Healthcare Regulation Brief
The HIPAA Security Rule overhaul slipped again, and the 240-day compliance window is the part nobody reads. Where the rule stands and what it will demand.
Read the post →Where audit requirements and actual security diverge, how to read severity scoring honestly, and what evidence an assessor will accept as proof.
22 posts
The HIPAA Security Rule overhaul slipped again, and the 240-day compliance window is the part nobody reads. Where the rule stands and what it will demand.
Read the post →One phishing simulation a year measures a single day with a single pretext. Why cadence beats the annual checkbox, and which metric is worth reporting.
Read the post →Researchers documented JadePuffer, the first known ransomware attack run end to end by an AI agent. What it actually demonstrates, and what it does not.
Read the post →Every supplier you onboard makes their security part of yours. Five questions to ask before handing over a login, an integration, or a copy of your data.
Read the post →Your staff already use AI tools you have not approved, exactly as they once used Dropbox. What is genuinely at risk, and why blocking it does not work.
Read the post →Most breaches are not clever. They come through an unpatched update, an unlocked screen, or an unencrypted disk. Three boring controls that do the work.
Read the post →Test, receive a report, fix the criticals, file the PDF, repeat next year. Why that cycle stopped being good enough, and what retesting should look like.
Read the post →If 95% of your estate is a priority and 32% of it is tested, you do not have a program, you have a bet. Where the gap comes from and how it widens.
Read the post →The annual penetration test satisfied compliance and reassured boards for a decade. The numbers now say that model has been overtaken. What replaces it.
Read the post →Attackers used to give you a month to patch and now give you five days, while regulators remove the choice about testing. What good looks like in 2026.
Read the post →Compliance verifies that controls exist. Security verifies they hold. Here is where the gap opens up, and why breached organizations were often fully certified.
Read the post →Attackers chain low-severity findings into serious compromise. Why severity scores rank issues badly on their own, and what to prioritise instead.
Read the post →CVSS v4 changes how severity is scored, and what your reports will look like. What is new, what improved, and how to read the two versions side by side.
Read the post →The most damaging incidents are quiet ones built for leverage. Five things worth doing this quarter, in the order that reduces the most risk soonest.
Read the post →Data poisoning, adversarial input, prompt injection, and model extraction. The five AI threats worth modelling once AI is embedded in how the business runs.
Read the post →A critical SharePoint flaw let attackers run code with no password at all. What the breach revealed about relying on vendor patches and nothing else.
Read the post →Threats that were theoretical a few years ago are routine now. How the landscape has shifted, and the preparation that survives the next shift too.
Read the post →The TSA’s proposed rule puts pipeline, rail, and bus operators under real cybersecurity obligations. What it asks for, and where testing fits the requirements.
Read the post →Compliance frameworks and penetration testing answer different questions. Where the two meet, and how testing supports a regulatory posture, not replaces it.
Read the post →The Clorox cyberattack cost far more than remediation. Why reputational damage outlasts the incident, and where regular testing changes the outcome.
Read the post →Data privacy is not the same as data security, and the difference matters when regulators ask. What personal data you hold, and the steps to protect it.
Read the post →The OWASP entry nobody notices is missing until an incident, when there is nothing to investigate with. What to log, what to watch, and free tools to start.
Read the post →Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.