All Briefs
20 dispatches on cyber law, data protection, and the incidents that keep reshaping both. Filter by category or read the docket in order.
The Docket
From Phishing Email to Wire Transfer: How Modern Social Engineering Actually Works
Arup and M&S look like different kinds of attacks on the surface — one a deepfake video call, one a ransomware breach. Underneath, they follow the same three-stage anatomy.
The EU AI Act's High-Risk Deadline, and the Fight to Delay It
August 2026 was supposed to be the date the AI Act's toughest obligations landed. A year of negotiation over the Digital Omnibus has left that date in genuine doubt.
Scattered Spider, DragonForce, and the Rise of Ransomware-as-a-Service
The group behind the M&S attack doesn't write its own ransomware. It rents it — and the platform it rents from offers affiliates an 80% cut.
DORA Turns Real: What 2026 Enforcement Actually Means for Financial Institutions
The grace period for the EU's operational resilience regulation ended in 2025. This is the year supervisors stopped reviewing paperwork and started demanding proof.
Deepfakes Are a Legal Problem, Not Just a Technical One
The Arup fraud and cases like it are usually filed under cybersecurity. The harder questions they raise — evidentiary standards, corporate liability, verification duties — belong to lawyers as much as engineers.
Why India's New Turnover-Based Licensing Rules Reshaped an Entire Compliance Industry
A regulation change most consumers will never hear about quietly emptied out one of India's largest small-business licensing markets, overnight.
Seven Years, Over €7 Billion: What GDPR Enforcement Actually Looks Like in 2026
The regulation just passed another grim milestone in cumulative fines. The more interesting number is who is paying, and who is winning on appeal.
When a Fine Gets Overturned: The Amazon Annulment and Why Process Still Matters
A €746 million penalty being struck down on procedural grounds is not a defeat for GDPR — it's a reminder that even privacy regulators have to follow their own rulebook.
Consent Managers, Explained: India's New Middlemen in Data Protection
From November 2026, a new category of registered intermediary starts managing consent between individuals and the businesses that process their data. It has no close precedent in Indian law.
The UK's Data (Use and Access) Act: A Quieter Departure from GDPR
Royal Assent in June 2025 started a year of staged changes to UK data law. None of them are dramatic individually. Together, they mark the UK's first real divergence from the EU regime it inherited.
TikTok's €530 Million Lesson: Why Cross-Border Transfers Are GDPR's Real Fault Line
The Irish DPC's penalty against TikTok confirms that moving European data to China, or anywhere outside the bloc, is now the single most expensive mistake a platform can make.
GDPR Meets the AI Act: Two Regulations, One Compliance Headache
A model can be perfectly GDPR-compliant on training data and still fail the AI Act's transparency rules. Organisations building on AI now have to satisfy both regimes at once.
The EU Just Put Amazon and Google Under Financial Regulation. Here's Why.
DORA's designation of 19 'critical' ICT providers marks the first time cloud infrastructure companies have been brought under direct EU financial supervision.
India's DPDP Rules Are Finally Here — and the Clock to May 2027 Is Running
After two years of waiting since the Act received presidential assent, the Digital Personal Data Protection Rules were notified in November 2025. Here is what actually starts, and when.
The Children's Data Problem: What Instagram and TikTok's Fines Actually Found
Two of the largest GDPR penalties on record both trace back to the same failure — child accounts that were public by default.
Four Arrests, One Ransomware Crew: What They Signal for Cybercrime Enforcement
The UK's National Crime Agency arrested four individuals connected to the M&S, Co-op, and Harrods attacks. That is progress — and also a reminder of how rarely arrests happen at all.
Inside the M&S Ransomware Attack: How One Phone Call Cost £300 Million
The breach that shut down Marks & Spencer's online ordering for 46 days did not start with a software vulnerability. It started with someone calling a help desk and asking nicely.
The Co-op and Harrods Attacks: Why Regulators Called This 'One Combined Cyber Event'
Three major UK retailers were hit within weeks of each other in 2025. A new independent body had to decide whether that was coincidence or coordination.
The $25 Million Video Call: Inside the Arup Deepfake Fraud
A finance employee joined a video call with his CFO and several colleagues, and authorised fifteen wire transfers. None of the people on that call were real.
Prohibited by Law: What the EU AI Act Actually Bans
Long before the high-risk rules arrive, a shorter list of AI practices became flatly illegal in the EU from February 2025. Most compliance conversations skip past what's already banned.