compliance thinking, not vendor noise.

GRC automation, AI governance, third-party risk, DPO best practice and cyber security — written by the people who build the platform.

Cyber Security

Citrix NetScaler zero-days under attack: a brutal week for the network edge

Citrix confirmed two actively exploited remote code execution flaws in NetScaler ADC and Gateway on 27 September. Five days earlier CISA had flagged exploited flaws in Check Point, Arista and F5 kit. The pattern matters more than any single CVE.

· 3 min read
AI Governance

27 companies breached for $25 a go: AI agents as attack tooling

One operator chained three open-source AI agent frameworks to breach at least 27 organisations in under a week, at an average cost of $25.46 per target. The interesting number is not 27. It is $25.46.

· 3 min read
Third-Party Risk

The payroll app that never existed: a lesson in checking the obvious

Attackers built convincing download pages for desktop clients of three US payroll platforms, each installing legitimate remote access software. The detail that undoes the whole scheme: none of those vendors offers a desktop client.

· 3 min read
Cyber Security

Malware that asks four AI models what to do next

Cisco Talos has documented a Windows implant that queries up to four large language models, takes a vote, and chooses its own next move. It has not been seen deployed in the wild — which makes this the right moment to think about detection.

· 3 min read
Regulatory Updates

Could your tracking IDs stop being personal data? The Council thinks maybe

A Council compromise text on the Digital Omnibus would let pseudonymised data be treated as non-personal by any party unable to re-identify the individual. For advertising identifiers, that is a structural change — and 127 organisations have objected.

· 3 min read
GRC & Compliance

A third of GenAI users are hiding it from their employer

Deloitte UK's survey of 25,000 workers puts numbers on something most compliance teams already suspected. The finding that should worry you is not the third who hide it — it is the £958 million they are spending personally.

· 3 min read
Cyber Security

A WAF rule is not a patch: the PeopleSoft bypass

Attackers linked to ShinyHunters used a simple encoding trick to slip past the web application firewall rules many organisations relied on instead of patching Oracle PeopleSoft. The technique is old. The lesson keeps needing to be relearned.

· 3 min read
Cyber Security

Singapore is using AI to pen test 2,000 government systems. Should you?

Faced with a persistent state-linked threat and thousands of systems, Singapore built AI tooling to automate parts of penetration testing. It is a serious answer to a real problem, and a useful lens on what automation can and cannot replace.

· 3 min read
AI Governance

SalesBleed: when a single untrusted lead can hijack your AI agent

Zenity Labs disclosed three flaws in Salesforce Agentforce that let a single untrusted lead turn a trusted enterprise agent into a data exfiltration and phishing channel. Salesforce fixed them. The design lesson applies to every agent you deploy.

· 3 min read
Regulatory Updates

California wants independent verifiers inside AI companies

California has appointed four experts to advise on an executive order exploring onsite independent verification inside frontier AI companies, third-party verification of safety disclosures and a tested emergency shutoff. The direction of travel matters more than the detail.

· 3 min read
Third-Party Risk

The platform wasn't breached. Your shoppers' data still left.

Attackers used compromised credentials for a third-party app to inject malicious scripts into BigCommerce merchant storefronts and harvest shopper details. BigCommerce's own platform was not breached, which is precisely the problem.

· 3 min read
AI Governance

The AI Act stopped being theoretical: first inspections begin

The European Commission has used its AI Act investigatory powers for the first time, and the AI Office has opened a coordinated inspection wave with 24 national authorities. Three high-risk categories are in scope, and two of them sit in ordinary HR and lending functions.

· 3 min read
GRC & Compliance

The high-risk AI deadline may move. Plan as if it won't.

Proposed changes would delay the AI Act's high-risk obligations by more than a year and loosen the threshold for using special category data in bias testing. Europe's data protection authorities are unimpressed — and delay is a weak basis for a compliance plan.

· 3 min read
Third-Party Risk

Sweden fined the supplier, not its customers. That should get your attention.

Sweden's data protection authority fined an IT supplier used by around 80% of the country's municipalities after a breach affecting 2.2 million people. What the regulator faulted was specific, and it is exactly what most supplier questionnaires never ask about.

· 3 min read
DPO Insights

23.6 million records, 490 million images, and a notification problem

An attacker exploited an upload server to reach Gyazo's backend, taking 23.6 million user records and metadata covering roughly 490 million images. The response was fast. The hard part is telling anonymous users what happened to them.

· 3 min read
AI Governance

Leaked GDPR draft would ease AI training on personal data

Documents published by noyb show EU governments discussing a GDPR change that would make legitimate interest the default route for AI development. It is not law yet, and your AI governance should not wait for it.

· 6 min read
Regulatory Updates

Google’s €403m location data fine: lessons for every controller

Ireland’s Data Protection Commission has fined Google €403 million over how it handled location data. The lessons on transparency, defaults and retention apply far beyond Big Tech.

· 5 min read
DPO Insights

Revolut data theft: when the ‘police request’ is the attack

Attackers claim they obtained data on around 700 Revolut customers by posing as Italian authorities. The weak point was not a firewall but a disclosure process. Here is how to harden yours.

· 5 min read
Regulatory Updates

DPDP cross-border rules aren’t live yet: how to prepare wisely

Contracts are being redrafted as if India’s DPDP cross-border rules already apply. They don’t, yet. Here is what is actually in force, what is coming and how to prepare without over-engineering.

· 5 min read
Third-Party Risk

Brevo supply-chain attack: one leaked key, 100,000 websites

A single hardcoded API key let attackers turn Brevo’s embedded forms and widgets into a malware delivery system for up to 100,000 websites. It is a textbook lesson in fourth-party risk.

· 6 min read
DPO Insights

The ICO becomes the Information Commission on 30 September

The UK data protection regulator moves from a single Commissioner to a board-led Commission on 30 September. The name barely changes, but how decisions are made does.

· 5 min read
Cyber Security

Cisco ISE zero-day (CVE-2026-76460): patch now, then hunt

Cisco has confirmed active exploitation of a maximum-severity flaw in Identity Services Engine, days after another exploited zero-day in its email gateway. Here is what to patch and what to check.

· 5 min read
AI Governance

Humans may read your AI chats. What that means for your data

Reports that contractors review real ChatGPT conversations, and Apple’s new opt-in for Siri training, are a reminder: what employees paste into AI tools may not stay between them and the machine.

· 5 min read
GRC & Compliance

EU Cyber Resilience Act reporting is live: the 24-hour clock

The first binding obligations of the EU Cyber Resilience Act now apply. Manufacturers of hardware and software sold in the EU must report actively exploited vulnerabilities and severe incidents on a 24-hour clock.

· 6 min read
Third-Party Risk

IDScan breach: the hidden risk in outsourced ID checks

Businesses scanned customers’ IDs for good reasons. A breach at their verification provider has left more than 150 million licence records in criminal hands. Here is what it teaches about vendor risk.

· 5 min read
AI Governance

Shadow AI Is Already Inside Your Organisation. Here's What To Do About It.

Your staff are using ChatGPT, Claude and Gemini today, whether or not there's a policy for it. We break down what's actually leaving the building, and the five-step response that works better than a ban.

· 11 min read
Third-Party Risk

DORA's Third-Party Register: What Financial Firms Still Get Wrong

A year into enforcement, the register of information remains the single biggest DORA compliance gap we see. Here's the checklist we use with clients.

· 7 min read
Praeferre signs MoU with SRPOST to advance Responsible AI in Korea
Company News

Praeferre signs MoU with SRPOST to advance Responsible AI in Korea

Praeferre partners with SRPOST via an MoU to strengthen Responsible AI, driving ethical and sustainable AI adoption in Korea.

· 3 min read
Praeferre joins Cyber Runway CNI to strengthen cyber resilience across UK critical national infrastructure
Company News

Praeferre joins Cyber Runway CNI to strengthen cyber resilience across UK critical national infrastructure

Praeferre joins Cyber Runway CNI to strengthen cyber resilience, security and innovation across the UK’s critical national infrastructure.

· 3 min read
Praeferre Wins World Smart City Prize 2025: Advancing Responsible AI for Smarter & Safer Cities
Company News

Praeferre Wins World Smart City Prize 2025: Advancing Responsible AI for Smarter & Safer Cities

Praeferre wins the World Smart City Prize 2025, advancing responsible AI to build smarter, safer and more sustainable cities worldwide.

· 3 min read
Understanding Data Governance: A Key to Unlocking Business Potential
GRC & Compliance

Understanding Data Governance: A Key to Unlocking Business Potential

Learn how data governance helps organisations manage data effectively, improve compliance, build trust and unlock long-term business value.

· 5 min read
Praeferre at RSA Conference USA 2025: Shaping the Future of Cybersecurity
Company News

Praeferre at RSA Conference USA 2025: Shaping the Future of Cybersecurity

Discover Praeferre at RSA Conference USA 2025, shaping the future of cybersecurity with trusted, innovative and responsible security solutions.

· 3 min read
Driving Responsible AI in Global Banking: UK–India Collaboration for a Fair AI Future
AI Governance

Driving Responsible AI in Global Banking: UK–India Collaboration for a Fair AI Future

Explore how UK–India collaboration is shaping responsible AI in global banking, promoting fairness, trust, compliance and sustainable innovation.

· 3 min read
Strengthening Telecom Security: Praeferre Joins UK–India Future Telecom Collaboration
Cyber Security

Strengthening Telecom Security: Praeferre Joins UK–India Future Telecom Collaboration

Praeferre joins the UK–India Future Telecom Collaboration to enhance telecom security, innovation and trusted digital infrastructure.

· 3 min read
Transforming Telecoms: How Centralised Compliance is Reinventing Data Privacy for Telcos
Cyber Security

Transforming Telecoms: How Centralised Compliance is Reinventing Data Privacy for Telcos

Discover how centralised compliance is transforming data privacy in telecoms, helping telcos ensure security, trust and regulatory adherence.

· 3 min read
A Guide on The Data Protection and Digital Information Bill in the United Kingdom
Regulatory Updates

A Guide on The Data Protection and Digital Information Bill in the United Kingdom

Learn what the UK Data Protection and Digital Information Bill means, its key changes, who it affects, and how organisations can prepare.

· 4 min read
Understanding the Core Principles of GDPR
GRC & Compliance

Understanding the Core Principles of GDPR

Learn the core principles of GDPR, including lawfulness, transparency, data rights and accountability, to ensure compliant protection.

· 5 min read
Understanding the CCPA (California Consumer Privacy Act)
Regulatory Updates

Understanding the CCPA (California Consumer Privacy Act)

Learn what the California Consumer Privacy Act is, who it applies to, and how businesses can comply with CCPA requirements effectively.

· 3 min read
Essential Guide to Information Security Management: Safeguarding Digital Assets in a Cyber World
Cyber Security

Essential Guide to Information Security Management: Safeguarding Digital Assets in a Cyber World

Learn how information security management protects digital assets, mitigates cyber risks, ensures compliance, and strengthens organisational resilience.

· 4 min read
Understanding the Fundamental Difference Between Data Privacy and Data Protection
GRC & Compliance

Understanding the Fundamental Difference Between Data Privacy and Data Protection

Understand the difference between data privacy and data protection, why both matter, and how organisations can ensure compliance and trust today

· 3 min read
Praeferre Showcased in Japan During the UK–Japan 5G Trade Mission
Company News

Praeferre Showcased in Japan During the UK–Japan 5G Trade Mission

Praeferre was showcased in Japan during the UK–Japan 5G Trade Mission, highlighting innovation, collaboration and global leadership in technology.

· 3 min read

No articles match your search

Try a different keyword, or clear the category filter.

Don't want to miss an update?

Get one email a month, no spam

Compliance insights worth reading, sent straight to your inbox.