Ravi Nayyar

528 Followers
191 Following
14.3K Posts
CTI x SSC x CNI x Regulation | CTI @ CyberCX, Fellow @ ASPI | Blogging @ TechLegalUpdate | #KalikaMataKiJai
A Techno-Legal Update Substackhttps://atechnolegalupdate.substack.com
Personal Substackhttps://randommusingsfromravi.substack.com/
Personal Blueskyhttps://bsky.app/profile/ravirockks.bsky.social
A Techno-Legal Update on Blueskyhttps://bsky.app/profile/atechnolegalupdate.substack.com
Xhttps://x.com/ravirockks
Red tape that tears us apart: regulation fragments Indo-Pacific cyber resilience | The Strategist

The fragmentation of cyber regulation in the Indo-Pacific is not just inconvenient; it is a strategic vulnerability. In recent years, governments across the Indo-Pacific, including Australia, have moved to reform their regulatory frameworks for cyber ...

The Strategist
As a regulatory nerd who wrote on cyber reg fragmentation while helping out at ASPI, I've put this on my reading list: https://www.lse.ac.uk/asset-library/defragmenting-cybersecurity-regulations-april-2026.pdf

'Some states are building explicit statutory mandates for offensive cyber — the Netherlands published a Defence Cyber Strategy in 2025 that moved from reactive to proactive operations, Germany is drafting legislation to allow its foreign intelligence services to conduct cyber operations abroad and Latvia is also warming up to cyber operations as a deterrent.

'The first point to consider is European states might have different perceptions of threats and expectations regarding the urgency with which these should be dealt with.

'Across the Atlantic, the United States is bold in publicly promoting cyber capabilities as part of its national power but at the same time diminishing investments in CISA and other critical parts of the infrastructure that enable protection and resilience. Europe should take note of this experience.

'The EU's designation of Integrity Technology Group came roughly fourteen months after US OFAC sanctioned the company and eighteen months after the initial Five Eyes advisory. What is more, in the seven years since the EU has adopted the cyber sanctions regime, it has only managed to use it five times.

'The disagreement between von der Leyen and Kallas over establishing an internal intelligence cell to counter Russian hybrid activities is a reminder that EU-level consensus on sensitive capabilities is not guaranteed — and that coalitions of willing states may need to move ahead of it.

'The more productive framing is one of complementarity in which a small number of capable states develop and employ offensive tools, while the broader European architecture – sanctions, attribution, intelligence-sharing, crisis management, and diplomatic cost imposition – is strengthened in ways that every Member State can contribute to. However, this requires ... sustained approach requires coordination'.
https://eucyberdirect.eu/blog/the-risk-of-making-offensive-cyber-the-new-shiny-silver-bullet

The Risk of Making Offensive Cyber the New Shiny Silver Bullet :: EU Cyber Direct

Horizon

'At South London and Maudsley NHS Foundation Trust (SLaM), pathology systems have not been restored as of publication ... without electronic requesting or reporting and relying on paper processes and manual uploads.

'It estimated the entering of 161,560 pathology reports into patient records had been delayed as of early January 2026.

'Copies of emails said clinicians at SLaM were warned not to rely on the timely return of blood results. Critical results are being communicated by phone, while full reports are being delivered as paper or PDFs and manually uploaded into patient records.

'... no pathology reports for SLaM patients have been available in the London Care Record ... and that normal service had not resumed for the trust'.

'The trust said these workaround processes carried risks including delays, transcription errors and the potential for patient misidentification. Its data recorded 122 patient safety incidents of incorrect, unavailable or delayed pathology results as of January 2026.

'[SLaM] said it had not been possible to quantify the impact of delays on diagnosis or treatment, despite recording incidents linked to missing or delayed results'.

Due to one critical and concentrated pathology provider being ransomwared around two years ago.
https://therecord.media/ransomware-nhs-cyberattack-disruption

Ransomware attack continues to disrupt healthcare in London nearly two years later

More than 18 months after a ransomware attack disrupted care at hospitals in South East London, documents show at least one NHS trust is still working without fully restored systems and managing large backlogs of delayed test results.

The Risks of Chinese-Produced Cellular Modules

House Select Committee on the CCP, Press Release, “Letter to Treasury and Defense Secretaries on ‘Chinese Military Company’ Quectel,” January 4, 2024. (https://chinaselectcommittee.house.gov/media/letters/letter-treasury-and-defense-secretaries-chinese-military-company-quectel); House Select Committee on the CCP, Press Release, “Gallagher, Krishnamoorthi Write to FCC on Potential Risk of Chinese Internet Connectivity Modules Sabotaging Americans’ Devices,” August 8, 2023. (https://chinaselectcommittee.house.gov/media/press-releases/gallagher-krishnamoorthi-write-fcc-potential-risk-chinese-internet); Charles Parton, “We must […]

FDD
US Navy ends USS Boise submarine overhaul after price tag soars

The U.S. Navy began a maintenance overhaul on the USS Boise in 2024 for $1.2 billion.

Navy Times
'The NHS App was the first government-sponsored app to offer passkeys as a login option for its services. Close partnership between the NHS and the NCSC has been central to accelerating wider UK adoption of passkeys, combining NHS England deployment experience with the NCSC’s technical expertise. Together, we are encouraging other organisations to follow suit, improving security for users nationwide'.
https://www.ncsc.gov.uk/blogs/strengthening-cyber-resilience-across-the-nhs-with-collaboration-and-innovation
Strengthening cyber resilience across the NHS with collaboration and innovation

How the NCSC is reducing risk, improving detection, and helping to keep vital services running.

National Cyber Security Centre

'Viva Energy Group Limited ... changed an accounting judgement applied in its financial report for the year ended 31 December 2025, resulting in an increase in impairment expenses of $25 million. This follows a[n ASIC] review ...

'ASIC reviewed the financial report of Viva Energy for the year ended 31 December 2024 and raised concerns about its approach to impairment testing of its convenience retail sites'.

Not ideal to see such poor corporate governance at a CNI asset operator.
https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-075mr-viva-energy-reassesses-accounting-approach-after-asic-review-resulting-in-25-million-impairment/

26-075MR Viva Energy reassesses accounting approach after ASIC review, resulting in $25 million impairment | ASIC

Fair, strong and efficient financial system for all Australians.

Reported 12 April:

'The oil tanker Thun Gemini has docked at the Port of Galway after being stuck since Friday morning due to the blockade that was in place, Fuels for Ireland have confirmed.

'The blockade at Galway Port by fuel protesters ended following an early morning garda operation.

'Overnight protesters had constructed a barrier of railings, wooden pallets and felled trees along the bridge leading to the terminal at the Port of Galway, which is a key fuel depot. [Nothing says tree-hugger like felling trees.]

'Protesters also parked trucks and tractors on both ends.

'Protesters restricting access to Rosslare Europort in Co Wexford have also stood down their protest'.

All I see is ideologically motivated targeting of CNI assets. Physical security hazard management matters!
https://www.rte.ie/news/ireland/2026/0412/1567774-galway-fuel-protest/

'Saudi Arabia recognises Pakistan’s dilemma and sent a not-so-subtle reminder to Islamabad of its obligations. At the end of April the UAE is demanding a loan repayment of $3.5 billion and the Saudis have stepped in with an additional $3 billion on top of its rolled-over loan of $5 billion. Little wonder that Pakistan deployed fighter jets and "support aircraft" to Saudi Arabia last week. Islamabad might have preferred the deployment to be kept secret but Riyadh very deliberately issued a statement that it was "as part of the joint strategic defence agreement signed between the two brotherly countries". The Indian media is alleging that 13,000 Pakistani troops have also been sent'.

https://www.rusi.org/explore-our-research/publications/commentary/pakistan-caught-between-president-trump-and-lethal-nuclear-dilemma

Pakistan. Caught Between President Trump and a Lethal Nuclear Dilemma

Pakistan, as mediator between the US and Iran, but with nuclear obligations to Saudi Arabia, will need all its agility to avoid abundant pitfalls.