5 short insights this week: The EU just took seven governments to court over resilience · DORA just stopped being paperwork · Hackers didn't breach Instagram. They asked the bot nicely.…
In this edition
Get the next GRC Brief in your inbox.
Subscribe to The GRC BriefThe EU just took seven governments to court over resilience
On April 28, the European Commission referred seven member states (Bulgaria, France, Luxembourg, the Netherlands, Poland, Spain and Sweden) to the Court of Justice for failing to transpose the CER Directive, and it is asking the Court to impose financial penalties. CER is the Critical Entities Resilience Directive, the physical and operational sibling to NIS2's cyber rules. Same October 2024 deadline. It covers critical entities in energy, transport, health, water, banking and digital infrastructure, and it takes an all-hazards view: not just cyberattacks, but sabotage, insider threats and physical disruption.
Source: European Commission · press release, 28 Apr 2026
My take
Everyone in GRC is buried in NIS2 right now. Meanwhile its twin is the one putting governments in front of a judge. CER is the half of EU resilience most security teams quietly skip, because it isn't "cyber." It's the fence, the backup generator, the single supplier, the guy who still has badge access two years after he left.
If you operate in a critical sector, you very likely fall under both. NIS2 asks whether you can keep attackers out of your systems. CER asks whether you can keep the service running when something physical goes wrong. Different question. Different controls. Same boardroom liability. This is operational resilience territory, not just infosec.
The signal is simple. The Commission has stopped sending letters and started asking for fines. When a government gets penalised for being late, that pressure does not stay in a ministry. It rolls down to entities. If "resilience" in your shop means antivirus and a nightly backup, you are reading half the brief.
DORA just stopped being paperwork
On June 3, the three European Supervisory Authorities published the first annual overview of major ICT incidents across the EU financial sector. The framework has officially moved from "implement it" to "we are reading your reports." They flagged risk that is increasingly borderless and interconnected, plus the rise of AI-driven attack tooling.
Source: National Law Review · ESAs first ICT-incident report
My take
This is the moment DORA grows teeth. The regulators now hold a full year of incident data, and they published it. Translation: they know what good reporting looks like, and they can spot who is faking it.
If you are a financial entity, or an ICT provider feeding one, your incident classification and your reporting clocks are no longer a theory exercise. They are being measured against everyone else's. Rehearse the 24-hour notification before reality forces you to improvise it.
Hackers didn't breach Instagram. They asked the bot nicely.
Attackers took over high-profile Instagram accounts by talking to Meta's AI support assistant. Spoof the location with a VPN, ask the bot to add a new recovery email, receive the one-time code, reset the password. No human involved. The Obama White House account and a US Space Force account were among those hit, and the flaw reportedly kept working after Meta said it was fixed.
Source: KrebsOnSecurity · reporting also by 404 Media, TechCrunch
My take
This is the AI governance lesson of the year, and it is free. Meta handed an AI agent the power to reset passwords and change recovery emails. Then nobody wrapped authorization controls around what that agent was allowed to do. So attackers simply asked.
This is exactly what ISO 42001 is about. Not "is the model biased." It is "what can this thing actually do, who signed off on that, and what stops it from causing harm." If you are deploying AI agents with real privileges, map their authority now. Before someone maps it for you.
And note the footnote: MFA blocked most of the takeovers. Boring controls still win.
Your weakest vendor is your real attack surface
The defining breach pattern of 2026 is not the front door. It is the supply chain. Poisoned open-source packages became the route into major firms. Two US banks were compromised through a single shared vendor. Attackers are no longer breaking in. They are walking in through someone you already trust.
Source: TechCrunch · the worst breaches of 2026 so far
My take
Nobody is kicking the door down anymore. They are being let in. Through a supplier, a library, a contractor, an integration you forgot you connected three years ago.
This is why NIS2 Article 21 and DORA both hammer third-party risk. It is not bureaucracy. It is the actual threat model. Pull your vendor list today and ask the ugly question: which one of these, if it gets popped, takes me down with it? That answer belongs at the top of your risk register. Not the firewall.
The AI Act just bought you time. Don't spend it.
Under the AI Act Omnibus (political agreement reached May 7), the heavy high-risk obligations got pushed back. Stand-alone Annex III systems now have until December 2, 2027. AI embedded in regulated products has until August 2, 2028. Formal adoption is expected any week now. But the transparency obligations still land on August 2, 2026.
Source: Gibson Dunn · AI Act Omnibus agreement
My take
A delay is not a pardon. The deadline moved. The work did not shrink. If you wait until 2027 to start your AI inventory and your risk assessments, you will be doing in a panic what you could be doing calmly right now.
And the transparency rules still hit this August, so "we got an extension" is not a plan. Use the runway. Build the inventory. Write the register. The version of you sitting across from an auditor will thank the version of you reading this.