Edition

NIST 800-171 Rev 3 with NO Phase-In, One-Day Patch Deadlines, and a Year-Long Undetected Breach

SaltyCloud Research Team

Updated Mar 12, 2026 Read Time 8 min

InfoSec GRC Brief | March 2026

Welcome back to the InfoSec GRC Brief from SaltyCloud, your go-to source for curated insights on governance, risk, and compliance (GRC) in information security. This edition covers the GRC news worth sharing from the first half of March 2026.

Let’s get into it.

Regulatory & Compliance Updates

White House Unveils Six-Pillar National Cybersecurity Strategy

The Trump Administration published its national cybersecurity strategy on March 6, organized around six pillars:

  1. Shape Adversary Behavior
  2. Promote Common Sense Regulation
  3. Modernize and Secure Federal Government
  4. Secure Critical Infrastructure
  5. Sustain Superiority in Critical and Emerging Technologies
  6. Build Talent and Capacity

A companion executive order directs federal agencies to coordinate rapid responses to cybercrime and cyber-enabled fraud.

The strategy explicitly calls for harmonizing overlapping federal cybersecurity requirements—a priority the GAO validates with hard evidence. Meanwhile, the CIRCIA final rule mandating 72-hour incident reporting is now expected by May 2026.

Read more →

GAO Report: Conflicting Cyber Regulations Create Compliance Morass

In July 2025, a GAO report on Cybersecurity Regulations found that inconsistent definitions, overlapping incident reporting timelines, and duplicative rules drive up costs, especially for smaller firms without dedicated compliance teams.

Now, according to a summary of the GAO panel discussion on March 5, industry representatives are calling on the administration to give the National Cyber Director authority to harmonize federal terminology, align reporting regimes, and create reciprocity agreements that let organizations satisfy multiple agencies through a single process.

This is the first time the compliance fragmentation problem has been formally documented at the federal level. The findings will shape regulatory reform priorities throughout 2026.

Read more →

Cyber Strategy Opens Door to Private-Sector Offensive Operations

Three former federal prosecutors analyzed the cyber strategy’s provision that incentivizes companies to conduct offensive cyber operations against adversary networks.

Their conclusion: the Computer Fraud and Abuse Act (CFAA) and state-level anti-hacking statutes still criminalize most private offensive activity. But no court has tested whether the CFAA’s government exception covers private contractors.

Companies that participate without explicit legislative authorization may face criminal liability, tort exposure from attribution errors, insurance complications, and mandatory disclosure obligations. More specifically, the authors warn against relying on “informal government assurances” of non-prosecution.

Defense, technology, and critical infrastructure firms should have legal and compliance teams assess this exposure now.

Read more →

GSA Mandates NIST 800-171 Rev 3 — No Phase-In Period

In January 2026, the U.S. General Services Administration (GSA) became the first major agency to require NIST SP 800-171 Revision 3 controls for contractors handling Controlled Unclassified Information, leapfrogging the Rev 2 baseline used in DoD’s CMMC program.

The mandate landed via an IT Security Procedural Guide with no public comment period and no phase-in. It applies immediately to new solicitations and can be added to existing contracts.

Requirements include:

  • A five-phase authorization process
  • Mandatory independent assessment by FedRAMP-accredited 3PAOs
  • One-hour incident reporting (even if the investigation is incomplete)
  • Nine “showstopper” controls covering MFA, vulnerability monitoring, and boundary protection

Rev 3 adoption across the federal government is moving faster than the CMMC timeline suggested. With assessor availability limited, contractors should start scheduling now.

Read now →

GRC Strategies

AI Agents Are Privileged Insiders Waiting to Be Compromised

Autonomous AI agents combine three capabilities that create what researchers call a “lethal trifecta”: access to private data, exposure to untrusted content, and the ability to communicate externally.

A compromised agent with all three can move laterally and exfiltrate data like a privileged insider, while operating at machine speed. Last month, for example, AWS documented a low-skilled attacker who used commercial AI to plan intrusions, map internal networks, and compromise over 600 FortiGate devices across 55 countries.

The recommended response is to treat AI agents exactly like privileged service accounts. That means network isolation, least-privilege access, deterministic policy-as-code enforcement (not prompt-based guardrails), and full audit logging.

Read more →

75% of Boards Cap Cyber Discussions at 30 Minutes Per Quarter

A survey of 650+ CISOs found that three-quarters of board cybersecurity discussions last 30 minutes or less per quarter. According to the IANS report, only 30% of boards call their CISO relationship “strong and collaborative,” and fewer than 41% participate in tabletop exercises. Roughly half of directors say their security leaders need to improve reporting on AI and emerging technology risks.

Boards understand current compliance status—82% rate that reporting as satisfactory. Where they struggle is forward-looking risk. The researchers recommend CISOs stop delivering status updates and start framing cybersecurity in terms boards already use: revenue exposure, risk tolerance, and business impact.

Read more →

Zero-Day Attackers Are Targeting Enterprise Systems, Not Consumer Products

Google Threat Intelligence Group found that enterprise-grade systems are now the primary target for zero-day exploitation over consumer devices. AI is expected to accelerate both the volume and sophistication of these attacks throughout 2026.

This directly challenges vulnerability management programs that prioritize all systems equally. Organizations running flat patch schedules should use this data to justify reallocating resources toward business-critical enterprise infrastructure.

The pattern shows up again later in this edition: when CISA compresses patch deadlines to days, the products involved are enterprise platforms like SolarWinds Web Help Desk and Ivanti Endpoint Manager.

Read more →

AI Budgets Up 50%, Encryption Coverage Down

The 2026 Thales Data Threat Report found that 30% of organizations now have a dedicated AI security budget, up from 20% last year. But the survey of 3,120 security professionals across 20 countries also said that protection is not keeping pace with adoption:

  • 59% have experienced deepfake attacks
  • Encryption of sensitive cloud data dropped to 47% (from 51% in 2025)
  • Only 34% have full visibility into where their data is stored

Tool sprawl compounds the problem: 77% of respondents use five or more data protection tools, and organizations average 2.26 cloud providers and 89 SaaS applications. Meanwhile, misconfiguration and human error remain the top breach cause at 28%.

AI governance belongs in enterprise risk assessments and board reporting in 2026, not next year.

Read more →

Cyber Incidents & Risk Implications

FBI Wiretap Systems Breached Through Vendor ISP

The FBI confirmed a breach of an unclassified system containing wiretap and surveillance warrant data. The agency detected anomalous log activity on February 17.

Now, the White House, DHS, NSA, and CISA have joined the investigation. Attackers exploited a commercial ISP vendor’s infrastructure, and investigators suspect Chinese government-affiliated hackers—the same attribution pattern as the Salt Typhoon telecom compromises in 2024.

The takeaway: vendor risk assessments that stop at direct service providers miss the infrastructure layer. ISPs, hosting providers, and telecom carriers underpin critical systems, and this breach shows they are actively targeted by nation-state actors.

Read more →

TriZetto Breach: 3.4 Million Patients, One Year Undetected

Cognizant subsidiary TriZetto Provider Solutions disclosed that attackers had unauthorized access from November 2024 through October 2025 (nearly 12 months) before anyone noticed. The stolen data covers 3.4 million patients: names, Social Security numbers, insurance member numbers, and provider information.

A year-long dwell time in an environment handling protected health information means something failed at a fundamental level—endpoint detection, network monitoring, or both. HIPAA breach notification obligations and potential OCR enforcement add regulatory consequences.

Healthcare organizations that rely on third-party technology vendors should be asking those vendors hard questions about detection capabilities and contractual monitoring commitments right now.

Read more →

CISA Compresses Patch Deadlines to Days — For the Third Time This Month

CISA gave federal agencies one day to patch a SolarWinds Web Help Desk deserialization flaw (CVE-2025-26399) and two weeks for an Ivanti Endpoint Manager authentication bypass (CVE-2026-1603).

Usually, the standard window is three weeks. But this is the third emergency-pace deadline for SolarWinds Web Help Desk in a single month—the platform manages ticketing and asset tracking for dozens of federal agencies.

The Ivanti flaw has been exploited since mid-February by Chinese nation-state attackers who “repeatedly targeted Ivanti throughout 2025 with novel bugs,” according to Google. Both cybercriminals and state actors are hitting these vulnerabilities simultaneously, which CISA cited as “rare circumstances” justifying the compressed timelines.

Read more →

Ericsson Breach: Vishing Attack, 10-Month Notification Gap

A voice-phishing attack on an unnamed third-party vendor gave attackers access to files containing names, Social Security numbers, driver’s licenses, passport numbers, financial data, and medical information for 15,661 people.

The access window was five days in April 2025, and the vendor discovered it on April 28. Ericsson was not notified until November 10, and individual notifications went out in February 2026. That’s a 10-month gap between discovery and notification.

The breach started with a phone call to a single vendor employee. Review your vendor contracts: do they include breach notification SLAs with specific timelines? And if they do, would those timelines actually hold up?

Read more →

Russian Hackers Phishing Signal and WhatsApp Users at Scale

Dutch intelligence identified a “large-scale global” Russian state-backed campaign targeting Signal and WhatsApp accounts. The attackers use phishing and social engineering (not malware) with some posing as Signal support staff. The goal is account takeover, not device compromise.

End-to-end encryption protects message content in transit. But it does nothing against someone who tricks you into handing over your account. Legal, executive, and compliance teams that use encrypted messaging for sensitive discussions are direct targets.

Update your security awareness training to cover messaging apps specifically, enforce mobile device management, and review acceptable-use policies.

Read more →

SaltyCloud Research

NIST 800-53 Compliance: Step-by-Step Guide & Checklist [2026]

How to select, implement, and document NIST 800-53 security controls — a practical guide for organizations building or maturing their compliance programs.

Read the guide →

RMF & NIST 800-53: How the Risk Management Framework and Control Catalog Work Together

How NIST SP 800-37’s Risk Management Framework and NIST SP 800-53 Rev 5 work together as complementary frameworks—useful context as GSA begins mandating Rev 3 compliance.

Read the guide →

GLBA Compliance Checklist

A ready-to-use checklist covering the Safeguards Rule, Financial Privacy Rule, and Pretexting Protection requirements — built for compliance teams preparing for exams or standing up a GLBA program.

Access the Checklist →

GLBA Compliance: Requirements, Checklist & Guide [2026]

Everything financial institutions need to know about GLBA compliance: Safeguards Rule, Financial Privacy Rule, and Pretexting Protection requirements.

Read the guide →

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Past Editions

Plus, the DoD codifies its CMMC Phase 2 suspension, IDScan breach exposes 153M driver's license scans, and NYDFS risk assessment guidance.

Edition
09.17.2026

Plus, inconsistent CUI markings inflate CMMC scope, CareCloud breach impacts 3.7M patients, and NIST SP 1353, an AI quick-start for CSF 2.0.

Edition
09.17.2026

Plus, California's new DROP deletion platform, EU AI Act transparency enforcement begins, and White House-authorized private hacking.

Edition
09.17.2026
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo