Edition

DORA’s First Register Deadline (93.5% Failure Rate) and NIST’s New Cyber-ERM Bridge

SaltyCloud Research Team

Updated Mar 25, 2026 Read Time 10 min

InfoSec GRC Brief | March 2026

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the second half of March 2026.

Let’s get into it.

Regulatory & Compliance Updates

CISA Orders Two-Day Patch for Max-Severity Cisco Firewall Flaw Tied to Ransomware

On March 20, CISA added CVE-2026-20131, a maximum-severity deserialization vulnerability in Cisco Secure Firewall Management Center, to the KEV catalog. It also  gave federal agencies until March 22 to patch it. To clarify, that is a two-day window.

The flaw allows unauthenticated attackers to execute arbitrary code as root via the web management interface. The Interlock ransomware gang has been exploiting it as a zero-day since late January, more than a month before a patch was available. Their victim list includes DaVita, Kettering Health, and Texas Tech University.

Under BOD 22-01, FCEB agencies must comply without a workaround. Non-federal organizations running Cisco FMC should treat this with equal urgency.

Read more →

EU AI Act Enforcement Takes Shape — But Only 8 of 27 Member States Are Ready

Starting August 2, 2026, the full high-risk EU AI Act framework applies. It covers:

  • Risk management
  • Data governance
  • Transparency
  • Post-market monitoring

The AI Office in Brussels retains exclusive authority over General-Purpose AI models, while national market surveillance authorities handle product-level risk management obligations. Supporting the structure are the European AI Board, a scientific expert panel, and an advisory forum.

With the deadline just four months away, covered organizations are soon expected to comply. However, a March 17 European Parliament Research Service briefing mapped the AI Act’s hybrid enforcement architecture.

The problem? Only 8 of the 27 member states have designated a national single contact point, which is a required step for enforcement readiness.

Organizations deploying AI in EU markets need to identify which national authority will oversee their operations and map their systems to the Act’s risk tiers now to avoid noncompliance.

Read more →

DORA’s First Register of Information Deadline Hits — and the Dry Run Was Brutal

The March 31, 2026 deadline for EU financial entities to transmit their Register of Information to national competent authorities marks the start of DORA’s permanent supervisory regime. Instead of a one-time filing, regulators will use RoI data to select firms for Threat-Led Penetration Testing and to designate Critical Third-Party Providers for years to come.

Meanwhile, the ESAs are applying a 116-point automated data quality audit across 15 templates. It covers:

  • Relational integrity.
  • LEI validation.
  • Mandatory field completion.

However, during the 2024 dry run, 93.5% of submissions — 886 out of 947 — triggered at least one data quality failure. The most common issues were:

  • Missing identification codes.
  • Invalid LEI entries.

Germany’s BaFin set a March 30 internal deadline with explicit guidance: “Best effort is a thing of the past. Compliance is now binary.”

Read more →

DOE Releases First 5-Year Cybersecurity Roadmap for Energy Infrastructure

The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) published a five-year cybersecurity strategy (2026-2030). The plan aligns with the national cybersecurity strategy released earlier this month. It focuses on three pillars:

  • Advanced OT security technology.
  • Infrastructure hardening across generation, transmission, and distribution.
  • Enhanced incident response coordination.

Rather than a hard requirement, the plan enables voluntary adoption via multifactor authentication, privileged access controls, and resilience measures.

However, despite an expanded mission scope, CESER requested just $150 million for fiscal 2026, down from $200 million in prior years. Combined with CISA staffing losses that create coordination bottlenecks, the gap between strategic ambition and execution capacity is significant.

Now, the capability divide between large utilities with dedicated security teams and smaller municipal or rural utilities remains the central implementation challenge.

Read more →

Morgan Lewis Maps the 2026 Regulatory Landscape: CMMC, DOJ Data Security, 20-State Privacy Expansion

Overlapping audit and assessment requirements across jurisdictions are creating operational burden that demands coordinated cybersecurity, privacy, legal, and compliance functions, according to a Morgan Lewis survey. It covers enforcement and regulatory developments spanning:

  • The CMMC final rule.
  • The DOJ Data Security Program restricting sensitive data transactions with countries of concern.
  • NIST CSF 2.0 governance expectations.
  • The expansion of state privacy laws to approximately half of all U.S. states, including new statutes in Tennessee, Minnesota, and Maryland.

This is a useful reference for any team updating its program roadmap for the rest of 2026. A closer look at the survey reveals that organizations still running isolated compliance programs are falling behind.

Read more →

GRC Strategies

NIST Bridges Cybersecurity and Enterprise Risk Management with New CSF 2.0 Guide

NIST finalized SP 1308, a Quick-Start Guide that integrates cybersecurity risk management, enterprise risk management, and workforce planning under the CSF 2.0 framework.

Separately, NIST released an initial public draft of SP 1347 on informative references — how to locate and apply the technical and operational references that map to CSF 2.0 outcomes — with a comment period open through May 6, 2026.

SP 1308 addresses the persistent problem of cybersecurity risk discussions that never connect to the enterprise risk language boards and executives use. The guide provides a structured pathway for aligning CSRM and ERM programs, exactly the gap that survey after survey keeps documenting.

Read more →

31% of Organizations Cannot See Their Own AI — Trend Micro Report

governance is losing the race against AI deployment, according to Trend Micro’s TrendAI State of AI Security report. In a survey of 3,700 business and IT decision makers, the numbers paint a clear picture:

  • 67% felt pressured to approve AI despite security concerns.
  • 57% say AI is advancing faster than they can secure it.
  • Only 38% have comprehensive AI policies in place.
  • 31% lack observability or auditability over deployed AI systems entirely.

But the agentic AI findings are particularly concerning.

  • Approximately 40% of organizations support an AI “kill switch” mechanism.
  • Nearly half remain undecided.

Put simply, that means autonomous agents are being deployed without consensus on how to retain control when systems fail or are misused. Meanwhile, as security teams react to top-down rollout decisions they had no input on, Shadow AI usage is rising.

Read more →

FCC Bans Foreign-Made Consumer Routers, Citing Typhoon Campaign Links

Effective March 23, the FCC prohibited the importation of all new consumer-grade routers manufactured outside the United States. The move acted on a National Security Determination tied to the Volt Typhoon, Flax Typhoon, and Salt Typhoon campaigns.

The ban covers any router where any significant phase of manufacturing, assembly, design, or development occurs outside the U.S. Effectively, it encompasses virtually all major consumer brands currently on the market.

Manufacturers may apply for conditional approval from the Departments of Defense and Homeland Security, and existing authorized models may continue to be sold through at least March 2027.

Still, the action sets a precedent for extending the FCC’s “Covered List” supply-chain security mechanism to consumer-premises equipment for the first time — a model that could expand to other IoT and network devices.

Read more →

Acting Federal CISO Outlines Implementation Roadmap for National Cyber Strategy

In a March 12 interview, Acting Federal CISO Mike Duffy outlined the implementation priorities that follow the Trump administration’s national cybersecurity strategy. They are:

  • Accelerating Zero Trust maturity across federal agencies.
  • Standing up the interagency operational cell spanning DOJ, State, FBI, and DoD.
  • Designing state-by-state critical infrastructure pilot programs in sectors including water, beef processing, and rural hospitals.

The key takeaway for GRC practitioners is that this is just the starting point. Follow-on guidance, pilot program standards, and coordination frameworks are expected throughout Q2 2026. The DOE’s new CESER strategic plan is one example of the first tangible outputs.

Organizations that interface with federal agencies or hold critical infrastructure designations should monitor which pilot standards get formalized. Likely, those will shape future contractual cybersecurity requirements and regulatory guidance.

Read more →

Only 18% of Organizations Have Fully Integrated TPRM with Enterprise Risk

Third-party risk management programs remain largely siloed, according to a KPMG survey of 851 organizations globally. In fact:

  • Only 18% have fully integrated TPRM with enterprise risk management.
  • Just 15% express high confidence in their program’s underlying data quality.
  • While over 50% are exploring AI for risk scoring, only 22% find their AI implementations effective.

The survey’s recommendations are blunt.

  1. Stop broad-based screening and focus on material risks.
  2. Break down silos between TPRM and ERM.
  3. Treat data as a strategic asset rather than a compliance artifact.
  4. Expand visibility into Nth-party supply chain relationships.

Compliance and cybersecurity remain the primary TPRM drivers. But programs that operate in isolation from enterprise risk simply aren’t meeting the standard that regulators and auditors increasingly expect.

Read more →

Cyber Incidents & Risk Implications

Stryker Tests SEC Cyber Disclosure Regime in Real Time After Intune-Based Wiper Attack

On March 11, Stryker Corporation disclosed a cyberattack that shut down global operations. Between March 11th and 23rd, the company filed multiple SEC 8-K disclosures as the investigation evolved, offering a real-time stress test of the SEC cybersecurity disclosure regime.

Eventually, Iran-aligned hacktivist group Handala claimed responsibility for the attack, framing it as retaliation for geopolitical events and part of a broader wave of retaliatory campaigns. During the incident, attackers exploited Microsoft Intune’s remote wipe capability — a legitimate IT administration tool — to issue mass device erasure commands across 79 countries. No malware was needed.

The attack exposed gaps in privileged access controls over endpoint management platforms. CISA and the FBI subsequently advised all organizations to implement least-privilege admin roles, phishing-resistant MFA on management consoles, and dual-approval policies for destructive actions like device wipes.

Read more →

CISA Adds SharePoint and Zimbra to KEV Catalog — Active Exploitation Confirmed

CISA added two actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog:

  • CVE-2026-20963 is a deserialization flaw in Microsoft SharePoint that allows unauthenticated remote code execution (CVSS 8.8), with a federal remediation deadline of March 21.
  • CVE-2025-66376 is a stored cross-site scripting vulnerability in Synacor Zimbra Collaboration Suite (CVSS 7.2), with a deadline of April 1.

The SharePoint flaw warrants particular attention. SharePoint is where many organizations store compliance documentation, audit evidence, and workflow data. Active exploitation of a remote code execution vulnerability in that platform represents a direct risk to the integrity of GRC records beyond infrastructure availability.

Read more →

Legacy Asset Blind Spots: Hikvision and Rockwell Flaws From 2017 and 2021 Added to KEV Catalog

Under BOD 22-01, Federal agencies now face near-term remediation deadlines for several critical-severity flaws recently added by CISA to the KEV catalog. They include:

  • Hikvision cameras (CVE-2017-7921, CVSS 10.0)
  • Rockwell Automation controllers (CVE-2021-22681, CVSS 9.8)
  • Three Apple iOS vulnerabilities linked to an active exploit chain

Both CVEs are legacy vulnerabilities — disclosed in 2017 and 2021 respectively — that remain actively exploited in the wild. Their addition to the KEV catalog highlights a persistent asset inventory and vulnerability management gap in OT/ICS environments, where patching cadences are measured in years, not weeks, and many devices never appear in centralized risk registers.

Organizations operating physical security cameras, industrial control systems, or building automation should treat these additions as a signal to audit asset inventories and remediation coverage, particularly in critical infrastructure sectors where these devices are ubiquitous.

Read more →

Geopolitical Risk Hits Enterprise Risk Registers: Iran-Linked Campaigns Surge Across U.S. Targets

Following U.S. and Israeli military operations against Iranian targets in late February 2026, researchers documented a surge in retaliatory cyber activity targeting U.S. corporate infrastructure. Dozens of incidents — DDoS attacks, website defacements, data exfiltration claims — were attributed to pro-Iranian and pro-Palestinian hacktivist groups.

According to KnowBe4’s 2025 Phishing Threat Trends Report, over 82% of analyzed phishing emails now contain AI-generated elements — a trend that amplifies the reach and credibility of geopolitically motivated campaigns.

For GRC teams, this is a reminder that geopolitical risk belongs in enterprise risk assessments, not just threat intelligence briefings. Organizations with Middle East exposure, defense contractor ties, or critical infrastructure designations should reassess third-party risk exposure, validate incident response plans and offline backups, and ensure geopolitical scenarios are reflected in their risk registers.

Read more →

SaltyCloud Research

NIST CSF 2.0: Complete Guide [2026]

A comprehensive walkthrough of the first major revision to the NIST Cybersecurity Framework since 2014 — timely context as NIST releases the SP 1308 and SP 1347 Quick-Start Guides covered in this edition.

Read the guide →

GLBA Compliance Checklist

A ready-to-use checklist covering the Safeguards Rule, Financial Privacy Rule, and Pretexting Protection requirements — built for compliance teams preparing for exams or standing up a GLBA program.

Access the checklist →

RMF & NIST 800-53: How the Risk Management Framework and Control Catalog Work Together

How NIST SP 800-37’s Risk Management Framework and NIST SP 800-53 Rev 5 work together as complementary frameworks — useful context as GSA begins mandating Rev 3 compliance.

Read the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

Plus, the DoD codifies its CMMC Phase 2 suspension, IDScan breach exposes 153M driver's license scans, and NYDFS risk assessment guidance.

Edition
09.17.2026

Plus, inconsistent CUI markings inflate CMMC scope, CareCloud breach impacts 3.7M patients, and NIST SP 1353, an AI quick-start for CSF 2.0.

Edition
09.17.2026

Plus, California's new DROP deletion platform, EU AI Act transparency enforcement begins, and White House-authorized private hacking.

Edition
09.17.2026
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo