This website uses cookies

Read our Privacy policy and Terms of use for more information.

CyberEyeQ Weekly Podcast — Episode 34

2026-08-13 · ~9 min · Alex & Sarah

This week: 12 regulatory developments across 7 jurisdictions. Meta's $942M child-safety ruling rewrites platform liability, the Dutch NIS2 enters force Friday, CMMC's RFI window closes tomorrow, China Order No. 24 lands next week, and the EU CRA reporting obligation approaches in September. Plus: a record FinCEN penalty and the recidivism enforcement multiplier.

Top Stories

  1. Meta ordered to pay $942M with 5-year child-safety injunction — New Mexico court rejects Section 230 defense; first US ruling treating a social-media platform as a public nuisance. Five-year injunction mandates default teen privacy, age verification, notification blackout, and semiannual compliance reports. NM DOJ press release

  2. Netherlands NIS2 (Cyberbeveiligingswet) enters force 15 Aug — No transition period for 8,000+ entities. Duty of care, 24h/72h incident reporting, board-level governance, and NCSC-NL registration all apply immediately. Fines up to €10M / 2% turnover.

  3. CMMC Reform Task Force RFI closes 14 Aug (noon ET) — Defense-industrial-base input on cost drivers, control efficacy, and managed-service substitution. Task Force reports mid-September.

  4. China Order No. 24 effective 20 Aug — Annual data-security risk assessments for important-data processors, 20-working-day filing, 3-year retention, stop-processing sanctions for non-compliance.

  5. EU CRA Art. 14 reporting applies 11 Sep — 24h early warning / 72h full notification / 14-day final report for actively exploited vulnerabilities via ENISA's SRP (still under development).

Enforcement Watch

  • Meta — $942M (NM court, child safety). Source

  • UBS Financial Services — $125M (FinCEN, BSA/AML recidivism). Largest-ever BSA penalty on a broker-dealer. Source

  • Order Express — $250K (NYDFS, 23 NYCRR Part 500). Source

Compliance Action Items & Deadlines

  • 14 Aug — Submit CMMC Reform Task Force RFI input by noon ET.

  • 15 Aug — Register with NCSC-NL; stand up 24h/72h incident-reporting workflow for Dutch NIS2.

  • 20 Aug — Confirm important-data classification and stand up annual risk-assessment process for China Order No. 24.

  • 11 Sep — Map CRA-scoped products and build 24h/72h CSIRT/ENISA reporting channel.

  • Now — Benchmark teen-account defaults against the NM Meta order standard.

  • Now — Document closure of remediation findings — regulators are treating unremediated gaps as enforcement multipliers.

Show Notes

Full show notes with source links: Episode 34 Show Notes

This episode is based on CyberEyeQ Weekly Newsletter Issue #31 (August 13, 2026).

CyberEyeQ — Actionable Regulatory Intelligence · cybereyeq.com · [email protected]

This briefing is provided for informational purposes only and does not constitute legal advice.