The Compliance Brief for security leaders
Every Tuesday, the breaches and incidents from the past week, and the decisions they put in front of whoever owns security at a growing company.
At a company without a full-time CISO, somebody still owns the decisions: who gets told about an incident, which vendor is too risky, what the board hears. The Compliance Brief is written for that person, one email a week with the incidents worth knowing about and a plain view on each.
Below are the stories from recent issues that bear on security leadership, each with the short version and a link to the full take.
Free weekly email
Get the next issue on Tuesday
Join the list and the next issue arrives Tuesday morning. Or read a few below first.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Latest on breaches, incidents and security leadership
- Ottawa is looking at how a breach was disclosed, not only how it happened
Canada's federal privacy regulator opened an investigation into IDScan following a data breach. - A stolen OAuth token from a former employee's laptop
CrowdSec confirmed that attackers took the contents of 170 private repositories from its GitHub organisation. - A departed employee's GitHub account was still live, and 170 private repos walked
CrowdSec disclosed that an attacker copied roughly 170 of its private GitHub repositories in May using the account of an employee who had recently left the company. - Revolut handed over customer data to someone pretending to be a government
Revolut confirmed that an unauthorized party obtained customer information by submitting a fraudulent data request from a legitimate government email domain. - Trezor's supplier breach keeps growing, and it was never Trezor's system
Trezor says a breach at its supplier ShipMonk is considerably worse than first reported, now affecting around 81,000 customers. - Revolut gave customer data to someone posing as a government agency
Revolut disclosed a breach after sharing customer data with a threat actor impersonating a government agency. - Delaware amends its privacy and breach notification laws
On September 2, 2026, Delaware's governor signed HB 380 and HB 381. - Thomson Reuters court software breached in March, disclosed in September
Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, in March 2026.
Every issue on HireACISO
- Issue 8: Ottawa is looking at how a breach was disclosed, not only how it happened
- Issue 7: A departed employee's GitHub account was still live, and 170 private repos walked
- Issue 6: Trezor's supplier breach keeps growing, and it was never Trezor's system
- Issue 5: Thomson Reuters court software breached in March, disclosed in September
- Issue 4: McKesson breach came through third-party applications
- Issue 3: SickKids gets hit through somebody else's software
- Issue 1: LexisNexis pulled products offline over a third-party vendor incident
Every issue in full, including the stories outside breaches, incidents and security leadership, is in the archive on traztech.ca. Issues with nothing on breaches, incidents and security leadership are listed there and not here.
Questions
How often does The Compliance Brief arrive?
Once a week, on Tuesday morning. Each issue covers the past week in five stories or so, with what happened and a short take on what it means for founders and executives who own security.
What does it cost?
Nothing. It is written by Jacob Masse, Principal at TrazTech Inc., which operates HireACISO. There is no paid tier.
Will signing up here send me anything else?
No. The form on this page adds you to The Compliance Brief and nothing else. Downloading a checklist elsewhere on the site is a separate signup, and it says what it sends before you give an address.
How do I stop it?
Every issue ends with a one-click unsubscribe link, and it is honoured immediately. Replying to any issue also reaches Jacob directly.
Free weekly email
Get it every Tuesday
One email a week on breaches, incidents and security leadership. Free, and one click to leave.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.