Privacy & Cybersecurity #81
ENISA Secure-by-Design Playbook | EU Commission CRA Guide | EU Commission AI Transparency Update | NCSC Recovery Guide for SMEs | Italy Implements the AI Act | NIST Warns on Post-Quantum Cryptography
August 2, 2026
🇪🇺 ENISA Publishes Secure by Design and Default Playbook for SME Software and Device Manufacturers
On 30 July 2026, the European Union Agency for Cybersecurity (ENISA) published its Secure by Design and Default Playbook, a guide for small and medium-sized manufacturers developing products with digital elements. The guidance is designed to help implement the security requirements of Cyber Resilience Act (CRA) by embedding security in the product life cycle.
The document translates security principles from ENISA guidance, NIST and OWASP into practices that can be incorporated into development processes. The playbook follows the product life cycle and identifies 22 practical playbooks covering areas such as:
threat modelling;
least privilege;
strong identity and authentication;
attack surface minimization;
defense in depth;
secure coding and verification;
vulnerability and patch management;
supply chain controls;
secure default configurations;
automated updates;
incident response and recovery.
ENISA emphasizes on “security evidence by design.” The report encourages organizations to move towards machine-processable attestations - machine-readable evidence demonstrating that security controls have been implemented and automatically verified during development and deployment.
Manufacturers are encouraged to generate cryptographically verifiable evidence directly from CI/CD pipelines, automated testing and build systems. Such attestations could be used to demonstrate implementation of security controls, support technical documentation required under the Cyber Resilience Act, and enable automated verification by customers, auditors and regulators.
🇪🇺 European Commission Publishes Guidance for Cyber Resilience Act Implementation
On 27 July 2026, the European Commission published guidance on the application of the Cyber Resilience Act (CRA). The guidance is intended to facilitate timely implementation of the CRA before its main obligations become applicable on 11 December 2027, while reminding businesses that the Act’s vulnerability and incident reporting obligations will already apply from 11 September 2026.
The guidance explains how the Commission interprets key provisions of the Regulation and how organizations should apply them in practice.
The guidance addresses several areas, including:
when products fall within the scope of the CRA, including products relying on remote data processing solutions and certain categories of free and open-source software;
what constitutes a “substantial modification” that may trigger renewed conformity assessment obligations;
how manufacturers should determine and communicate the required support period for products with digital elements;
practical approaches to cybersecurity risk assessments; and
compliance with the CRA’s vulnerability and incident reporting obligations.
The Commission states that the guidance includes 67 practical examples, together with flowcharts, diagrams and use cases intended to help microenterprises and SMEs understand how the legal requirements apply to real-world situations.
🇪🇺 European Commission Updates AI Act Transparency Guidance Ahead of New Compliance Deadline
The European Commission published updated implementation materials designed to help organizations comply with the new transparency requirements. The package includes a Commission Communication and revised guidance addressing practical questions raised during stakeholder consultations.
The updated guidance clarifies several aspects of the transparency regime, including:
when AI systems fall within the scope of Article 50;
how providers and deployers should implement transparency notices;
expectations for labeling AI-generated and manipulated content;
practical examples illustrating compliance in different scenarios; and
additional implementation support through flowcharts, use cases and explanatory diagrams. T
The AI Act’s transparency obligations apply from 2 August 2026.
For more information read our previous material European Commission Publishes AI Act Transparency Guidelines.
🇬🇧UK NCSC Publishes Guidance on Recovering from Highly Disruptive Cyber Attacks
The UK National Cyber Security Centre (NCSC) has published guidance, What to do when cyber attacks disrupt your organization. The guidance addresses the full lifecycle of organizational recovery, from the first hours after an attack through long-term rebuilding and resilience.
The NCSC frames recovery as an enterprise-wide management program involving governance, legal, communications, finance, HR, and operational functions.
During the first hours, organizations should establish an incident command structure with decision-making authority, engage an NCSC-assured Cyber Incident Response provider where appropriate, determine whether systems should be disconnected or shut down, conduct rapid business-focused triage, identify regulatory notification obligations, maintain a central incident record, and establish coordinated communications. The guidance emphasizes that business priorities should determine recovery sequencing. It cautions against rushing restoration before investigators understand how attackers gained access and whether they still retain persistence within the environment.
For the days and weeks following the incident, the NCSC recommends establishing a formal recovery program aimed at restoring Minimum Viable Operations (MVO), defined as the lowest operational capability at which the organization can continue operating safely while meeting legal obligations and maintaining stakeholder trust. The recovery program should consist of dedicated workstreams covering incident investigation, business recovery, infrastructure restoration, legal and regulatory management, communications, customer relations, HR support, financial modelling, and external supplier coordination.
The guidance identifies trusted identity as a prerequisite for recovery, noting that compromised identity systems may need to be rebuilt before other services can safely return online. It also advises organizations to treat backups cautiously, assuming they may themselves have been targeted until their integrity has been verified. Temporary manual workarounds should be planned carefully, security-reviewed before implementation, and designed so that data generated outside normal systems can later be reconciled into a trusted source of truth.
Organizations are encouraged to maintain detailed records of decisions throughout the incident, coordinate communications across internal and external stakeholders, manage regulatory obligations in parallel with operational recovery, monitor staff wellbeing, and conduct financial modelling to evaluate recovery options and trade-offs. The NCSC additionally reiterates that it does not encourage, endorse, or condone payment of ransomware demands, stressing that payment neither guarantees rapid recovery nor resolves the underlying compromise.
The rebuild phase focuses on long-term resilience. The guidance encourages organizations to improve documentation, address architectural weaknesses, strengthen recoverability, embed resilience into future system design, and conduct structured lessons-learned exercises examining not only technical failures but also organizational processes, governance, incentives, and human factors that contributed to the incident. The NCSC emphasizes that recovery should include people as well as technology, recognizing the psychological and operational pressures placed on staff during cyber incidents.
🇩🇪 German Court Clarifies GDPR Damages for Accidental Disclosure of Recruitment Data
On 23 June 2026, Germany’s Federal Court of Justice (Bundesgerichtshof, BGH) issued a judgment on compensation for non-material damage under Article 82 GDPR and the availability of injunctions following unlawful disclosures of personal data. The ruling (Case VI ZR 97/22) provides guidance on what constitutes harm after a GDPR violation.
The case arose from a recruitment process in which a bank accidentally sent a Xing message intended for a job applicant to another individual who was not involved in the recruitment process. The message disclosed the applicant’s identity, participation in an ongoing recruitment process, salary expectations, and the bank’s proposed remuneration. The unintended recipient knew the applicant professionally, contacted him about the message, and asked whether he was looking for a new job. The applicant sought both compensation for non-material damage under Article 82 GDPR and an injunction preventing similar future disclosures.
The BGH confirmed that the accidental transmission constituted an unlawful disclosure of personal data in breach of Article 6 GDPR. The court also confirmed that the information qualified as personal data even though additional contextual knowledge was required to identify the applicant. Consistent with CJEU case law, the court reiterated that information remains personal data where identification is reasonably possible using information available to the recipient.
The significant aspect of the judgment concerns non-material damage under Article 82 GDPR. The BGH held that the applicant was entitled to compensation in principle because the unlawful disclosure resulted in a genuine loss of control over his personal data. The court found that damage existed once the unintended recipient actually used the disclosed information by contacting the applicant about his job search. At that point, the loss of control had produced real consequences.
The court also accepted that the applicant’s concern that the recipient, who worked in the same industry, might use or further disseminate the information could constitute compensable non-material The BGH emphasized that actual misuse of the data is not required. Rather, a well-founded fear of misuse, supported by the circumstances of the case and accompanied by genuine negative consequences, may satisfy Article 82 GDPR.
In reaching this conclusion, the BGH relied on the CJEU’s September 2025 judgment in Case C-655/23, which had answered preliminary questions referred by the German court. The decision reinforces the approach that a GDPR infringement alone does not automatically create a right to compensation, no minimum seriousness threshold applies to non-material damage, claimants must nevertheless demonstrate that they actually suffered compensable harm, and loss of control over personal data, together with objectively justified concerns about subsequent misuse, may satisfy that requirement.
The BGH rejected the applicant’s request to prohibit future similar disclosures. The court held that the necessary risk of repetition no longer existed. The disclosure arose from a specific recruitment process that had already ended, making recurrence sufficiently unlikely. The earlier accidental disclosure alone was therefore insufficient to justify an ongoing injunction under the circumstances.
The BGH did not determine the amount of compensation. Instead, it returned the case to the appellate court, which must now assess damages applying the principles established by both the CJEU and the BGH.
🇮🇹 Italy Continues AI Act Implementation
Italy is continuing implementation of the EU AI Act by finalizing national legislation that designates competent authorities and establishes sector-specific rules for the use of artificial intelligence. On 14 July 2026, the Italian Data Protection Authority (Garante) issued two opinions on draft legislative decrees implementing Regulation (EU) 2024/1689, while recommending a number of amendments to strengthen data protection safeguards.
The first opinion concerns Italy’s general AI governance framework, including the designation of national authorities, market surveillance, regulatory sandboxes, AI in education and employment, and coordination among regulators. The draft designates the Agency for Digital Italy (AgID) as the national notifying authority and the National Cybersecurity Agency (ACN) as the principal market surveillance authority for AI systems, while assigning sector-specific responsibilities to financial regulators and recognizing the Garante’s role under Article 74(8) of the AI Act.
The Garante requested several amendments:
the Garante should have explicit authority to issue guidelines, recommendations and best practices alongside other AI regulators;
the legislation should clarify procedural rules governing the Garante’s enforcement powers and sanctions;
the Italian AI regulatory sandbox should formally involve the Garante whenever projects involve personal data, consistent with Article 57(10) of the AI Act; and
employment provisions should strengthen protections against automated decision-making by extending safeguards beyond purely automated decisions to significant evaluative decisions affecting workers.
The draft legislation also contains provisions concerning automated decision making. Employers using AI systems would be prohibited from making hiring, employment or dismissal decisions solely through automated processing. Human decision-makers would remain responsible for final decisions, employees would have to receive meaningful information about AI-assisted decisions, and employers would be required to respect privacy, dignity and non-discrimination principles. The draft also establishes an Italian AI regulatory sandbox, introduces AI literacy measures for schools, and expands trade secret protection to cover AI training data, algorithms and model architectures where existing confidentiality requirements are satisfied.
The second opinion addresses the use of AI by law enforcement authorities. It establishes rules governing AI systems used for policing, biometric identification and criminal investigations while attempting to align national law with the AI Act’s limited exceptions for law enforcement uses.
The Garante proposed several additional safeguards:
replacing the concept of “qualified human review” with the broader AI Act concept of effective human oversight;
prohibiting the use of sensitive operational data during AI research and testing, favoring synthetic or properly pseudonymised data instead;
requiring higher-quality reference databases and stronger deletion safeguards for biometric identification systems;
limiting facial recognition processing to targeted ex post investigations rather than indiscriminate biometric processing of everyone entering public spaces;
requiring data protection impact assessments alongside the AI Act’s fundamental rights impact assessments; and
expressly prohibiting the use of biometric databases created through untargeted scraping or in breach of data protection law.
🇺🇸 NIST Urges Organizations to Begin Post-Quantum Cryptography Migration Now
On 30 July 2026, the U.S. National Institute of Standards and Technology (NIST) published an interview with cryptography expert Andrew Regenscheid explaining why organizations should begin migrating to post-quantum cryptography (PQC) without waiting for practical quantum computers to emerge.
NIST finalized its first three post-quantum cryptographic standards in 2024 and is now focused on developing implementation guidance, supporting technology vendors, and working with international standards bodies such as ISO and the Internet Engineering Task Force (IETF) to facilitate global adoption. According to NIST, the challenge has shifted from selecting secure algorithms to managing what is expected to be one of the largest cryptographic migrations in the history of information technology.
The publication reiterates that the principal security concern is “harvest now, decrypt later” threat. Adversaries can already intercept and store encrypted communications today with the expectation that sufficiently powerful quantum computers may eventually be able to decrypt them. As a result, information with a long confidentiality lifecycle, including health records, financial information, intellectual property, government information and other sensitive business data, may already be exposed to future compromise if protected only by current public-key cryptography. Waiting until cryptographically relevant quantum computers become available would therefore be too late for many categories of data.
NIST acknowledges that no one knows precisely when quantum computers will become capable of breaking today’s widely deployed cryptographic algorithms. Current quantum computers remain too small and unstable for such attacks. Nevertheless, NIST argues that uncertainty about the timeline should not delay preparation because cryptographic migrations typically take many years to complete. Organizations will need to update operating systems, applications, network protocols, embedded devices, hardware components and cloud services in a coordinated manner, often relying on technology vendors that are themselves undergoing lengthy development cycles.
NIST recommends that organizations first develop a comprehensive inventory of where cryptography is used across their environment, including applications, infrastructure, devices and stored data. They should identify information requiring long-term confidentiality, develop a phased migration roadmap, and begin discussions with software providers, cloud vendors and hardware suppliers regarding their post-quantum migration strategies. Procurement processes should also begin incorporating PQC readiness as products supporting the new standards become commercially available.
The agency views the coming years as a period for inventory, planning, procurement and gradual deployment. Quantum resilience is increasingly being treated as a long-term technology modernization program.
***
Direct your questions to groundcontrol@kepler.consulting.
Until the next transmission, stay secure and steady on course. Ground Control, out.

