Cyber risk, governed with rigor and explained in plain terms.
SenasoftConsult helps public institutions, growing businesses, and professionals build security governance that holds up to auditors, regulators, and real incidents.
Who are you looking for support for?
Choose one to see where most engagements like yours begin.
Five ways to work together, from a single focused session to a full governance program. Every engagement is scoped to your environment, obligations, and budget.
Cybersecurity and GRC consulting
Recommended for you
Align governance, risk, and security operations with your business priorities and regulatory obligations.
Governance structure, roles, and policy framework design
Risk register, risk appetite, and treatment planning
Control mapping to NIST CSF 2.0, ISO/IEC 27001, and sector regulation
AI governance aligned to ISO/IEC 42001 and the NIST AI RMF
SenasoftConsult is a cybersecurity and governance practice serving governments, SMEs, and individuals worldwide.
The practice is led by a cybersecurity and digital forensics professional whose work spans cyber governance, incident response, threat intelligence, enterprise risk, and critical-infrastructure resilience, alongside research and policy development.
That range matters in practice: governance advice is grounded in how incidents actually unfold, and technical findings are translated into decisions leaders can act on.
Research and policy work on how organizations govern cyber and AI risk, and how essential services stay resilient when things go wrong.
Focus areas
The questions that shape this practice's research, and the advice it gives clients.
Cyber governance and board accountability
How leadership teams set risk appetite, assign ownership, and measure whether security investment is reducing risk.
Critical-infrastructure resilience
How operators of essential services prepare for, withstand, and recover from disruption, and how public policy can support them.
AI governance and assurance
How organizations put management systems and controls around AI so its use can be explained, audited, and trusted.
Incident response and reporting obligations
How overlapping reporting deadlines across regulators change the way incident response has to be planned and rehearsed.
Core regulatory frameworks
The laws, standards, and frameworks this practice works with. Engagements map your controls and evidence to the ones that apply to you.
HIPAA Privacy, Security, and Breach Notification Rules
U.S. HHS, Office for Civil Rights Regulation
Federal requirements for protecting health information held by covered entities and their business associates, including administrative, physical, and technical safeguards.
Requires non-bank financial institutions to run a written information security program with a designated qualified individual, risk assessment, and board reporting.
SEC cybersecurity disclosure rules (2023)
U.S. Securities and Exchange Commission Regulation
Require public companies to disclose material cybersecurity incidents and to describe cyber risk management, strategy, and governance in annual reports.
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
U.S. CISA Law (rule pending)
Once the final rule takes effect, covered critical-infrastructure entities must report covered cyber incidents within 72 hours and ransom payments within 24 hours.
Cybersecurity risk-management and incident-reporting obligations for essential and important entities, with explicit accountability for management bodies.
North American Electric Reliability Corporation Mandatory standard
Mandatory cybersecurity requirements for entities that own or operate the bulk electric system in North America.
Listed for reference. SenasoftConsult is independent and not affiliated with, or endorsed by, the organizations that publish these frameworks.
News
The regulatory changes and threat trends shaping our clients' obligations, with what each one means in practice.
Updated 1 October 2026. Timelines change often; confirm with the issuing authority before relying on a date.
Key dates ahead
Deadlines our clients are planning around, in date order.
10 Nov 2026CMMC Phase 2: Level 2 third-party certification in applicable DoD solicitations
2 Dec 2026EU AI Act: marking of AI-generated content for systems already on the market
11 Dec 2026Cybersecurity Information Sharing Act of 2015 expires unless extended
July 2027HIPAA Security Rule final action (target, not binding)
2 Dec 2027EU AI Act: high-risk obligations for stand-alone (Annex III) systems
11 Dec 2027EU Cyber Resilience Act: full application
To be setCIRCIA reporting begins on the final rule's effective date
Regulatory watch
New obligations and the status of pending rules in the U.S. and EU.
New obligation
EU Cyber Resilience Act: vulnerability and incident reporting is now mandatory
Since 11 September 2026, manufacturers of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe security incidents through ENISA's new Single Reporting Platform. An early warning is due within 24 hours, a full notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for incidents. This applies to products already on the market, not only new ones. The rest of the Act applies from 11 December 2027.
What it means for you: Manufacturers and software vendors selling into the EU need a working process to detect, triage, and report exploitation within 24 hours. If you rely on such vendors, ask how they are meeting this duty.
CMMC Phase 2: third-party Level 2 certification becomes a condition of award
From 10 November 2026, applicable Department of Defense solicitations will require contractors that handle Controlled Unclassified Information to hold a CMMC Level 2 certification from an accredited third-party assessor, not a self-assessment. Assessor capacity is limited, so lead times are significant.
What it means for you: Defense contractors and their subcontractors should confirm which contracts are in scope, close gaps against NIST SP 800-171, and book an assessment now rather than after a solicitation arrives.
CIRCIA: the September target passes without a final rule
CISA had targeted September 2026 for the final rule under the Cyber Incident Reporting for Critical Infrastructure Act. As of 1 October 2026, CISA still states that organizations do not have to report until a final rule is published and takes effect. Once it does, covered entities in 16 critical-infrastructure sectors must report covered incidents within 72 hours and ransom payments within 24 hours.
What it means for you: The timing keeps moving, but the 72-hour and 24-hour clocks are fixed in the statute. Use the extra time to confirm whether you are covered and to build the reporting decision into your incident response plan.
Cyber threat information-sharing law extended only to 11 December 2026
The Cybersecurity Information Sharing Act of 2015, which gives companies legal protections when they share cyber threat indicators with the government and each other, was extended to 11 December 2026 by the stopgap funding law signed on 2 September. A long-term reauthorization has not passed.
What it means for you: If the law lapses, the liability and antitrust protections for sharing threat information could lapse with it. Legal and security teams should agree now on how they will share threat information if that happens.
EU AI Act: high-risk deadlines deferred, transparency duties now apply
The EU's Digital Omnibus on AI entered into force on 27 July 2026. It defers obligations for stand-alone high-risk AI systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. The Article 50 transparency obligations were not deferred, and machine-readable marking of AI-generated content applies to systems already on the market from 2 December 2026.
What it means for you: The extra time is best used to inventory AI systems, classify their risk, and build a management system such as ISO/IEC 42001 that will support compliance when the deadlines arrive.
HIPAA Security Rule overhaul: final action now targeted for July 2027
HHS proposed the largest update to the HIPAA Security Rule in two decades in January 2025, including mandatory encryption of ePHI, multi-factor authentication, and stricter oversight of business associates. The federal regulatory agenda has moved the final rule to a July 2027 target, and it could still change or be withdrawn.
What it means for you: The current Security Rule is still being enforced, and risk analysis remains the most frequently cited deficiency. A current, documented risk analysis is the best preparation for either outcome.
What the latest evidence says about how breaches happen.
Threat trend
Exploited vulnerabilities and third parties now drive breaches
Verizon's 2026 Data Breach Investigations Report found that exploitation of vulnerabilities was the leading way in, at 31% of breaches, while credential abuse fell to 13%. Third parties were involved in 48% of breaches, and ransomware appeared in 48%. Patching slowed: the median time to fully remediate rose to 43 days, and only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated.
What it means for you: Prioritize patching by known exploitation rather than severity score alone, and review critical vendors continuously rather than once a year. Both are now where most breaches start.
Cybersecurity Awareness Month 2026: “Don't Make It Easy for Them”
The National Cybersecurity Alliance opened the 23rd Cybersecurity Awareness Month on 1 October with a focus on four everyday habits: strong, unique passwords; multi-factor authentication; keeping devices updated; and caution with suspicious messages.
What it means for you: October is a good moment for a short staff refresher and a check that multi-factor authentication is enforced on email, remote access, and administrator accounts.
Previous editions, kept for reference. Some details have since changed; see the current items above for the latest status.
September 2026 edition3 items: HIPAA, CIRCIA, EU AI Act
The CIRCIA item below reflects CISA's September target, which has since passed without a final rule.
Regulatory watch
HIPAA Security Rule overhaul: final action now targeted for July 2027
HHS proposed the largest update to the HIPAA Security Rule in two decades in January 2025, including mandatory encryption of ePHI, multi-factor authentication, and stricter oversight of business associates. The federal regulatory agenda has since moved the final rule to a July 2027 target, and it could still change or be withdrawn.
What it means for you: The current Security Rule is still being enforced, and risk analysis remains the most frequently cited deficiency. A current, documented risk analysis is the best preparation for either outcome.
CISA missed the October 2025 statutory deadline for the CIRCIA final rule, held stakeholder town halls in June 2026, and now targets September 2026 for publication. Once in effect, covered entities across 16 critical-infrastructure sectors must report covered cyber incidents within 72 hours and ransom payments within 24 hours.
What it means for you: Those reporting clocks are set in the statute. Organizations that may be covered should confirm scope now and build the reporting decision into their incident response plans. Check cisa.gov/circia for publication status.
EU AI Act: high-risk deadlines deferred, transparency duties now apply
The EU's Digital Omnibus on AI entered into force on 27 July 2026. It defers obligations for stand-alone high-risk AI systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. The Article 50 transparency obligations were not deferred.
What it means for you: The extra time is best used to inventory AI systems, classify their risk, and build a management system such as ISO/IEC 42001 that will support compliance when the deadlines arrive.
SenasoftConsult launches a new website and visual identity
The new site brings together the firm's services, its approach, its research focus, and its leadership team, alongside a refreshed logo and brand system built for clarity across print and screen.
Our team
SenasoftConsult is led by three partners who share responsibility for the quality of every engagement, from first scoping call to final report.
James H.E Senanu
Executive Managing Partner
James leads the firm's strategy, client relationships, and the quality of its advisory work. A cybersecurity and digital forensics professional, he works across cyber governance, incident response, threat intelligence, enterprise risk, and critical-infrastructure resilience, alongside research and policy development.
That combination shapes how the firm works: governance advice grounded in how incidents actually unfold, and technical findings translated into decisions leaders can act on.
Leads the firm's work on emerging technology, including how clients adopt AI and new tools with the right controls in place, and how the firm's own methods and service offerings evolve.
Responsibilities
Emerging technology and AI adoption advisory
Development of new services and delivery methods
Research partnerships and thought leadership
Photo to be added
[Full name]
Partner, Global Relations and Equity
Leads the firm's international relationships and partnerships, and makes sure its services reach organizations of every size and region, including governments and SMEs with limited security resources.
Responsibilities
International partnerships and client relationships