ComplexDiscovery is an online publication highlighting cybersecurity, information governance, and legal discovery insight and intelligence.

Tallinn, Estonia
✈️ Flying to the Camino Portugués Coastal Route: 4,700 miles to walk 167 🇵🇹 Houston to Porto is about 4,700 miles in a straight line. The walk on the other end is 167. 🛫 The flight leaves this afternoon. Thursday it lands in Porto, and the transfer runs up the coast to Matosinhos. Friday morning three walkers from ComplexDiscovery start north, and 15 days later the route ends in Santiago de Compostela. 🏛️ The route is the Camino Portugués Coastal Route. Up the Portuguese shore to the mouth of the Minho, across into Galicia by boat, then inland at Pontevedra onto the Variante Espiritual, and finally up the Ría de Arousa by water into Padrón. 👣 Posts will follow from the walk, and it is worth saying up front what they will be about, because it is not quite what you would expect from a pilgrimage. 🔎 Almost everything on this route comes with two histories. There is what the record establishes, and there is what tradition has attached to it over a thousand years. The two are usually different. The gap between them is the interesting part. 🖥️ So that is the series. One thing per stage worth looking at, what can actually be documented about it, and what got added later. Some of it sits awkwardly next to the tourist copy. None of it makes the walk smaller. 💻 Working with digital content and records for a living turns out to be reasonable preparation. 🗓️ Next update Friday, from a beach north of Porto where the Roman ruins are partly reproductions, and the museum says so. 📰 Read the route overview from ComplexDiscovery OÜ at complexd.blog/4xc91J2. #CaminoDeSantiago #CaminoPortugues #VarianteEspiritual #Camino2026 #Pilgrimage #Galicia #Portugal #InformationGovernance #eDiscovery #Provenance
73
🇷🇺 How a general's walk across a bridge tested Putin's claim to Svyatohirsk 🔎 Putin told the world on Sept. 1 that Russian forces had taken Svyatohirsk. Six days later, Brig. Gen. Andriy Biletskyi walked across the town’s bridge on camera, unhelmeted, and told Russia’s leadership to take off their clown noses. Between those moments, four Institute for the Study of War assessments, a Kyiv Post fact check, Reuters reporting from Moscow, and a Conflict Intelligence Team sitrep supplied every step a verifier would run: the claim in the claimant’s words, the doctored evidence offered for it, a Russian milblogger’s admission, an unmoved DeepState map and a bakery that was open. 💡 Cybersecurity, data privacy, compliance and eDiscovery professionals will recognize the sequence as authentication under adversarial conditions. It mattered beyond one town because, Reuters reported, Putin told two U.S. envoys on Sept. 5 that Russia was making “real progress,” and a person close to the Kremlin said his year-end confidence rests on his commanders’ reports. 👀 Watch next for what follows the Sept. 8 Trump-Putin call, whether the three-way format the envoys hoped to revive takes shape, and whether the front-line ceasefire Russia did not accept resurfaces. 📰 Read the complete article from ComplexDiscovery OÜ's geopolitics beat at complexd.blog/4xcxcXK. #Ukraine #Russia #ISW #OSINT #Verification #InformationIntegrity #Cybersecurity #eDiscovery
57
🔎 Law professors propose a three-part test for what counts as AI slop ⚖️ Two Boston University law professors have given policymakers something the AI slop argument has lacked: a test with edges. Jessica Silbey and Woodrow Hartzog provisionally define slop as machine output produced with little exertion that shifts the burden onto recipients and erodes the domain it lands in. The test turns on effort, imposition and domain degradation rather than on quality, and that is what makes it usable. It separates a clumsy first draft, which is fine, from a polished report nobody will stand behind, which is not. 🕛️ The timing sharpens the point. Transparency duties under Article 50 of the EU AI Act and California’s AI Transparency Act both became operative Aug. 2, with three more compliance dates through 2028 and a penalty formula that inverts for smaller firms. Meanwhile, the courts, where the counting has actually been done, are what the paper’s policy catalog never reaches. A public database of decisions involving hallucinated material stood at 2,022 when checked Sept. 7. 👀 Watch two developments next. Whether detection tooling hardens into an enforcement layer, carrying its false-positive problem. And whether governance programs start treating unattributable AI output as a retention and defensibility question rather than an HR one. 📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at buff.ly/GZMnf3O. #AISlop #InformationGovernance #eDiscovery #AIGovernance #EUAIAct #AIRegulation #LegalTech
56
🇵🇹 Camino Portugués Coastal Route: what the record shows and what tradition added 🇪🇸 The Pilgrim's Reception Office in Santiago issued 530,987 Compostelas in 2025, its highest annual figure, and the Portuguese routes accounted for 190,344 of them. ComplexDiscovery walks the coastal one this month, Matosinhos to Santiago, with the Variante Espiritual for the final stages. ⛪️ What the route offers, beyond the Atlantic and the granite, is an unusually clear view of how institutions handle their own histories. 👣 A monastery on this walk publishes its founding legend and labels it a legend. A Spanish national archive supports Baiona's Columbus claim, then states in the next sentence that no testimony of the report behind it survives. 📃 Set against those: a heritage decree credited with a property count it never states, a hillfort population that circulates as a figure and was produced as an estimate, promotional superlatives with no institutional origin, and a World Heritage listing the route does not hold. 🔎 For readers whose work turns on provenance, that contrast is the story. The habits that separate a documented fact from an attached tradition are the habits that separate an established finding from a confidently repeated claim. 💡 This piece opens Camino Month at ComplexDiscovery OÜ. 📰 Read the complete article from ComplexDiscovery OÜ at complexd.blog/4xc91J2. #CaminoDeSantiago #CaminoPortugues #VarianteEspiritual #Camino2026 #Pilgrimage #Galicia #Portugal #InformationGovernance #eDiscovery #Provenance
60
💼 D.C.'s highest court struck a brief over four fake citations and called its own sanctions authority unclear 🏛️ A court of last resort struck an institutional litigant’s brief this month over four citations that did not exist. Its most quotable line, that “every firm attorney who signed the brief bears some responsibility,” is real. Senior Judge Stephen H. Glickman wrote separately to urge a narrower reading, and to argue that existing rules appear to leave the court little beyond a published admonishment and the strike itself. Rule 38 in the District reaches frivolous appeals, but not briefs; its Rule 46 covers only bar admission, and inherent authority needs a bad-faith finding this record would not support. ⚖️ Practitioners who stop at that line will miss the qualification, and that gap is where compliance effort can get misdirected. Anyone building AI governance for a regulated function should read what the order leaves unanswered: who reviewed the brief, and how the drafter was trained and supervised. 🔎 Two things to carry. The panel called the full scope of its sanctions authority unclear and sent the question to its Rules Committee, where the answer will come from. And the vendor hallucination figures the order quotes, now in two published decisions, assign the numbers to the wrong products; the Stanford study says the reverse. 📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at buff.ly/0cUbNfj. #LegalTech #eDiscovery #InformationGovernance #AIGovernance #LegalAI #ArtificialIntelligence #LawFirmCompliance #AIHallucinations #AppellateLaw
2
58
🗓️ In six days the Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours of becoming aware. The platform they must file through has no published web address. 💼 ENISA updated its guidance Sept. 4, and the update is the story. No API at launch, so every filing against the clock is a person and a form. No voluntary reporting through it at launch. If it is down, ENISA says to wait. And ENISA discloses that its 72-hour counter can show a report overdue before 72 hours have run from awareness. 🕛️ A second timing question sits underneath. The regulation’s penalty article is not among the provisions that take effect early, so on the face of the text its fine ceilings apply only from Dec. 11, 2027. No official guidance reviewed addresses enforcement before then. 🔎 Anyone checking whether open-source stewards face fines should read the corrected regulation. A July 2025 correction moved the boundary of the penalty exclusions, and the original text gives the wrong answer. 🔐 For cybersecurity, privacy, compliance, and eDiscovery readers, the operative question is when a manufacturer became aware – a judgment to be evidenced rather than defined. Watch for the address and the counter logic. 📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at complexd.blog/4cZL5kE. #CyberResilienceAct #CRA #ENISA #VulnerabilityManagement #Cybersecurity #InfoGov #eDiscovery
1
1
66
📢 A fresh wave of legal-technology launches just hit the market this week — Querious integrated with 8am MyCase and Descrybe brought its Legal Engine into Microsoft 365 Copilot, both announced on September 3, 2026, following iManage's Gemini Enterprise for Legal rollout in late August. ⚔️ Every one of those launch teams will eventually sit in a room and reach agreement on go-to-market plans, and this analysis argues that the moment everyone nods in unison is exactly the moment to slow down and ask who was not in the room. 📘 Drawing on Clausewitz's center of gravity, Sun Tzu's positioning discipline, Everett Rogers' adopter categories, Geoffrey Moore's chasm and whole-product concepts, Igor Ansoff's growth matrix, Clayton Christensen's innovator's dilemma, and Gary Klein's premortem technique, the piece builds a 15-question "Launch Doctrine" gate for cybersecurity, information governance, eDiscovery, and legal technology launches. 🖥️ Concrete industry examples ground the framework, from antitrust second requests as a demanding beachhead segment to technology-assisted review's long march toward judicial defensibility and generative-AI review tools now facing mainstream evidentiary scrutiny. 🔎 Read the complete analysis from ComplexDiscovery OÜ complexd.blog/4eTuVLa. #LaunchStrategy #ProductLaunch #Cybersecurity #InformationGovernance #eDiscovery #LegalTechnology #B2BMarketing #StrategicPlanning
1
81
⚖️ A lawyer fed AI citations to his own regulator, and the tribunal struck him off 🏛️ A disciplinary tribunal in London has removed a lawyer from the register of foreign lawyers over legal authorities that generative AI invented, and those authorities sat in his defense against the regulator prosecuting him. When the regulator’s counsel flagged the errors, he answered with an email he had also drafted using AI, and that email carried further false material. The Solicitors Disciplinary Tribunal says this is the first time a lawyer’s use of AI in legal proceedings has been litigated before it. 🔎 Professionals in cybersecurity, data privacy, regulatory compliance and eDiscovery should read the culpability findings rather than the headline. The tribunal weighed both how Kumar began using AI and what he did once the errors were identified, and it gave very substantial weight to the repetition. The same distinction runs through incident-response practice, where the handling of a defect is judged separately from the defect. 👀 Watch the referral route. Courts on both sides of the Atlantic have referred AI citation failures to regulators, though no court referred Kumar; the SRA was already prosecuting him. The Solicitors Regulation Authority (SRA) said it received 42 reports of potential AI misuse in the year to July 2026, with investigations underway. 📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at complexd.blog/4yloBTw. #eDiscovery #LegalTech #AIGovernance #InformationGovernance #LegalAI #AIRisk #Compliance #LegalOps
54
🔍 Who really controls your cloud provider? Europe’s proposed Cloud and AI Development Act could expand cloud audits beyond data residency and security, bringing ownership, governance, and control directly into the audit process. 📋 Auditors may be asked to examine: ✅ Ownership structures and cap tables ✅ Ultimate beneficial owners ✅ Strategic decision-making bodies ✅ Voting thresholds and control mechanisms ✅ Shareholders holding 5% or more of ownership or voting rights 🌍 As concerns around digital sovereignty and strategic technology grow, the proposal highlights a critical question for buyers: Is vendor risk only about where data resides, or also about who controls the company behind the service? 💡 Regardless of whether the regulation is adopted, the draft offers a practical framework for stronger vendor due diligence today. 📖 Read the complete article from ComplexDiscovery OÜ's data privacy and protection beat at complexd.blog/4qRebbA. #CloudComputing #Cybersecurity #DataPrivacy #RiskManagement #VendorManagement #Compliance #DigitalSovereignty #LegalTech
26
🚨 When the Agent Becomes a Witness 🤖 As organizations increasingly rely on AI agents to search, classify, recommend, and act, a critical question is emerging: Can agent-generated activity be proven, reconstructed, and defended when it becomes relevant to litigation, investigations, audits, or regulatory reviews? 📔 This new Oxford-style tutorial from ComplexDiscovery examines the intersection of AI, evidence, accountability, and discovery. Through 21 contestable propositions, it explores agent logs, privilege, retention, oversight, authentication, proportionality, and testimony in an era where machine actions may become part of the evidentiary record. Key Questions ✅ Are AI logs evidence or simply telemetry? ✅ Can agent activity be reconstructed months or years after an event? ✅ Who can explain an AI agent's conduct when challenged by regulators, auditors, investigators, or courts? ✅ Are today's governance, procurement, and logging decisions sufficient to answer tomorrow's questions? ⚖️ Capability without accountability may create significant operational, legal, and governance risks. As agentic AI adoption accelerates, organizations should consider not only what systems can do, but also how actions can be verified, explained, and defended when scrutiny arrives. 🔗 Read the full tutorial from ComplexDiscovery OÜ at complexd.blog/4cO37pW. #ArtificialIntelligence #GenerativeAI #AgenticAI #eDiscovery #InformationGovernance #LegalTech #DigitalEvidence #AIGovernance #Compliance #Cybersecurity #DataGovernance #RiskManagement #LegalOperations #TechnologyLeadership
1
33
🔎 Germany names Russia for the Leipzig drone, and keeps most of its evidence out of view ✈️ Germany’s Sept. 1 attribution of the Leipzig/Halle airport drone to Russia came with a consulate closure, a lease termination and a sanctions push, and with categories of evidence rather than the underlying material. The Federal Prosecutor General’s Aug. 6 release names no suspect, no state and no service. The ministers named the state four weeks later but no suspect or intelligence service, though ARD reported that investigators had turned up at least one person believed to be tied to a Russian service and had made no arrests. Most physical detail in view, from the Semtex in a tin can to the DNA traces, arrived through unnamed security sources, and some of it has already been revised: the reported DNA link to the 2024 DHL fire was contradicted within a day, and the reported collision with a DHL freighter is now assessed as probably a bird. 🔐 For cybersecurity, information governance, and eDiscovery readers, this is attribution under two standards: the sufficient-probability standard one lawyer says diplomatic measures require, and the criminal standard a Stuttgart court applied on Aug. 18 to convict one recruit and acquit two. ⚖️ Watch the Federal Prosecutor General’s office for an arrest or an indictment, and the Bundestag for the intelligence-law reform. 📰 Read the complete article from ComplexDiscovery OÜ's geopolitics beat at complexd.blog/4ylmAH8. #Leipzig #HybridWarfare #Attribution #Cybersecurity #InfoGov #eDiscovery #DigitalForensics #Germany #Russia #NATO #Geopolitics #ChainOfCustody
1
48
📍 EDRM published its new map and the reasoning behind what it kept 🖥️ The diagram that has organized eDiscovery vocabulary for two decades is final, and EDRM published the argument along with it. EDRM 2.0 arrived Tuesday carrying four structural shifts: information governance moves underneath the whole lifecycle, four early-stage activities group into a Data Acquisition framework, disposition becomes a phase of the diagram for the first time, and analysis runs as a continuous band across every stage. EDRM then grouped public comment into eight sections. The trustees say one produced two adjustments, both to how the diagram reads. The other seven asked to change what the diagram contains or what it calls things and received written responses explaining why the trustees made no change. Those answers are the part worth reading twice. ⚖️ Practitioners across three disciplines have work to do here. Records and governance teams get a disposition definition they can hold against their retention schedules. Security teams get a widely used framework that names deletion as a phase, which strengthens the internal argument for minimization on breach-hold data. Legal operations groups and providers should test their RFP and statement-of-work language against the Data Acquisition grouping before buyers start quoting it. 👀 Watch the thought leadership phase now beginning, because the terms that settle there may shape procurement documents later. 📰 Read the complete article from ComplexDiscovery OÜ's eDiscovery beat at complexd.blog/4i3A6u1. #eDiscovery #EDRM #InformationGovernance #LegalTech #DataGovernance #RecordsManagement #LegalOperations #DefensibleDeletion #Cybersecurity #eDisclosure
24
🔎 When the Evidence Never Arrives 🇪🇪 Estonia scrambled NATO fighter jets and activated air defenses after drones approached and briefly crossed its border. Yet the most important detail may be what didn't happen: no crash, no debris, no recoverable evidence. 💡 The incident highlights a challenge familiar to cybersecurity, information governance, and eDiscovery professionals: establishing facts when critical evidence sits beyond accessible channels or never materializes at all. Estonia has faced this before, reaching conclusions about a drone's likely origin while remaining unable to determine responsibility due to limits on evidence collection. 🚧 In contested environments, origin and responsibility are not the same finding. Effective decision-making depends on understanding the difference and resisting the urge to bridge evidentiary gaps with assumptions. 🕛️ A timely reminder that the future of national security may increasingly hinge on principles that legal, compliance, and investigative professionals already know well: preserve what you can prove, clearly mark what you cannot, and build conclusions only as far as the record allows. 📰 Read the complete article from ComplexDiscovery OÜ's geopolitics beat at complexdiscovery.com/estonia…. #Geopolitics #Cybersecurity #eDiscovery #InformationGovernance #RiskManagement #Evidence #NATO #DataGovernance #Investigation
50
🔐 Berlin Refused the Ransom Before the Auction Opened 🐻 Berlin's decision to reject a ransomware demand before attackers publicly launched an auction for allegedly stolen government data highlights a growing challenge in cyber incidents: the legal and ethical questions begin long before the facts are fully known. ⚖️ The Real Question Isn't Just About the Breach As the Rhysida ransomware group claims to hold millions of files from Berlin state agencies, the more immediate issue for legal and compliance professionals may be: What happens if leaked information becomes publicly available? 📂 When Stolen Data Appears Online Can lawyers review it? Must they notify opposing counsel? Does privilege survive unauthorized disclosure? The answers vary by jurisdiction, and existing ethics rules offer far less certainty than many practitioners assume. 🌍 Cross-Border Complexity Matters This incident underscores how cybersecurity, legal ethics, data protection, and international law increasingly intersect. What may be permissible in one jurisdiction can raise entirely different questions in another. 💡 Key Takeaway Organizations often prepare for preserving evidence after a breach. Fewer prepare for a different scenario: when potentially relevant evidence arrives through an unauthorized public leak. The question then becomes not what must be preserved, but who gets to decide whether anyone should access it at all. 📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at complexdiscovery.com/berlin-…. #Cybersecurity #eDiscovery #DataPrivacy #InformationGovernance #LegalTech #Ransomware #DigitalRisk #Compliance #DataBreach
162
🔍 NIST Wants Comment on AI-Drafted CSF Profiles, and Its Guide Never Says Authentication 🤖 AI can draft cybersecurity profiles in hours instead of weeks, according to NIST's new draft guidance on using generative AI for Cybersecurity Framework (CSF) analysis and reporting. ⚖️ But one notable omission stands out: the guide never addresses authentication, evidentiary foundations, chain of custody, or other issues that may become critical when AI-generated outputs are later scrutinized in litigation, investigations, or regulatory reviews. 📋 As organizations increasingly rely on AI for compliance and cybersecurity assessments, the question may not be whether the output is useful, but whether someone can explain and defend how it was created. 📅 NIST is accepting public comments on the draft through October 15, 2026, creating an opportunity for practitioners to help shape the future of AI-assisted cybersecurity reporting. 📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at complexdiscovery.com/nist-wa…. #NIST #Cybersecurity #AI #GenerativeAI #Governance #Compliance #eDiscovery #InformationGovernance #RiskManagement #LegalTech #DataGovernance #CyberRisk
32
📢 When Capability Claims Meet Inspection 💥 A ruler whose banned stockpiles were gone spent more than a decade persuading the world they might remain. The irony is that the U.S. Army's own history of the Iraq War later concluded that the clearest beneficiary of the conflict was Iran, the very rival that strategic ambiguity was intended to deter. 🔎 A recent ComplexDiscovery analysis explores what happens when perceived capability outlives actual capability and why that lesson extends far beyond geopolitics. From Saddam Hussein's postwar explanations to Enron's collapse and today's AI-washing enforcement actions, the article examines a familiar pattern: claims that get ahead of verification. 💼 In business, the mechanism can take different forms: • Offerings announced ahead of capability • Revenue recognized ahead of economics • Performance sustained by underinvesting in future capacity • Marketing narratives that outpace operational reality The consequences are not always immediate. Eventually, however, inspectors arrive. 🗓️ Today, those inspectors increasingly include regulators, courts, customers, auditors, and procurement teams. Recent actions involving unsupported AI claims suggest that "trust us" is giving way to "show us." Sales decks, security questionnaires, and product claims may ultimately become evidence when capabilities are challenged. ⚖️ For cybersecurity, data privacy, compliance, information governance, and eDiscovery professionals, the role is becoming clear: test whether asserted capabilities can withstand verification. ❓️The question worth watching next: Will AI enforcement continue to expand, and will procurement shift from collecting assurances to demanding evidence? 🔗 Read the complete article from ComplexDiscovery OÜ's leadership beat at complexd.blog/45epfpq #AI #Leadership #Governance #Compliance #Cybersecurity #InformationGovernance #eDiscovery #LegalTech #RiskManagement #AIWashing #TrustButVerify
61
🔎 When the agent becomes a witness: an Oxford-style tutorial on AI evidence, accountability and discovery 🏛️ Regulators moved the deadline. Litigation did not. When the EU AI Act reached general application on Aug. 2, 2026, the record-keeping duties most practitioners associate with it, automatic event logging under Article 12 and the six-month retention floor under Article 26(6), did not take effect. The AI omnibus in force July 27, 2026 pushed those Chapter III obligations to Dec. 2, 2027 and Aug. 2, 2028. The questions they were written to answer arrived anyway, in 2026 rulings on AI prompts, privilege and generative review. 📚️ This tutorial gives ComplexDiscovery OÜ’s three audiences a way to work the problem before it is theirs. Discovery teams face preservation and production decisions about agent traces that sit on two sets of retention clocks and rarely appear on a custodian chart. Information governance teams set the instrumentation and retention policies that decide, years in advance, which questions a record can answer. Security teams own the telemetry everyone else will treat as evidence. 💡 Three things are worth watching this autumn: the Advisory Committee’s return to proposed Rule 707, the outcome and publication of ISO/IEC 24970, and the first order that squarely tests authentication of an agent log. 📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at complexd.blog/4cO37pW. #eDiscovery #InformationGovernance #Cybersecurity #AIGovernance #LegalTech #AIAct #AgenticAI #EvidenceLaw #DataPrivacy
1
54
⚖️ The Meta settlement built an age-assurance architecture and gave Meta a release to go with it 💼 Meta announced a separate Texas accord Aug. 26, the day Judge Yvonne Gonzalez Rogers entered a consent judgment in the federal case in California. Thirty-three states brought it in 2023; 29 tried it. The judgment implements a broader agreement of 51 attorneys general; Meta’s roughly $18 billion umbrella spans 52, Texas included. It matters to companies which never signed it: the settling attorneys general released specified COPPA and analogous state-law claims over the data Meta needs to detect users under 13, and Meta’s commitment to build the model turns on that release. 🔎 For privacy and eDiscovery readers, the architecture is the story. Covered age-assurance data is held only long enough to determine age status, subject to permissions for specified U13 Data and Retainable Data. The rule does not reach a user’s stated date of birth, stated age or the outcome of the Age Assurance Method. 🖥️ Watch two developments. Paxton’s TikTok trial arrives this fall, and roughly $5.3 billion remains contingent on Industry-Wide Adoption by Snap, TikTok, YouTube and qualifying new entrants, plus a separate monetary trigger for Core Industry Members with annual profits above $10 billion. That trigger may be satisfied through qualifying state-by-state obligations or a qualifying multistate settlement. 📰 Read the complete article from ComplexDiscovery OÜ's data privacy and protection beat at complexdiscovery.com/the-met…. #eDiscovery #InformationGovernance #DataPrivacy #Cybersecurity #AgeAssurance #COPPA #LegalTech #Compliance #DataMinimization #PrivacyLaw
1
52
⚖️ Discernis bets its architecture answers a Colorado judge 🏛️ A federal magistrate in Colorado spent part of March writing contract terms into a protective order, and a seed-stage discovery vendor has since made that order the centerpiece of its marketing. The appeal is easy to see. Morgan v. V2X, Inc. bars confidential material from any AI platform unless the provider is contractually barred from training on inputs and from passing them onward except as essential to delivering the service, and Discernis Discovery describes an architecture that speaks to those concerns. 💼 What this piece adds is the distance between them. Morgan asks for contractual prohibitions, a contractual deletion right, and retained written documentation. Discernis publishes architecture, deployment descriptions, and a 30-day removal window. Those are different kinds of claim, and the public pages do not show the customer contract. The company also publishes three statements of throughput and three ways of stating performance, a reminder that vendor numbers need a denominator. 🔎 Practitioners in cybersecurity, data privacy, regulatory compliance and eDiscovery share one interest here, because a court order that specifies what a vendor’s contract must prohibit turns procurement language into a discovery obligation. Watch whether other courts adopt Braswell’s provision, and whether vendors start publishing contract terms rather than architecture. 🖥️ Read the complete article from ComplexDiscovery OÜ's eDiscovery beat at complexdiscovery.com/discern…. #eDiscovery #LegalTech #InformationGovernance #Cybersecurity #AIGovernance #LegalAI #DocumentReview #DataPrivacy #LegalOps #VendorRisk
1
37
📚 Explain It Like a Fifth Grader: Four days offline, and a threshold already under review 🧒 The fifth-grader version: Imagine a small power plant gets hit by hackers and has to stop working for four days. Nobody loses electricity, but people start asking an important question: "Should this have been reported to the government?" The tricky part is that there are special rules about which power companies have to report cyberattacks. Those rules depend on things like how big the company is and how many people are affected. Because nobody knows exactly which company was involved, it's hard to tell whether the attack crossed the line that requires reporting. 💡 Why it matters: This isn't just a story about a cyberattack. It's a story about whether today's cybersecurity rules are keeping up with reality. If a small power facility can be shut down for days by hackers, regulators may need to rethink where the reporting and oversight boundaries should be drawn. 🔍 Big takeaway: Sometimes a rule can look right on paper, but a real-world event quickly reveals reasons to review it. 🔗 Read the full article from ComplexDiscovery OÜ at complexd.blog/4wLmNBW. #ExplainItLikeAFifthGrader #ComplexDiscovery #Cybersecurity #CriticalInfrastructure #InformationGovernance #DigitalRisk #eDiscovery #Regulation
41