EY Third-Party Data Breach: 15 Days Inside Helpdesk

EY third-party data breach

EY third-party data breach: attackers spent 15 days inside a support-ticketing platform used by Ernst & Young’s tax practice, walking out with client tax filings, Social Security numbers and financial account data before anyone noticed — the firm’s third vendor-side security failure in under three years. What Happened This EY third-party data breach ran from…

Read More

NIS2 Compliance in Practice: Lessons from Belgium’s First Year

NIS2 compliance

NIS2 compliance has long felt like an approaching deadline rather than a lived reality for many organisations across Europe. That is beginning to change. As member states move from transposition to enforcement, the directive is shifting from policy language to operational impact — altering reporting practices, governance expectations, and supply chain dynamics. Belgium offers one…

Read More

The Value of External Review of Your GDPR Compliance Practices

Compliance is a tricky topic, and that’s especially true in the case of the EU’s flagship data protection law, the GDPR. With 261 pages to navigate, 99 individual articles, 7 principles for data processing, and large fines at stake for breaches, the risk of non-compliance is too high. In-house teams tasked with overseeing GDPR compliance…

Read More