CMMC
Key Takeaways AI Agents Get Over-Privileged Credentials. Enterprises grant machine identities broad access without applying human-level hygiene like rotation or least privilege. Forrester Predicts a Major Breach by End of...
M365 Device Code Phishing: The AI-Assisted Kill Chain Compromising Hundreds of Organizations Daily
Key Takeaways Daily Mass Compromises. Hundreds of M365 tenants are breached daily through an automated, AI-driven phishing campaign abusing device code authentication. Legitimate Flow Exploitation. Attackers weaponize Microsoft’s device code...
AI Attacker Doubling Rate Hits 4.7 Months: Govern Data Now
The U.K. government just published the most uncomfortable benchmark in cybersecurity. The AI Security Institute (AISI), a research arm of the Department for Science, Innovation and Technology, has been tracking...
Why CVE-2026-42897 Is the Email Architecture Wake-Up Call
On May 14, 2026, Microsoft disclosed CVE-2026-42897, an actively exploited critical cross-site scripting vulnerability in Microsoft Exchange Server. CVSS 8.1. Affects Exchange Server 2016, Exchange Server 2019, and Exchange Server...
Another MOVEit Vulnerability. Same Pattern. Different Stakes.
On April 30, 2026, Progress Software disclosed two vulnerabilities in MOVEit Automation, the workflow and scheduling engine that thousands of organizations use to automate enterprise file transfers. The National Vulnerability...
Test Safeguard Patient Privacy in Compliance With HIPAA
The Kiteworks Private Data Network delivers a unified and secure system for sharing and transferring PHI that ensures strict compliance with HIPAA and HITECH, mitigates governance gaps, and reduces the risk of...
Control Plane DPE
The Data Policy Engine is the enforcement layer of the Kiteworks secure data exchange platform. It ensures that every piece of sensitive data moving into, out of, or through your organization — whether accessed...
Your Employees Are Sending Sensitive Emails Right Now — And Nobody’s Watching
Kiteworks Email Protection Gateway automates email encryption with zero user intervention. Policy-driven security for HIPAA, GDPR, and CMMC compliance.
Achieve CPCSC Compliance: Certify Your Defence Supply Chain Without the Complexity
CPCSC is Canada's mandatory cyber security certification for defence suppliers handling sensitive unclassified government information. Managed by Public Services and Procurement Canada, the program requires certification across three levels: Level 1 (13...
From Exposure to Compliance: Support for Israel’s Privacy Protection Law With Kiteworks
Kiteworks supports Israel’s Privacy Protection Law Amendment No. 13 compliance with encryption, access controls, audit logging, and DPO monitoring.
AI Compliance by Industry: A Regulatory Reference Guide
There is no universal AI compliance framework. Every organization deploying AI inherits the regulatory obligations attached to the data it processes — and those obligations vary dramatically by industry, data...
AI Compliance Requirements for Federal Contractors: What You Need to Know
Federal contractors occupy one of the most demanding AI compliance environments in the enterprise market. The regulatory stack they operate under — CMMC 2.0, NIST 800-171, FedRAMP, ITAR, FISMA, and...
AI Compliance Requirements for Manufacturers: What You Need to Know
Manufacturing sits at a unique intersection in the AI compliance landscape. Defense manufacturers must satisfy CMMC 2.0 and ITAR compliance requirements that apply with full force to AI systems touching...
What Is Compliant AI? A Plain-English Guide for Enterprise Leaders
Enterprise AI is moving fast. Compliance thinking is not keeping pace. Most organizations deploying AI agents today treat compliance as a model problem: review the AI vendor’s certifications, configure a...
CMMC 2.0 and AI Agents: What “Authorized Access” Means for CUI-Touching Workflows
Defense contractors are deploying AI agents across proposal development, program documentation, supply chain management, and technical data workflows. Many of these workflows touch controlled unclassified information. That puts them squarely...