- Cybersecurity Docket
- Posts
- Tata Data Breach Prompts Tightening of Internal Controls
Tata Data Breach Prompts Tightening of Internal Controls
Plus, legal tech firm sues U.S. government over order limiting foreign access to top-tier Anthropic models.

Good morning! Here’s what’s up.

People
David Stauss announced in a LinkedIn post that he has founded a new boutique law firm, Stauss PLLC, to provide “practical, risk-based, understandable advice” on privacy, artificial intelligence, and cybersecurity issues. Previous roles include serving as a partner at Troutman Pepper Locke in the firm’s privacy and cyber practice group; and heading the privacy and cybersecurity practice at Husch Blackwell.
Philip Martin has joined Uber as chief information security officer. Previously, he was chief security officer at Coinbase.

Clips ✂️
EXCLUSIVE: Apple supplier Tata tightens internal controls after data breach, sources say
Tata Electronics, a key Indian supplier to Apple has restricted internal access to sensitive systems as it investigates a leak of thousands of secret client files on the dark web, a Tata source and two industry officials said.
Tata has also hired a global consultant to conduct a forensic audit and has reported the incident to the Indian government and its clients, said the Tata source, declining to be named given the sensitivity of the matter.
Reuters reported this week that ransomware group World Leaks posted more than 200,000 files to the dark web, including purported component design papers from Apple and Tesla, both of which are Tata clients. Reuters could not verify the authenticity of the data.
Tata has said it had identified a "cybersecurity incident" and there was no impact on operations, without providing additional details.
Legal tech firm sues US over order limiting foreign access to top-tier Anthropic models
A U.S. legal technology company on Tuesday sued the federal government, challenging a directive by President Donald Trump’s administration that resulted in the artificial intelligence firm Anthropic halting access to two of its most advanced models for users worldwide.
Legion LegalTech Corp filed its lawsuit, opens new tab in Washington, D.C., federal court, saying a June 12 order by the U.S. Commerce Department’s Bureau of Industry and Security unlawfully required Anthropic to disable its Fable 5 and Mythos 5 models for “any foreign national.” Anthropic turned off access for all customers the same day to ensure compliance.
San Jose, California-based Legion says it depends on Anthropic’s tools for its software platform and that the U.S. government’s action immediately cut off access for members of its Canada-based software development team and disrupted its business. The company builds drafting and case-management tools for attorneys.
Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity
On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking.
The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it.
Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking.
Forrester: AI Agents Pose New Cybersecurity Risks for CISOs
Artificial intelligence innovation is reshaping enterprise cyber risk. To protect the enterprise, CISOs need to ensure better agent visibility, strengthen identity governance and maintain human oversight as cyberattackers improve their AI capabilities, said Jitin Shabadu, analyst at Forrester.
Shabadu, co-author of Forrester's Top Cybersecurity Threats in 2026 report, said AI agents are expanding enterprise attack surfaces while creating new challenges for machine identities, software supply chains and detection. He urges security leaders to understand where AI is deployed across their environments before investing in new controls, noting that defensive AI capabilities have not yet reached the maturity of offensive use cases.
"Everything agent is an identity problem... You cannot just govern AI agents like it's another human identity. It's not how AI agents work," Shabadu said.
Visibility should be the top priority for security teams as AI adoption accelerates to ensure security teams put "the right guardrails and controls in place," he said.
👉 In this video interview with Information Security Media Group, Shabadu discussed how AI is accelerating nation-state cyber operations and autonomous attacks; why AI agent visibility and identity governance should be immediate CISO priorities; and how security leaders can reduce AI software supply chain risk while improving cyber resilience.
ALGORITHMIC WARFARE: Canada Launches Its Own Version of CMMC
The second implementation phase of the U.S. Defense Department’s Cybersecurity Maturity Model Certification program begins this November. Meanwhile, the Canadian government is introducing similar requirements in its military contracts starting this summer.
The Canadian Program for Cyber Security Certification, or CPCSC, uses the same underlying technical controls as CMMC to minimize duplication by closely aligning with U.S. requirements and standards, a Public Services and Procurement Canada spokesperson said in an email.
Like CMMC, the Canadian program has three levels and will be rolled out in phases. Level 1 — which requires suppliers to annually self-assess their implementation of 13 security controls — will be introduced in select defense contracts starting this summer.
From April 2027 to March 2028, Level 2 or 3 certification requirements will be gradually incorporated into select defense contracts, according to the Government of Canada website.
NIST Guidelines for Secure Remote Access in Water and Wastewater Systems
The NIST National Cybersecurity Center of Excellence (NCCoE) has released the final version of NIST Special Publication 1800-45, Cybersecurity for the Water and Wastewater Sector: Build Architecture, demonstrating how to securely enable remote access to operational technology for critical infrastructure.
Background
The Water and Wastewater Systems sector plays an integral role in our national critical infrastructure, supplying clean water to our communities and removing harmful materials from wastewater.
As the Water and Wastewater Systems sector continues its digital transformation, many organizations are adopting automation to improve utility management, operations, and service delivery. The adoption of internet-connected sensors, data collection, network devices, and analytic software increases cybersecurity risks and vulnerabilities.
Through collaboration with water utilities, technology vendors, and industry experts, the NCCoE’s Cybersecurity for the Water and Wastewater Sector project built and demonstrated secure remote access architectures and sample implementations in a lab environment using commercially available technologies. The resulting guidelines demonstrate how organizations of different sizes and resource levels can deploy practical remote access approaches based on their operational needs.
