regulation-2016-679-of-27-april-2016 Piergiorgio Venuti

Almost ready for the GDPR

regulation-2016-679-of-27-april-2016

The 2016-679 regulation of 27 April 2016 will apply in all Member States from 25 May 2018, within which the companies will have to comply with the new Privacy Act.

As activities related to privacy advice and specifically in relation to the minimum security measures that must be prepared following the Gap Analysis and Privacy Assessment, the Cyberfero offers the following services.

 

Our services for the regulation-2016-679-of-27-april-2016

   ♦ GDPR CONSULTING

      It is the consulting activity for the adaptation to the new 2016-679 privacy regulation. Find out more.

 

   ♦ PRIVACY ASSESSMENT

      It is one of the first activities within the GDPR consulting projects aimed at “photographing” the current state of the company on the topic of Privacy. Find out more.

 

   ♦ VULNERABIITY ASSESSMENT & PENETRATION TEST

      The activities of the Vulnerability Assessment and Penetration Test are aimed at assessing the level of IT security of an IT infrastructure. Find out more.

 

   ♦ PRIVACY TRAINING

 

      The training of persons in charge of processing personal data, in addition to constituting a legal obligation, is one of the most effective security measures to protect the same data. In fact, training is essential for logical and physical security measures, as well as policies and procedures adopted by companies, to find concrete and conscious application in daily practice.

The courses are delivered in the classroom directly at the customer, and are designed and maintained by Privacy Officer and teachers who are experts in personal data security and organization.

All our courses are highly practical and are carried out through a constant interaction between teacher and participants, with the aim not only to make the fundamental principles of the law known, but also and above all to increase the participants’ awareness on safety measures from adopt and on the behavioral guidelines for the correct use of company tools. Find out more.

 

   ♦ LOG MANAGEMENT

      The collection, aggregation and secure storage of logs are some of the activities to be considered in the process of adaptation to the GDPR. Find out more.

 

   ♦ AUDIT MANAGEMENT

      Our Audit Management system verifies the access of “privileged” users to remote servers, prevents unauthorized behavior, records activities in searchable video sessions and generates compliance and support reports.

 

   ♦ STRONG AUTHENTICATION

 

   ♦ ENCRYPTION

 

   ♦ BACKUP ON CLOUD

      Data resilience, backup and threat protection are fundamental aspects of the new 2016-679 Regulation of 27 April 2016. Find out more.

 

The Cyberfero primarily has put in place the appropriate measures to comply with the adaptation in order to protect the privacy of its users.

[btnsx id=”2931″]

USEFUL LINKS:

Privacy

Public Cloud

New European regulation (GDPR)

Cloud Provider Reggio Emilia

Introducing a set of new GDPR tools

IaaS | Cloud | Infrastructure as a Service

Share


RSS

More Articles…

Categories …

Tags

RSS Unknown Feed

RSS Full Disclosure

  • [REVIVE-SA-2026-003] Revive Adserver Vulnerabilities July 9, 2026
    Posted by Matteo Beccati on Jul 08======================================================================== Revive Adserver Security Advisory REVIVE-SA-2026-003 ------------------------------------------------------------------------ https://www.revive-adserver.com/security/revive-sa-2026-003 ------------------------------------------------------------------------ Date: 2026-06-25 Risk Level: Medium to High Applications affected: Revive Adserver Versions...
  • OPNsense XPATH Injection (CVE-2026-53582) July 7, 2026
    Posted by evan on Jul 06SUMMARY: a stored XPATH injection allows any user with just ca manager/certificate manager perms to leak any secret key/any value in config.xml, thus achieving privilege escalation and potentially remote code execution. this can also likely be chained via csrf and some clever hiding. see https://github.com/opnsense/core/security/advisories/GHSA-xww7-76m6-mh2r == VULN == the primary […]
  • SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+ July 7, 2026
    Posted by Jan Hüber via Fulldisclosure on Jul 06Authentication Bypass for SafeLine SL6 and SL6+ =============================================== The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. […]
  • Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties July 2, 2026
    Posted by Red Nanaki via Fulldisclosure on Jul 02Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties ## Summary The anonymous reporting flow on `whistleblowersoftware.com` encrypts report text end-to-end in the browser but does not extend the same guarantee to attachments and exposes the reporter's network identity and timing to a US-based third party. Together these […]
  • OpenBlow Multiple Deanonymization Vulnerabilities July 2, 2026
    Posted by Red Nanaki via Fulldisclosure on Jul 02OpenBlow Multiple Deanonymization Vulnerabilities Summary A production deployment was observed (HTTP archive of a full, real whistleblower submission) to route its anonymous reporting flow through Google. The intake CAPTCHA is Google reCAPTCHA, enforced as a mandatory, server-validated gate on report submission, and the UI additionally pulls a […]
  • Whistlelink: Site-access password exposed in web server access logs via GET query string July 2, 2026
    Posted by Red Nanaki via Fulldisclosure on Jul 02Whistlelink: Site-access password exposed in web server access logs via GET query string Severity: CRITICAL SUMMARY The Whistlelink reporting portal protects optionally-enabled, password-gated whistleblowing sites with a site-access password. When a visitor unlocks such a site, the client validates the password by issuing an HTTP GET request […]
  • APPLE-SA-06-29-2026-3 Safari 26.5.2 July 2, 2026
    Posted by Apple Product Security via Fulldisclosure on Jul 02APPLE-SA-06-29-2026-3 Safari 26.5.2 Safari 26.5.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/127685. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Web Extensions Available for: macOS Sonoma and macOS Sequoia Impact: A […]
  • APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 July 2, 2026
    Posted by Apple Product Security via Fulldisclosure on Jul 02APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 macOS Tahoe 26.5.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/127595. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. IOGPUFamily Available for: macOS Tahoe Impact: An app may […]
  • APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 July 2, 2026
    Posted by Apple Product Security via Fulldisclosure on Jul 02APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 iOS 26.5.2 and iPadOS 26.5.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/127594. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. IOGPUFamily Available for: iPhone 11 […]
  • pwnlift: symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root July 2, 2026
    Posted by Greg via Fulldisclosure on Jul 021. Advisory information ----------------------- Title: Symlink following and TOCTOU in pwnlift upload handler allow arbitrary file write as root Advisory: https://github.com/GregDurys/security-advisories GHSA: GHSA-2v7v-rhpw-m9w4 CVE: CVE-2026-56815 Class: CWE-59 (Improper Link Resolution Before File Access), CWE-367 (Time-of-check Time-of-use Race Condition) CVSS: 7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Date: 2026-06-27...

Customers