Edition

InfoSec GRC Brief | June 25, 2026

Mariah Brooks

Updated Jun 25, 2026 Read Time 8 min

InfoSec GRC Brief | June 25, 2026:
NIST PQC Compliance by 2030, a Record-Breaking Patch Tuesday, and 110M Credentials Harvested from FortiGate Firewalls

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the second half of June 2026.

Let’s get into it.

Regulatory & Compliance Updates

White House Orders Post-Quantum Cryptography Adoption

President Trump signed Executive Order 14409 on June 22, 2026. The order set firm deadlines for migrating high-value federal assets to NIST-approved post-quantum cryptography (NIST PQC).

Reaching beyond federal IT, it directs contracting agencies to require NIST PQC compliance and asks critical infrastructure operators to build their own adoption plans.

More specifically, the EO outlines:

  • 30 days for agencies to name a PQC migration lead.
  • 180 days for CISA to publish cryptographic bill-of-materials guidance.
  • Key establishment by December 31, 2030.
  • Digital signatures by December 31, 2031.

The move suggests that quantum readiness is evolving from a future planning item to a current compliance obligation. And the contractor and critical-infrastructure provisions make it a supply chain question, too.

“Harvest now, decrypt later” means sensitive long-lived data captured today can be unlocked once quantum capability arrives. Still, any organization holding that kind of data carries the same exposure, regardless of sector.

Organizations outside the federal supply chain can treat the order as a template. The first move is mapping where encryption operates across systems.

Read more →

NIST Opens Public Comment on SP 800-219 R2

On June 22, NIST released a draft of SP 800-219 R2, the second revision of its macOS Security Compliance Project. The guidance provides automated, ready-to-apply secure configuration baselines for macOS, iOS, and visionOS, mapped to established control frameworks.

Importantly, the revised baselines change what auditors will expect to see for any organization running Apple endpoints under FedRAMP, CMMC, or a NIST-based program. Its mSCP approach turns control requirements into machine-readable configuration profiles, which effectively closes the gap between a written policy and the setting actually deployed on a device.

NIST SP 800-219 R2 is open for public comment through August 14, 2026. This is a chance for covered organizations to shape the baseline before it lands in audit scope.

Compliance teams with Apple fleets can review the draft baselines against current configurations, identify where settings drift from proposed controls, and submit feedback.

Read more →

Health Plan Pays $450K HIPAA Fine After Skipped Risk Analysis

Spencer’s Gifts’ employee health plan paid a $450,000 settlement to HHS OCR following a 2021 Conti ransomware breach that affected 10,023 individuals. Investigators found the plan never conducted an adequate HIPAA Security Rule risk analysis and lacked required policies and procedures.

The incident marks OCR’s 20th ransomware enforcement action and the 14th to cite risk analysis deficiencies.

Clearly, the enforcement pattern is consistent: When ransomware hits an organization that never completed a risk analysis, the settlement follows the missing analysis, not the attack.

Covered entities and business associates can confirm their most recent risk analysis reflects current systems, vendors, and data flows. Remember, a risk analysis that predates a major infrastructure change may not hold up under OCR review.

Read more →

GRC Strategies

Verizon DBIR 2026 Analyzes +22,000 Breaches

The 2026 Verizon DBIR analyzed more than 22,000 breaches and reports that third-party breaches jumped 60% year over year, now accounting for 48% of all incidents.

Still, most tabletop exercises only rehearse one scenario: the ransomware payment decision. But vendor incidents introduce friction that ransomware drills rarely cover, including:

  • Vendor communication delays
  • Compressed remediation timelines
  • Legal-comms coordination

Programs that never simulate those conditions tend to find the weak spots mid-incident.

Security teams can widen their next tabletop beyond ransomware to a multi-stakeholder vendor breach. Testing how quickly your team reaches a critical vendor — and what happens when that vendor goes quiet — can reveal gaps in your response plan.

Read more →

Where Automated GRC Systems Fall Short

Color-coded GRC dashboards can hide flawed data sources and present different risk signals as if they were equivalent, according to Onspring CISO Nichole Windholz.

The warning lands as boards lean harder on dashboards for oversight. A green indicator built on stale or mismatched data hands leadership false confidence, and the CISO ends up defending the number instead of explaining the risk.

More specifically, Windholz says automated platforms usually struggle to measure:

  • Insider behavior
  • Vendor concentration risk
  • Geopolitical exposure

GRC leaders can audit the data lineage behind their dashboards, validate sources with periodic spot checks, and keep the narrative attached to every risk signal that reaches the board.

Read more →

What COBIT Can Teach Us About Tech Governance

To celebrate the framework’s 30th anniversary, COBIT expert Mark Thomas offers 30 lessons on technology governance.

The key insight? Frameworks don’t fail, implementations do. To summarize, Thomas’s lessons cover:

  • The distinction between governance and management.
  • The need for measurable outcomes before oversight means anything.
  • The role of ethics and accountability as the foundation of a program that lasts beyond audit cycles.

For GRC professionals, the value sits in a reminder that a framework is a tool, not a result. A program that confuses adopting COBIT with governing technology tends to produce documentation without decisions. Particularly, Thomas says, it’s the governance-versus-management split that clarifies who actually owns what.

Teams can revisit whether their framework adoption produces measurable outcomes or just artifacts. Asking what decision each control informs separates governance that works from governance that only looks complete.

Read more →

Cyber Incidents & Risk Implications

110 Million Credentials Harvested From FortiGate Firewalls

A multi-vendor credential-harvesting campaign compromised over 430,000 FortiGate firewalls worldwide. Launched by FortiBleed in February 2026, the campaign successfully extracted 110 million credentials, including NTLM hashes and Kerberos tokens.

But patching alone does not close it. Because Symlink artifacts persist through firmware updates, even a patched device can stay compromised.

Affected organizations can take four immediate containment steps:

  • Rotate all credentials exposed to the compromised devices
  • Audit SSL-VPN and SMB logs for anomalous activity
  • Review Active Directory activity originating from VPN sources
  • Enable MFA on every internet-facing device

Unfortunately, this is the kind of incident where “we applied the update” creates a false sense of security. Persistent artifacts mean remediation takes more than a patch, and the harvested credentials open the door to lateral movement long after the initial fix.

Read more →

141 npm Packages Compromised at Mastra AI

On June 17, North Korea’s Sapphire Sleet group compromised 141 packages in the Mastra AI framework’s npm scope. Within 45 minutes, the cryptocurrency-stealing malware reached roughly 8 million weekly downloads.

The entry point? A compromised maintainer account.

If anything, the incident demonstrates just how little time defenders get once a maintainer account falls. Here, a single upstream account became thousands of downstream exposures. Any organizations pulling third-party npm packages inherit that risk directly.

Teams can scan for the affected versions, rotate any secrets that may have passed through compromised CI/CD pipelines, and add package integrity verification through lockfile pinning and SLSA provenance checks.

Read more →

iRhythm Discloses Breach of Patient Data Through Third-Party Applications

Medical device maker iRhythm disclosed that a threat actor social-engineered access to third-party-hosted business applications and exfiltrated patient protected health information. The company filed an SEC Form 8-K that deems the incident material.

The breach lands two compliance obligations at once:

But Healthcare organizations that trade publicly answer to both. To comply, publicly traded healthcare organizations should confirm their breach notification procedures address HHS OCR timelines and the SEC’s four-business-day materiality requirement together, not as separate workflows.

Read more →

Record-Breaking Patch Tuesday in June 2026

Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities, including:

Then, exploit code for at least three of the flaws went public immediately after patching. According to researchers, the historic volume of June patches is attributed to AI-assisted vulnerability research. They also warn that this pace may become the new normal.

A 200-vulnerability month would put strain on any patch cycle. Plus, immediate public exploit code shortens the window to act. Basically, if AI-assisted discovery keeps volume this high, fixed SLA targets may no longer be realistic.

In response, vulnerability management teams can reassess whether existing SLA targets hold under this new discovery rate, prioritizing the wormable and actively exploited flaws first.

Read more →

AI To Reshape Cyber Threats Within Months

Intelligence agencies from the US, UK, Canada, Australia, and New Zealand issued a joint warning that frontier AI will reshape offensive and defensive cyber capabilities within months, not years. At the center of the concern is the shrinking window between vulnerability discovery and exploitation.

Before AI-enabled adversaries force the issue, the agencies recommend four moves:

  • Accelerate patching for known and actively exploited flaws.
  • Treat legacy systems as strategic liabilities, not deferred costs.
  • Strengthen authentication across users and machine identities.
  • Give cyber leaders the authority and funding to drive systemic change.

The warning reframes AI risk as a near-term operational issue rather than a forecast. When the time between a disclosed vulnerability and a working exploit keeps shrinking, slow patching and aging systems turn into immediate liabilities.

Read more →

SaltyCloud Research

TPRM Maturity Checklist

A free one-page scoring sheet built around the TPRM Maturity Model that maps each stage to NIST CSF 2.0 and NIST SP 800-53.

Access the checklist →

TPRM Maturity Model for Third-Party Risk: Complete Guide [2026]

A self-assessment framework for scoring third-party risk management (TRPM) program maturity against NIST CSF 2.0 and NIST SP 800-53.

Read the guide →

GRC Tools and Solutions for Mid-Market Companies: Complete Guide [2026]

What to look for in GRC tooling when resources are limited, including platform categories, build-versus-buy trade-offs, and evaluation criteria for teams.

Read the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

InfoSec GRC Brief | August 27, 2026: CMMC Task Force Takes On CUI Markings, EU Cyber Resilience Act Reporting Begins, and CareCloud Breach Impacts...

Edition
09.04.2026

InfoSec GRC Brief | August 13, 2026: CMMC Comment Period Closes, CA Launches DROP Platform, and CISA Sets Cisco Firewall Patch Deadline Welcome back...

Edition
09.04.2026

InfoSec GRC Brief | July 30, 2026: HHS Delays HIPAA Overhaul, FTC Issues $2.25M Fine, and EU Defers AI Act Deadline Welcome back to the InfoSec GRC...

Edition
09.04.2026
The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo