InfoSec GRC Brief | June 25, 2026:
NIST PQC Compliance by 2030, a Record-Breaking Patch Tuesday, and 110M Credentials Harvested from FortiGate Firewalls
Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the second half of June 2026.
Let’s get into it.
Regulatory & Compliance Updates
White House Orders Post-Quantum Cryptography Adoption
President Trump signed Executive Order 14409 on June 22, 2026. The order set firm deadlines for migrating high-value federal assets to NIST-approved post-quantum cryptography (NIST PQC).
Reaching beyond federal IT, it directs contracting agencies to require NIST PQC compliance and asks critical infrastructure operators to build their own adoption plans.
More specifically, the EO outlines:
- 30 days for agencies to name a PQC migration lead.
- 180 days for CISA to publish cryptographic bill-of-materials guidance.
- Key establishment by December 31, 2030.
- Digital signatures by December 31, 2031.
The move suggests that quantum readiness is evolving from a future planning item to a current compliance obligation. And the contractor and critical-infrastructure provisions make it a supply chain question, too.
“Harvest now, decrypt later” means sensitive long-lived data captured today can be unlocked once quantum capability arrives. Still, any organization holding that kind of data carries the same exposure, regardless of sector.
Organizations outside the federal supply chain can treat the order as a template. The first move is mapping where encryption operates across systems.
NIST Opens Public Comment on SP 800-219 R2
On June 22, NIST released a draft of SP 800-219 R2, the second revision of its macOS Security Compliance Project. The guidance provides automated, ready-to-apply secure configuration baselines for macOS, iOS, and visionOS, mapped to established control frameworks.
Importantly, the revised baselines change what auditors will expect to see for any organization running Apple endpoints under FedRAMP, CMMC, or a NIST-based program. Its mSCP approach turns control requirements into machine-readable configuration profiles, which effectively closes the gap between a written policy and the setting actually deployed on a device.
NIST SP 800-219 R2 is open for public comment through August 14, 2026. This is a chance for covered organizations to shape the baseline before it lands in audit scope.
Compliance teams with Apple fleets can review the draft baselines against current configurations, identify where settings drift from proposed controls, and submit feedback.
Health Plan Pays $450K HIPAA Fine After Skipped Risk Analysis
Spencer’s Gifts’ employee health plan paid a $450,000 settlement to HHS OCR following a 2021 Conti ransomware breach that affected 10,023 individuals. Investigators found the plan never conducted an adequate HIPAA Security Rule risk analysis and lacked required policies and procedures.
The incident marks OCR’s 20th ransomware enforcement action and the 14th to cite risk analysis deficiencies.
Clearly, the enforcement pattern is consistent: When ransomware hits an organization that never completed a risk analysis, the settlement follows the missing analysis, not the attack.
Covered entities and business associates can confirm their most recent risk analysis reflects current systems, vendors, and data flows. Remember, a risk analysis that predates a major infrastructure change may not hold up under OCR review.
GRC Strategies
Verizon DBIR 2026 Analyzes +22,000 Breaches
The 2026 Verizon DBIR analyzed more than 22,000 breaches and reports that third-party breaches jumped 60% year over year, now accounting for 48% of all incidents.
Still, most tabletop exercises only rehearse one scenario: the ransomware payment decision. But vendor incidents introduce friction that ransomware drills rarely cover, including:
- Vendor communication delays
- Compressed remediation timelines
- Legal-comms coordination
Programs that never simulate those conditions tend to find the weak spots mid-incident.
Security teams can widen their next tabletop beyond ransomware to a multi-stakeholder vendor breach. Testing how quickly your team reaches a critical vendor — and what happens when that vendor goes quiet — can reveal gaps in your response plan.
Where Automated GRC Systems Fall Short
Color-coded GRC dashboards can hide flawed data sources and present different risk signals as if they were equivalent, according to Onspring CISO Nichole Windholz.
The warning lands as boards lean harder on dashboards for oversight. A green indicator built on stale or mismatched data hands leadership false confidence, and the CISO ends up defending the number instead of explaining the risk.
More specifically, Windholz says automated platforms usually struggle to measure:
- Insider behavior
- Vendor concentration risk
- Geopolitical exposure
GRC leaders can audit the data lineage behind their dashboards, validate sources with periodic spot checks, and keep the narrative attached to every risk signal that reaches the board.
What COBIT Can Teach Us About Tech Governance
To celebrate the framework’s 30th anniversary, COBIT expert Mark Thomas offers 30 lessons on technology governance.
The key insight? Frameworks don’t fail, implementations do. To summarize, Thomas’s lessons cover:
- The distinction between governance and management.
- The need for measurable outcomes before oversight means anything.
- The role of ethics and accountability as the foundation of a program that lasts beyond audit cycles.
For GRC professionals, the value sits in a reminder that a framework is a tool, not a result. A program that confuses adopting COBIT with governing technology tends to produce documentation without decisions. Particularly, Thomas says, it’s the governance-versus-management split that clarifies who actually owns what.
Teams can revisit whether their framework adoption produces measurable outcomes or just artifacts. Asking what decision each control informs separates governance that works from governance that only looks complete.
Cyber Incidents & Risk Implications
110 Million Credentials Harvested From FortiGate Firewalls
A multi-vendor credential-harvesting campaign compromised over 430,000 FortiGate firewalls worldwide. Launched by FortiBleed in February 2026, the campaign successfully extracted 110 million credentials, including NTLM hashes and Kerberos tokens.
But patching alone does not close it. Because Symlink artifacts persist through firmware updates, even a patched device can stay compromised.
Affected organizations can take four immediate containment steps:
- Rotate all credentials exposed to the compromised devices
- Audit SSL-VPN and SMB logs for anomalous activity
- Review Active Directory activity originating from VPN sources
- Enable MFA on every internet-facing device
Unfortunately, this is the kind of incident where “we applied the update” creates a false sense of security. Persistent artifacts mean remediation takes more than a patch, and the harvested credentials open the door to lateral movement long after the initial fix.
141 npm Packages Compromised at Mastra AI
On June 17, North Korea’s Sapphire Sleet group compromised 141 packages in the Mastra AI framework’s npm scope. Within 45 minutes, the cryptocurrency-stealing malware reached roughly 8 million weekly downloads.
The entry point? A compromised maintainer account.
If anything, the incident demonstrates just how little time defenders get once a maintainer account falls. Here, a single upstream account became thousands of downstream exposures. Any organizations pulling third-party npm packages inherit that risk directly.
Teams can scan for the affected versions, rotate any secrets that may have passed through compromised CI/CD pipelines, and add package integrity verification through lockfile pinning and SLSA provenance checks.
iRhythm Discloses Breach of Patient Data Through Third-Party Applications
Medical device maker iRhythm disclosed that a threat actor social-engineered access to third-party-hosted business applications and exfiltrated patient protected health information. The company filed an SEC Form 8-K that deems the incident material.
The breach lands two compliance obligations at once:
- HIPAA requires notification to HHS OCR on one timeline.
- The SEC requires a materiality disclosure within four business days for public companies.
But Healthcare organizations that trade publicly answer to both. To comply, publicly traded healthcare organizations should confirm their breach notification procedures address HHS OCR timelines and the SEC’s four-business-day materiality requirement together, not as separate workflows.
Record-Breaking Patch Tuesday in June 2026
Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities, including:
- Wormable CVE-2026-45586 (CVSS 9.8)
- A BitLocker bypass, CVE-2026-50507.
Then, exploit code for at least three of the flaws went public immediately after patching. According to researchers, the historic volume of June patches is attributed to AI-assisted vulnerability research. They also warn that this pace may become the new normal.
A 200-vulnerability month would put strain on any patch cycle. Plus, immediate public exploit code shortens the window to act. Basically, if AI-assisted discovery keeps volume this high, fixed SLA targets may no longer be realistic.
In response, vulnerability management teams can reassess whether existing SLA targets hold under this new discovery rate, prioritizing the wormable and actively exploited flaws first.
AI To Reshape Cyber Threats Within Months
Intelligence agencies from the US, UK, Canada, Australia, and New Zealand issued a joint warning that frontier AI will reshape offensive and defensive cyber capabilities within months, not years. At the center of the concern is the shrinking window between vulnerability discovery and exploitation.
Before AI-enabled adversaries force the issue, the agencies recommend four moves:
- Accelerate patching for known and actively exploited flaws.
- Treat legacy systems as strategic liabilities, not deferred costs.
- Strengthen authentication across users and machine identities.
- Give cyber leaders the authority and funding to drive systemic change.
The warning reframes AI risk as a near-term operational issue rather than a forecast. When the time between a disclosed vulnerability and a working exploit keeps shrinking, slow patching and aging systems turn into immediate liabilities.
SaltyCloud Research
TPRM Maturity Checklist
A free one-page scoring sheet built around the TPRM Maturity Model that maps each stage to NIST CSF 2.0 and NIST SP 800-53.
TPRM Maturity Model for Third-Party Risk: Complete Guide [2026]
A self-assessment framework for scoring third-party risk management (TRPM) program maturity against NIST CSF 2.0 and NIST SP 800-53.
GRC Tools and Solutions for Mid-Market Companies: Complete Guide [2026]
What to look for in GRC tooling when resources are limited, including platform categories, build-versus-buy trade-offs, and evaluation criteria for teams.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.