Edition

InfoSec GRC Brief | August 13, 2026

Mariah Brooks

Updated Aug 13, 2026 Read Time 6 min

InfoSec GRC Brief | August 13, 2026:
CMMC Comment Period Closes, CA Launches DROP Platform, and CISA Sets Cisco Firewall Patch Deadline

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of August 2026.

Let’s get into it.

Regulatory & Compliance Updates

CMMC Comment Period Closes on August 14th

On July 13, 2026, the DoD suspended CMMC Phase II certification requirements and opened a Request for Information (RFI) on the compliance burden. Comments are due at noon ET on August 14, 2026, and must be submitted via email, no longer than ten pages, and focused on concrete cost and process pain points.

The RFI stands to shape the next version of the rule, but it does not pause current contractual obligations. Phase I self-assessment obligations and existing CUI safeguarding requirements stay fully in effect during the suspension.

See the CMMC guide to learn more about mapping self-assessments to NIST 800-171 while the Phase 2 pause continues.

Read more →

California Launches DROP Platform

Enforcement for California’s Delete Request and Opt-Out Platform (DROP) began on August 1, 2026. Here’s how it works:

  • Residents can submit a single deletion request that reaches every registered data broker at once.
  • Data brokers face growing fines for missed deadlines or lapsed registration with the California Privacy Protection Agency.

Because California defines a “data broker” as any company that sells, licenses, or shares consumer data with third parties, the new requirement applies to many organizations that never considered themselves data brokers until now.

Teams that handle California consumer data may want to confirm their CPPA registration status and stand up a DROP request-handling workflow, before missing a deadline.

Read more →

Enforcement Begins for EU AI Act Transparency Rules

On August 2, 2026, the European Commission began enforcing Article 50 transparency obligations under the EU AI Act. Now, providers and deployers of chatbots, AI agents, deepfake tools, and emotion-recognition or biometric-categorization systems must:

  • Disclose AI interactions clearly.
  • Label AI-generated content with visible and machine-readable marks.
  • Use EU-provided labeling icons.

The rule applies to any organization deploying AI systems with EU users, including embedded chatbots or AI-generated marketing content. Non-compliance can trigger fines up to €15 million or 3% of global annual turnover, with a €750,000 ceiling for EU institutions and reduced exposure for SMEs.

Under Article 50(2) of the AI Omnibus provisional agreement, generative AI systems on the market before May 2026 have until December 2, 2026 to meet the machine-readable marking requirement.

To confirm that disclosure and labeling controls are implemented and operating effectively, inventory every AI-facing touchpoint with EU users.

Read more →

GRC Strategies

Security Leaders Don’t Trust Agentic AI

For security and IT leaders, trust in AI drops as the stakes of its actions rise. According to a recent Arctic Wolf survey:

  • 94% of organizations now use LLMs in some capacity.
  • 53% of security and IT leaders are comfortable letting AI handle narrowly defined actions.
  • 40% trust it with automatic vulnerability patching.
  • 30% would let it dismiss alerts on its own.
  • 14% have made AI central to their security strategy.

Meanwhile, 35% of leaders now name AI itself as their top cybersecurity threat, surpassing ransomware for the second year in a row. As for the barriers to giving AI more authority, data privacy concerns and unclear accountability rank at the top.

Read more →

Website Tracking Leaks More Data Than Companies Realize

Most organizations collect, share, or expose more personal data through website tracking than they realize. According to IAPP, enforcement is already accelerating faster than most compliance teams can keep up.

As of today, 19 state privacy laws are active and more are expected by 2028. For example:

Yet most tracking pixels, third-party scripts, and ad-tech integrations were built well before most state data privacy laws existed.

A simple policy update won’t close the gap on its own. To surface the exposure, GRC teams can run a tracking-technology audit that pairs legal and engineering teams.

Read more →

Workplace Surveillance Is a Governance Problem

For companies with AI-enable employee monitoring employees for productivity scoring, surveillance is now a question of both privacy and governance. Many organizations already have the capability to monitor their employees, but far fewer have the governance layer to do so responsibly.

When poorly governed, however, monitoring can backfire operationally. Employees who feel like they’re always being watched are less likely to report misconduct or take part in investigations, for instance.

To keep monitoring defensible, treat it as a cross-functional decision from the start. That means documented retention, access controls, and bias review for any AI-driven scoring that feeds employment decisions.

Read more →

Cyber Incidents & Risk Implications

White House Authorizes Private-Sector Offensive Hacking

A national security memorandum signed on August 12, 2026, authorizes vetted private companies to run offensive cyber operations against transnational criminal organizations. The effort will be coordinated through a new federal center under DOJ and DHS oversight.

To participate, firms must:

  • Sign government contracts.
  • Pass vetting.
  • Operate within existing law, including the Computer Fraud and Abuse Act.
  • Submit to ongoing reporting.

Some call the move a meaningful shift in U.S. cyber policy. But others warn that the new and largely untested liability and reporting framework could unintentionally reward companies for pursuing offensive activity.

Companies weighing participation may want to map the new reporting obligations and CFAA exposure before signing on.

Read more →

CISA Patch Deadline for Cisco Firewall Flaw Is August 14

CISA confirmed active exploitation of CVE-2026-20349 and ordered federal agencies to patch by August 14, 2026.

The flaw lets attackers crash Cisco Secure Firewall ASA and FTD devices by sending malformed HTTP requests through remote-access connections to cause a denial of service.

A downed firewall leaves the network behind it exposed, which is precisely why CISA set a hard federal deadline.

Read more →

VMware vCenter Flaw Hits 361 Victims Across 47 Countries

Just five days after Broadcom disclosed and patched the critical directory-traversal flaw in VMware vCenter, CVE-2026-59310 is under active exploitation by a suspected APT actor.

The flaw lets attackers plant malicious cron jobs that open backdoor connections on the server. Because the backdoors also run outbound to bypass inbound controls, patching cannot evict an attacker already inside.

With only a few days to implement the fix, however, many teams were left exposed. So far, researchers have identified 361 confirmed victim IPs across 47 countries.

First, patch vCenter. Then, hunt for unauthorized cron jobs or unexpected outbound SSH on any instance deployed after July 29.

Read more →

Russian State Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Logins

A Russian foreign-intelligence-linked group called Midnight Blizzard has been compromising hotel and conference Wi-Fi captive portals to harvest Microsoft 365 login credentials since February 2026.

The campaign, called CaptiveCrunch, uses fake Microsoft 365 login pages, device-code phishing against Microsoft Entra ID, and fake software-update prompts that deploy custom malware to steal browser cookies, passwords, cloud tokens, and Wi-Fi credentials.

Traveling executives and staff are the target. Once employees connect to hotel Wi-Fi, the standard corporate network defenses they’re accustomed to disappear.

Here are a few practical safeguards to update any travel security policy:

  • Treat hospitality Wi-Fi as untrusted.
  • Require cellular or managed connections for sensitive work.
  • Block software updates prompted through captive portals.

Read more →

SaltyCloud Research

NIST CSF 2.0 Readiness Scorecard

A free NIST CSF 2.0 self-assessment to score cybersecurity maturity and prioritize next steps.

Access the scorecard →

Conducting an IT Security Risk Assessment: Complete Guide

How to conduct an IT assessment that reveals whether security controls are operating effectively and which vulnerabilities and requirements matter most.

Read the guide →

Building an ISRM Program: Complete Guide

A step-by-step guide to building an information security risk management program that keeps pace with new regulations.

Read the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

InfoSec GRC Brief | August 27, 2026: CMMC Task Force Takes On CUI Markings, EU Cyber Resilience Act Reporting Begins, and CareCloud Breach Impacts...

Edition
09.03.2026

InfoSec GRC Brief | July 30, 2026: HHS Delays HIPAA Overhaul, FTC Issues $2.25M Fine, and EU Defers AI Act Deadline Welcome back to the InfoSec GRC...

Edition
09.03.2026

InfoSec GRC Brief | July 15, 2026: DoD Suspends CMMC Phase 2, Treasury Sanctions VPN Provider, and Zero-Day Exploit Hits 100+ Companies Welcome back...

Edition
09.03.2026
The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo