<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Compliance</title><description>Cybersecurity articles tagged #Compliance on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>UK Cyber Security and Resilience Bill Targets High-Risk Vendors</title><link>https://runtimerebel.com/blog/uk-cyber-security-and-resilience-bill-targets-high-risk-vendors</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-security-and-resilience-bill-targets-high-risk-vendors</guid><description>The UK amends its Cyber Security and Resilience Bill to grant ministers powers to block high-risk technology suppliers from critical infrastructure.</description><pubDate>Wed, 02 Sep 2026 19:07:21 GMT</pubDate><category>Supply Chain Attack</category><category>Critical Infrastructure</category><category>Compliance</category><category>Cyber Security and Resilience Bill</category></item><item><title>Strategic Security: Aligning CISO Goals with Business Outcomes</title><link>https://runtimerebel.com/blog/strategic-security-aligning-ciso-goals-with-business-outcomes</link><guid isPermaLink="true">https://runtimerebel.com/blog/strategic-security-aligning-ciso-goals-with-business-outcomes</guid><description>CISOs face a double standard, hired for technical expertise but judged on business growth and customer trust.</description><pubDate>Mon, 24 Aug 2026 16:26:17 GMT</pubDate><category>Cybersecurity Leadership</category><category>Business Alignment</category><category>Risk Management</category><category>Compliance</category><category>CISO</category></item><item><title>CMMC Compliance: Confidence Rises, Proof Lags for DoD Contractors</title><link>https://runtimerebel.com/blog/cmmc-compliance-confidence-rises-proof-lags-for-dod-contractors</link><guid isPermaLink="true">https://runtimerebel.com/blog/cmmc-compliance-confidence-rises-proof-lags-for-dod-contractors</guid><description>DoD contractors report higher confidence in CMMC compliance, yet struggle to provide verifiable proof, leading to legal and contract risks.</description><pubDate>Mon, 24 Aug 2026 00:42:31 GMT</pubDate><category>Supply Chain Security</category><category>Compliance</category><category>CMMC</category><category>DFARS</category><category>DoD</category></item><item><title>Shadow AI: Managing Emerging Cybersecurity Risks in the Enterprise</title><link>https://runtimerebel.com/blog/shadow-ai-managing-emerging-cybersecurity-risks-in-the-enterprise</link><guid isPermaLink="true">https://runtimerebel.com/blog/shadow-ai-managing-emerging-cybersecurity-risks-in-the-enterprise</guid><description>Organizations face new data governance and compliance challenges from unsanctioned AI tool use, demanding proactive identification and management.</description><pubDate>Fri, 21 Aug 2026 08:34:16 GMT</pubDate><category>Shadow AI</category><category>AI Security</category><category>Data Governance</category><category>Risk Management</category><category>Compliance</category></item><item><title>Cloudflare Achieves FedRAMP High Status for Government</title><link>https://runtimerebel.com/blog/cloudflare-achieves-fedramp-high-status-for-government</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloudflare-achieves-fedramp-high-status-for-government</guid><description>Cloudflare for Government achieves FedRAMP Class D (High) certification, enabling federal agencies to secure the nation&apos;s most sensitive unclassified data.</description><pubDate>Mon, 10 Aug 2026 16:47:50 GMT</pubDate><category>Cloudflare</category><category>Compliance</category><category>Cloud Security</category><category>FedRAMP</category><category>Government</category></item><item><title>Outdated Cybercrime Laws Threaten Security Researchers</title><link>https://runtimerebel.com/blog/outdated-cybercrime-laws-threaten-security-researchers</link><guid isPermaLink="true">https://runtimerebel.com/blog/outdated-cybercrime-laws-threaten-security-researchers</guid><description>Outdated cybercrime laws endanger ethical hackers, creating legal risks that stifle critical vulnerability research.</description><pubDate>Mon, 10 Aug 2026 16:46:01 GMT</pubDate><category>Ethical Hacking</category><category>Policy</category><category>Compliance</category><category>Cybercrime Laws</category><category>Security Research</category></item><item><title>Effective Compliance: Prioritizing Foundational Questions</title><link>https://runtimerebel.com/blog/effective-compliance-prioritizing-foundational-questions</link><guid isPermaLink="true">https://runtimerebel.com/blog/effective-compliance-prioritizing-foundational-questions</guid><description>Discover why adaptable, question-based compliance programs outperform rigid, extensive frameworks in addressing evolving cybersecurity risks and regulatory changes.</description><pubDate>Thu, 30 Jul 2026 17:31:25 GMT</pubDate><category>Compliance</category><category>Cybersecurity Frameworks</category><category>Risk Management</category><category>Security Strategy</category><category>Governance</category><category>Adaptive Security</category></item><item><title>US Export Controls &amp; Frontier AI: Securing Volatile Models</title><link>https://runtimerebel.com/blog/us-export-controls-frontier-ai-securing-volatile-models</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-export-controls-frontier-ai-securing-volatile-models</guid><description>Explore the implications of US export controls on frontier AI models, highlighting regulatory uncertainty and strategies for security leaders to manage AI as a volatile…</description><pubDate>Wed, 15 Jul 2026 17:24:06 GMT</pubDate><category>AI Regulation</category><category>Export Controls</category><category>Frontier AI</category><category>AI Security Strategy</category><category>Compliance</category></item><item><title>Google&apos;s €4.1B EU Fine Stands: Android Antitrust Implications</title><link>https://runtimerebel.com/blog/google-s-eur4-1b-eu-fine-stands-android-antitrust-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-s-eur4-1b-eu-fine-stands-android-antitrust-implications</guid><description>Google loses final appeal against its €4.1 billion EU antitrust fine concerning Android&apos;s dominance. Understand the compliance implications for tech giants.</description><pubDate>Thu, 02 Jul 2026 17:54:31 GMT</pubDate><category>Google</category><category>Android</category><category>EU</category><category>Antitrust</category><category>Compliance</category><category>Regulatory</category><category>CJEU</category><category>Competition Law</category></item><item><title>Quantifind Secures Funding for AI-Native Risk Intelligence Expansion</title><link>https://runtimerebel.com/blog/quantifind-secures-funding-for-ai-native-risk-intelligence-expansion</link><guid isPermaLink="true">https://runtimerebel.com/blog/quantifind-secures-funding-for-ai-native-risk-intelligence-expansion</guid><description>Quantifind&apos;s $200M funding will accelerate its AI-native risk intelligence platform, enhancing capabilities for financial crime detection and compliance globally.</description><pubDate>Tue, 30 Jun 2026 09:19:36 GMT</pubDate><category>AI Native Risk Intelligence</category><category>Financial Crime</category><category>Compliance</category><category>Machine Learning</category><category>Fraud Detection</category><category>Sanctions Screening</category></item><item><title>Automating GRC: AI Agents for Continuous Control Monitoring</title><link>https://runtimerebel.com/blog/automating-grc-ai-agents-for-continuous-control-monitoring</link><guid isPermaLink="true">https://runtimerebel.com/blog/automating-grc-ai-agents-for-continuous-control-monitoring</guid><description>Explore how AI agents can automate GRC functions, continuously monitor controls, identify evidence gaps, and streamline remediation tasks for enhanced security…</description><pubDate>Fri, 26 Jun 2026 16:48:07 GMT</pubDate><category>GRC</category><category>AI</category><category>Automation</category><category>Compliance</category><category>Security Controls</category></item><item><title>Data Sovereignty Challenges: Geopolitical Tensions &amp; EU Residency Implications</title><link>https://runtimerebel.com/blog/data-sovereignty-challenges-geopolitical-tensions-eu-residency-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/data-sovereignty-challenges-geopolitical-tensions-eu-residency-implications</guid><description>Explore the growing imperative for data sovereignty, driven by geopolitical tensions, and how EU data residency options address evolving compliance requirements.</description><pubDate>Thu, 04 Jun 2026 20:47:40 GMT</pubDate><category>Data Sovereignty</category><category>Data Residency</category><category>EU Data Regulations</category><category>GDPR</category><category>Geopolitical Risk</category><category>Compliance</category></item><item><title>Asia&apos;s Emerging Cyber Insurance Market: Strategic Risk Transfer for Security Leaders</title><link>https://runtimerebel.com/blog/asia-s-emerging-cyber-insurance-market-strategic-risk-transfer-for-security-leaders</link><guid isPermaLink="true">https://runtimerebel.com/blog/asia-s-emerging-cyber-insurance-market-strategic-risk-transfer-for-security-leaders</guid><description>Explore the dynamics of Asia&apos;s burgeoning cyber insurance market, its impact on risk management, and how security professionals can leverage evolving policies.</description><pubDate>Fri, 29 May 2026 17:21:20 GMT</pubDate><category>Cyber Insurance</category><category>Asia</category><category>Risk Management</category><category>Compliance</category><category>Financial Risk</category></item><item><title>Beyond Checkbox Compliance: True Cyber Risk Measurement</title><link>https://runtimerebel.com/blog/beyond-checkbox-compliance-true-cyber-risk-measurement</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-checkbox-compliance-true-cyber-risk-measurement</guid><description>Traditional checkbox assessments fail to measure dynamic cyber risk. Explore modern approaches to security governance and continuous risk management.</description><pubDate>Thu, 14 May 2026 00:56:17 GMT</pubDate><category>Risk Management</category><category>Security Assessment</category><category>Compliance</category><category>Cyber Governance</category><category>Audit</category></item><item><title>Addressing Shadow AI Risks: A Governance and Visibility Imperative</title><link>https://runtimerebel.com/blog/addressing-shadow-ai-risks-a-governance-and-visibility-imperative</link><guid isPermaLink="true">https://runtimerebel.com/blog/addressing-shadow-ai-risks-a-governance-and-visibility-imperative</guid><description>Enterprises face growing risks from unmanaged AI tool usage. This analysis details Shadow AI threats, compliance challenges, and crucial governance strategies.</description><pubDate>Sat, 18 Apr 2026 00:41:16 GMT</pubDate><category>Shadow AI</category><category>AI Governance</category><category>Enterprise AI</category><category>Data Security</category><category>Compliance</category></item><item><title>OT Cryptographic Readiness: Addressing the PQC Attestation Gap</title><link>https://runtimerebel.com/blog/ot-cryptographic-readiness-addressing-the-pqc-attestation-gap</link><guid isPermaLink="true">https://runtimerebel.com/blog/ot-cryptographic-readiness-addressing-the-pqc-attestation-gap</guid><description>OT asset owners struggle to meet regulatory PQC attestation requirements due to a lack of visibility tools, creating a false sense of security in ICS environments.</description><pubDate>Mon, 13 Apr 2026 20:26:06 GMT</pubDate><category>ICS Security</category><category>OT Security</category><category>Post Quantum Cryptography</category><category>Compliance</category><category>PQC</category></item><item><title>Federal Evaluators Flag Microsoft Cloud Security Documentation</title><link>https://runtimerebel.com/blog/federal-evaluators-flag-microsoft-cloud-security-documentation</link><guid isPermaLink="true">https://runtimerebel.com/blog/federal-evaluators-flag-microsoft-cloud-security-documentation</guid><description>U.S. federal evaluators expressed a &apos;lack of confidence&apos; in Microsoft&apos;s cloud security posture due to insufficient documentation, despite approval.</description><pubDate>Thu, 09 Apr 2026 12:48:24 GMT</pubDate><category>Microsoft Cloud</category><category>Cloud Security</category><category>Federal Government</category><category>Security Documentation</category><category>Compliance</category></item><item><title>Mitigating Shadow AI Risks: Data Leaks from AI Browsers</title><link>https://runtimerebel.com/blog/mitigating-shadow-ai-risks-data-leaks-from-ai-browsers</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-shadow-ai-risks-data-leaks-from-ai-browsers</guid><description>Banning AI browsers leads to &apos;Shadow AI&apos; and uncontrolled data exposure. Learn to implement controlled enablement and robust governance to prevent data leakage.</description><pubDate>Tue, 03 Mar 2026 20:13:32 GMT</pubDate><category>Shadow AI</category><category>AI Browsers</category><category>Data Exfiltration</category><category>Compliance</category><category>Governance</category><category>Data Security</category><category>Risk Management</category></item><item><title>UK ICO Fines Reddit £14.47M Over Children&apos;s Data Privacy Failures</title><link>https://runtimerebel.com/blog/uk-ico-fines-reddit-ps14-47m-over-children-s-data-privacy-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-ico-fines-reddit-ps14-47m-over-children-s-data-privacy-failures</guid><description>The UK ICO fined Reddit $19.5 million for processing data of 1.5 million children without parental consent, citing systemic age verification failures.</description><pubDate>Tue, 24 Feb 2026 16:28:54 GMT</pubDate><category>Reddit</category><category>ICO</category><category>UK GDPR</category><category>Data Privacy</category><category>Age Verification</category><category>Compliance</category></item></channel></rss>