Cybersecurity

On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”).  

The NSPM follows Executive Order 14390, which, together with the U.S. National Cybersecurity Strategy, demonstrated the U.S. government’s continued focus on disrupting foreign cyber-enabled criminal organizations that engage in fraud, scams, and related cyber-enabled schemes.  The NSPM, which states that “it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” signals a potential shift in the U.S. government’s approach to offensive cyber operations by non-government actors.  At the same time, the NSPM makes clear that any such operations would be conducted only after U.S. government vetting and authorization, under federal coordination and oversight, and consistent with U.S. law.   This post summarizes the NSPM and identifies practical takeaways for private-sector entities that may be considering whether to participate in the program.  Additional implementation guidance is expected by mid-October 2026 (60 days after the NSPM publication).

Continue Reading White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

Continue Reading White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse

On 3 June 2026, the European Commission published several legislative and policy measures wrapped up in one “tech sovereignty” package (see our posts summarising the package as a whole here, and diving deeper into the Cloud and AI Development Act here). But the EU’s tech sovereignty drive has a long history, and is by no means limited to this package.

In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors.

Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience

On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and risk-management matter that requires active oversight at “the highest levels of executive management.”  It is a helpful document for organizations that are likely to be subject to NIS2, expect to be supervised in Ireland, and that are considering their governance structures and board-level oversight mechanisms.

Continue Reading Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation

On June 22, 2026, the White House released two Executive Orders (EOs) on quantum technologies: Securing the Nation Against Advanced Cryptographic Attacks (EO 14412) and Ushering in the Next Frontier of Quantum Innovation (EO 14413).  Through the first EO, the White House seeks “to safeguard America’s most sensitive data, [U.S.] critical infrastructure, and the digital economy that drives jobs and growth.”  (For further reading on this topic, our Post-Quantum Cryptography: A Practical Guide provides a high-level overview of steps organizations should consider to move toward post-quantum cryptography (PQC) to protect their systems.)  The second EO, in comparison, seeks “to supercharge U.S. innovation in quantum technologies.”  Together, these EOs reflect a continued U.S. government focus on core themes in the quantum space — security and innovation.

Continue Reading Trump Administration Releases Two Executive Orders on Quantum

A key benefit of quantum computing is that it may, in the future, enable a very substantial increase in computing power.  This could create significant benefits, in the life sciences and financial services sectors (see our prior posts on the potential implications for these sectors here and here).  However, it also creates potential risks.  In particular, it could lead to the breaking of many of the encryption methods currently used by governments and businesses alike.  As commercially-viable quantum computers become an increasing reality, organisations must prioritise “quantum readiness” and specifically migration to post-quantum cryptography (“PQC”).

In this post, we set out a brief overview of the main steps that regulators and industry bodies (including the U.S. National Institute of Standards and Technology (“NIST”), the UK National Cyber Security Centre (“NCSC”), and the EU Agency for Cybersecurity (“ENISA”)) have indicated businesses should take to move towards PQC and protect their data and systems from the risks posed by quantum computing.

Continue Reading Post-Quantum Cryptography: A Practical Guide

On June 2, 2026, the White House issued an executive order titled “Promoting Advanced Artificial Intelligence Innovation and Security” (the “Order”).  The Order reflects the Administration’s stated policy of advancing U.S. leadership in artificial intelligence (“AI”) while addressing national security risks associated with increasingly capable AI systems.  To accomplish these policy goals, the Order outlines two approaches: (1) strengthening U.S. Government and private industry cyber defenses in response to “advanced AI,” and (2) developing voluntary benchmarking and review frameworks for secure development and release of “frontier” AI models.

Continue Reading White House Releases Executive Order on Advanced AI Innovation and Security

On June 3, the European Commission published its Tech Sovereignty Package, a set of legislative and policy initiatives designed to address what the Commission characterizes as Europe’s technological dependencies on non-European suppliers. The Package marks a further step in the evolution of the EU’s technology policy, with initiatives spanning the full tech stack—from chips and infrastructure to software, cloud, and artificial intelligence. Through this “ecosystem” approach, the Commission seeks to reduce supply-side dependencies by strengthening domestic capabilities in Europe and stimulating demand in downstream sectors.

The Package comprises four components: two legislative proposals—(i) the Cloud and AI Development Act (CADA), and (ii) the Chips Act 2.0—as well as two non-legislative initiatives—(iii) the EU Open Source Strategy and (iv) a Strategic Roadmap for Digitalisation and AI in Energy.

Continue Reading EU Tech Sovereignty Package

Earlier this month, the Cybersecurity & Infrastructure Security Agency (CISA), in collaboration with the National Security Agency and other international partners, released guidance for organizations on adopting agentic artificial intelligence systems (i.e., systems composed of one or more agents that fundamentally rely on an AI model, such as an LLM, to interpret and reason about the state of the world and can autonomously make decisions and take actions). The guidance highlights the primary security risks and challenges linked to agentic AI and offers practical guidance for safely designing, implementing, and managing these systems.

Continue Reading CISA Releases Guidance on the Careful Adoption of Agentic AI Services

On March 6, 2026, the Administration released “President Trump’s Cyber Strategy for America” alongside an Executive Order (entitled “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens”) and accompanying Fact Sheet.  The framework set forth in the Strategy document is significantly shorter and higher-level than the prior National Cybersecurity Strategy issued in March 2023.  We have summarized below the highlights of the Strategy document (Part I) and the Executive Order (Part II), along with key takeaways from each and areas to watch going forward. 

Continue Reading White House Releases New National Cyber Strategy and Executive Order