Chrome, Firefox Updates Patch 115 Vulnerabilities
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.
The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.
The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.
The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek.
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek.
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance.
The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek.

When AI Breaks Out of the Sandbox What Happens When AI Escapes? AI assistants are gaining unprecedented access to the inner workings of businesses, but that trust comes with one...
The post Innovator Spotlight: Rubrik Zero Labs appeared first on Cyber Defense Magazine.
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
The post OpenAI Agents Exploited Linux Kernel Flaw on Companyβs Own Systems appeared first on SecurityWeek.
CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.
The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek.
Cybercriminals used to hacking home routers and security cameras have found another Internet-connected device to add to their botnets: your car, according to research published by Kaspersky Lab.
The post Malware Takes the Wheel: Kaspersky Finds First Car Head Unit-Specific Attack appeared first on The Security Ledger with Paul F. Roberts.
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.
Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it throughout its journey.
Yet despite this progress, one area continues to receive far less attention than it deserves: how data is shared.
Most organisations have become very good at protecting data while it is stored. Files are encrypted, key handling is properly managed, access is restricted and systems are monitored around the clock. However, once that information needs to leave the organisation, whether itβs being sent to a customer, supplier, auditor or business partner, the controls often become less robust.
Every day, organisations exchange contracts, financial information, employee records, legal documents and commercially sensitive files. More often than not, this happens via email attachments or cloud-based file-sharing services because they are familiar and convenient. The problem is that convenience does not always equal security.
Email remains one of the most common routes for cyber attacks. Phishing, spoofed domains, malicious attachments and business email compromise continue to account for a significant proportion of successful breaches. However, most incidents do not involve a sophisticated bad actor. The official UK annual Cyber Security Breaches Survey continues to show the majority of incidents stem from everyday mistakes.Β An email sent to the wrong recipient, an attachment forwarded outside the organisation or a file shared with overly broad permissions can expose sensitive information in seconds.
Human error remains one of the biggest cyber risks organisations face, particularly as businesses become increasingly connected. Information now flows constantly between employees, customers, suppliers, consultants and regulators. Every transfer creates another opportunity for something to go wrong.
What is often overlooked is that securing data is not just about protecting where it is stored. It is also about understanding the journey it takes.
Many organisations assume that because they operate in the UK, their sensitive information remains within UK borders. In reality, emails and attachments may be routed through multiple countries and cloud infrastructures before arriving at their destination. While this is often an invisible part of modern digital communications, it raises important questions around governance, compliance and data sovereignty.
For organisations operating in regulated sectors, this matters. Financial services firms, local authorities, healthcare providers and legal organisations are increasingly expected to demonstrate not only that data is protected, but also that it is managed responsibly throughout its entire lifecycle. Knowing where information is stored is only part of the picture. Understanding where it travels, who has access to it and how it is controlled has become equally important.
This is why conversations around geofencing and data sovereignty are gaining momentum. Rather than simply encrypting information and hoping for the best, organisations are beginning to ask whether they should have greater control over where sensitive data is permitted to travel. If businesses routinely place restrictions on the movement of physical assets, it seems only logical that they should apply similar thinking to digital information.
At the same time, regulators and auditors are asking more searching questions about how organisations exchange information with third parties. They want to understand how access is controlled, whether there is a complete audit trail and what safeguards exist once information leaves the organisation. These are no longer technical questions reserved for IT teams. They are governance issues that increasingly involve compliance, procurement, risk and senior leadership.
There is also a growing disconnect between the way organisations work and the security controls they have in place. Hybrid working, cloud collaboration and increasingly complex supply chains mean information rarely stays within a single organisation. Yet many businesses continue to rely on processes that were designed for a very different way of working.
This is where a change in mindset is needed.
Cybersecurity should not end when a document is saved securely on a server or in the cloud. Information is often at its most vulnerable when it is moving between people, organisations and systems. Protecting data in transit should therefore be considered just as important as protecting data at rest.
That does not mean making it harder for employees to do their jobs. Quite the opposite. Security should support the way people work, allowing information to be shared safely without creating unnecessary barriers or encouraging workarounds that introduce even greater risk.
Organisations need to take a more holistic view of information security. Protecting sensitive data means understanding its entire lifecycle, from creation and storage through to sharing, collaboration and eventual deletion. It means knowing not only who can access information, but where that information is travelling and whether that journey aligns with the organisationβs security, compliance and governance obligations.
Threats arenβt standing still, and neither are regulators. Focusing only on data thatβs sitting in storage means missing one of the biggest holes in your security. Itβs not enough to just lock data away; it needs to stay safe wherever it travels.
*DOQEX provides a secure data exchange and email gateway platform that helps businesses protect confidential information.
Β
The post The Hidden Risk in Data Transfer appeared first on IT Security Guru.

The Vulnerability Apple fixed a major security vulnerability in their image handling framework for both desktop and mobile devices on August 18, 2026. The vulnerability, which is tracked as CVE-2026-65346,...
The post Dangerous Apple Bug Lets Images Execute Malicious Code appeared first on Cyber Defense Magazine.
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.

A Modern Blueprint for Software Transparency On July 29, 2026, CISA linked up with the NSA, FBI, and 15 international cybersecurity partners to drop new joint guidance titled β2026 Minimum...
The post CISA Upgrades SBOM Standards appeared first on Cyber Defense Magazine.
Last Updated on July 31, 2026 by Narendra Sahoo
If you supply parts, software, or engineering services to a German automotive OEM or a Tier 1 supplier, you have likely been asked for one of two things: an ISO 27001 certificate or a TISAX label. The two get confused constantly, and the confusion is costly β companies routinely invest in the wrong assessment, discover it does not satisfy their customerβs contract clause, and start over. This guide breaks down what each framework covers, where they overlap, where they diverge, what each one actually costs and takes to achieve, and how to sequence the work so you are not paying for two separate efforts from scratch.
What Is ISO 27001?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It is sector-agnostic: a bank, a hospital, a software vendor, and a car parts manufacturer can all certify against the same standard, currently built around 93 Annex A controls under the 2022 revision. The certificate is issued by an accredited certification body, is valid for three years, and requires annual surveillance audits to stay active.
ISO 27001 focuses on the management system itself β how an organization identifies risk, selects controls, documents policies, and continuously improves. It contains no automotive-specific requirements, and an ISO 27001 certificate on its own is not accepted by OEMs as proof of TISAX compliance.
Building or renewing your ISO 27001 ISMS? VISTA InfoSecβs ISO 27001 consultants help you scope the management system correctly the first time β so it can later be extended into TISAX without starting over.
TISAX (Trusted Information Security Assessment Exchange) is the automotive industryβs shared assessment framework, built and maintained by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Rather than each OEM auditing every supplier separately, TISAX lets a supplier complete one assessment and share the resulting label with multiple customers through the ENX portal β which is why VW, BMW, Mercedes-Benz, Audi, Porsche, and their Tier 1 and Tier 2 suppliers now require it as a condition of doing business.
TISAX assessment criteria come from the VDA ISA (VDA Information Security Assessment) catalogue, itself built on ISO 27001βs structure. Under VDA ISA 6.0, the information security module contains 45 controls and 297 individual requirements at the High protection level (Assessment Level 2), with 17 additional requirements layered on for the Very High protection level (Assessment Level 3). Organizations are scored on a maturity model running from Level 0 (Incomplete) to Level 5 (Optimizing), and must reach at least Maturity Level 3 (βEstablishedβ) on every relevant audit objective to pass.
The underlying requirement set is largely the same for AL 2 and AL 3; what changes is audit depth. AL 2 relies on document review, interviews, and screen-shared evidence, while AL 3 adds physical, on-site verification.
Pricing and timelines vary by provider, company size, and starting maturity, so treat the figures below as planning ranges rather than fixed quotes. Independent consultancy estimates put the ENX-accredited auditorβs fee at roughly β¬3,000 for an AL2 remote assessment, rising to β¬9,000ββ¬12,000 for an AL3 on-site assessment; total project cost, including internal preparation or consulting support, more commonly lands between β¬10,000 and β¬35,000 depending on company size and how much of the ISMS already exists. End to end, companies starting from scratch typically need four to twelve months to reach a TISAX label, with the ENX label itself issued within two to four weeks of a successful assessment. For comparison, ISO 27001 certification for a small-to-mid-size organization is commonly estimated at $25,000β$50,000, with a three-to-eight month timeline depending on starting maturity.
Not sure which TISAX assessment level your OEM contract actually requires? VISTA InfoSec runs TISAX gap assessments against the VDA ISA catalogue and guides you through AL2 or AL3 readiness, including the prototype and data protection modules.
| Aspect | ISO 27001 | TISAX |
|---|---|---|
| Governing body | International Organization for Standardization (ISO/IEC) | ENX Association, based on the VDA ISA catalogue (German Association of the Automotive Industry) |
| Industry scope | Any industry, any organization size | Automotive industry supply chain only |
| Outcome | Certification, valid 3 years with annual surveillance audits | Assessment label, shared via the ENX portal, typically valid 3 years |
| Control set size | 93 Annex A controls (ISO 27001:2022) | 45 controls / 297 requirements at AL2 (High), +17 requirements for AL3 (Very High) under VDA ISA 6.0 |
| Assessment depth | Single certification level; auditor evaluates the ISMS as a whole | Three assessment levels (AL 1β3) tied to information sensitivity |
| Unique coverage | Broad ISMS: policies, risk treatment, asset management, access control | Everything in ISO 27001, plus prototype protection and a dedicated data protection (GDPR) module |
| Typical cost* | Roughly $25,000β$50,000 for a small organization; more for mid-size, per certification-body estimates | Provider audit fee β β¬3,000 (AL2) to β¬9,000ββ¬12,000 (AL3); total cost incl. internal preparation often β¬10,000ββ¬35,000, per consultancy estimates |
| Typical timeline* | Roughly 3β8 months depending on company size and starting maturity | Roughly 4β12 months from a standing start; label issuance 2β4 weeks after a successful assessment |
| Who requires it | Customers, regulators, and partners across any sector | OEMs such as VW, BMW, Mercedes-Benz, Audi, and Porsche, and their Tier 1/Tier 2 suppliers |
| Result portability | Not automatically recognized by automotive OEMs as a TISAX substitute | Shared once via ENX and reused across multiple OEM relationships, avoiding repeat audits |
*Cost and timeline figures are third-party planning estimates, not official ENX or ISO pricing β confirm current rates with your chosen audit provider.
The following is a representative composite scenario based on common engagement patterns our advisory team observes, not a specific named client.
In Practice
A Tier 2 automotive electronics supplier already held ISO 27001 certification, achieved originally to satisfy a non-automotive customerβs security questionnaire. When the company began supplying a component program for a German OEM, the OEMβs onboarding process required a TISAX AL2 label rather than the existing ISO certificate. Because the ISMS, risk register, and access control policies were already in place, the gap assessment against the VDA ISA catalogue found roughly 70% of requirements already met. The remaining work centered on building out the prototype protection controls for the area where test units were stored and adding the data protection module to cover personal data shared by the OEM. The AL2 assessment was scheduled and passed within roughly five months of the gap assessment, avoiding a second ISMS build from zero.
For most suppliers in the automotive value chain, the practical answer is: you need TISAX, and ISO 27001 is the fastest, most defensible way to get there. Because VDA ISA is structurally derived from ISO 27001, an organization that has already built policies, risk assessments, an asset inventory, and access controls to ISO 27001 standard typically only needs to layer on the automotive-specific controls β prototype protection, the data protection module, and supplier chain requirements β to be ready for a TISAX assessment. Going the other direction does not work: an OEM will not accept an ISO 27001 certificate as a substitute for a TISAX label, because it does not evaluate prototype handling or the automotive supply chain controls the OEM actually cares about.
Donβt Miss the Corrective Action Window
If an audit objective falls short of Maturity Level 3, the supplier and audit provider agree a corrective action plan, and the supplier has nine months from the last day of the main assessment to implement it and pass a follow-up review. Missing that window invalidates the assessment and requires starting over β a strong argument for budgeting realistic internal preparation time rather than treating the audit date as a hard deadline.
Germanyβs NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) has been in force since December 2025 and is expected to bring roughly 29,500 companies into scope during 2026, including many automotive suppliers that previously sat outside formal cybersecurity regulation. NIS2 requires an ISMS, documented risk management, business continuity planning, and strict incident reporting timelines (24 hours, 72 hours, and one month), backed by fines of up to β¬10 million or 2% of global turnover.
ENXβs own analysis concludes that organizations holding a TISAX label under the ISA 6.0 catalogue are already well positioned to meet NIS2βs core requirements β risk management, incident response, supply chain security, and governance overlap substantially. In practical terms, automotive suppliers who invest in TISAX, built on an ISO 27001 foundation, are addressing three compliance demands β OEM contracts, international security expectations, and German/EU regulation β with one coordinated program instead of three separate ones.
Practical Framework Checklist
Key Takeaways
No. TISAX produces an assessment label shared through the ENX portal, not an ISO certificate. The underlying criteria (VDA ISA) are built on ISO 27001 but add automotive-specific requirements, including prototype protection and a dedicated data protection module that ISO 27001 does not cover.
No. OEMs and Tier 1 suppliers in the German automotive industry require a valid TISAX label specifically. ISO 27001 certification significantly accelerates TISAX readiness but is not accepted as a substitute.
Third-party estimates put the ENX-accredited auditorβs fee at roughly β¬3,000 for AL2 and β¬9,000ββ¬12,000 for AL3, with total project cost including internal preparation commonly landing between β¬10,000 and β¬35,000 depending on company size and starting maturity. Confirm current rates directly with your chosen audit provider.
Companies starting from scratch typically need four to twelve months to reach a TISAX label; the label itself is issued two to four weeks after a successful assessment. Organizations that already hold ISO 27001 typically move faster, since policies, risk management, and core controls are already in place.
This is set by your OEM customer based on the sensitivity of the information and prototypes you handle. AL 2 (remote/hybrid audit) is the most common requirement; AL 3 (full on-site audit) applies when highly sensitive or physical prototype data is involved.
The supplier and audit provider agree a corrective action plan, and the supplier has nine months from the last day of the main assessment to implement it and pass a follow-up review. Missing that window invalidates the assessment and requires starting over.
TISAX does not automatically equal NIS2 compliance, but ENXβs analysis found that TISAX-labeled organizations under ISA 6.0 already meet a substantial portion of NIS2βs core requirements around risk management, incident response, and governance, making the gap to full NIS2 compliance considerably smaller.
ISO 27001 and TISAX are not competing choices β they are sequential ones. Suppliers who treat ISO 27001 as the foundation and TISAX as the automotive-specific layer on top get to a passing assessment faster and avoid rebuilding an ISMS from scratch. Suppliers who wait until an OEM contract forces the question end up doing both under deadline pressure, at a higher cost, with less room to fix gaps before an auditor finds them.
Get Assessment-Ready With VISTA InfoSec
VISTA InfoSec works with automotive suppliers across the value chain to build ISO 27001-aligned ISMS programs and prepare for TISAX assessment β including gap analysis against the VDA ISA catalogue, prototype and data protection module readiness, and guidance on selecting the right assessment level for your OEM relationships. Our team can help you sequence the work so you satisfy all three with one coordinated program instead of three separate ones.
The post TISAX vs ISO 27001: What German Automotive Suppliers Need to Know appeared first on Information Security Consulting Company - VISTA InfoSec.