Extended Security Updates for Exchange Server 2016 and 2019 end on 31 October 2026

By |2026-09-09T09:42:10-04:00September 3rd, 2026|Data Compliance, Email security|

On 20 July 2026 the Exchange Server team answered a question a lot of IT departments had been quietly hoping to hear a different answer to. There will be no Period 3.  Extended Security Updates for Exchange Server 2016 and 2019 end on 31 October 2026. Period 2 was the final window. It cannot be renewed or extended, and enrolled organizations get no further patches after that date, including for a critical vulnerability disclosed on 1 November. Roughly eight weeks from today.  What Does the Period 2 ESU Actually Cover? Less than most people assume. Extended Security Updates deliver only

Comments Off on Extended Security Updates for Exchange Server 2016 and 2019 end on 31 October 2026

Microsoft 365 Retention Is Not Backup

By |2026-09-09T09:22:47-04:00September 3rd, 2026|Cloud Migration, Microsoft 365|

Ask your IT team whether your Microsoft 365 data is backed up. You will usually get a confident yes.  Then ask a follow-up. What happens if your finance director deletes a mailbox folder in March and nobody notices until June? The confidence tends to fade around that point.  Microsoft 365 retention policies preserve data for compliance. They do not restore it. Under Microsoft's shared responsibility model, Microsoft guarantees platform availability and infrastructure resilience while you remain responsible for the data itself. Standard Microsoft 365 licenses do not include a backup solution, and the native recovery windows are shorter than most organizations assume. Does Microsoft Back Up Your Microsoft 365 Data?  Not in the

Comments Off on Microsoft 365 Retention Is Not Backup

Did the EU Delay the AI Act? What Changed in 2026

By |2026-08-25T06:59:33-04:00August 25th, 2026|Uncategorized|

Did the EU Delay the AI Act? What Actually Took Effect on August 2, 2026. Did the EU delay the AI Act? Partly. The Digital Omnibus on AI, given final Council approval on June 29, 2026, deferred high-risk obligations for Annex III systems to December 2, 2027. Article 50 transparency obligations were not deferred and took effect on August 2, 2026, exactly as scheduled.   The headline most organizations heard was simpler. "The EU delayed the AI Act." Half true, and imprecise in a way that creates exposure.   What the Digital Omnibus Actually Changed   For more than a year, August 2, 2026 anchored enterprise AI compliance planning.

Comments Off on Did the EU Delay the AI Act? What Changed in 2026

AI Tools Are Inside Your Organization. Is Your Governance Framework Ready?

By |2026-08-11T10:28:27-04:00August 11th, 2026|Data Compliance, eDiscovery|

When employees use AI tools, whether sanctioned or not, they pull organizational data into environments that may retain it, share it with third parties, or process it in ways that create compliance, eDiscovery, and records management obligations the organization never planned for.  Most organizations are already past the point of deciding whether to allow AI tools. Research published in 2026 found ChatGPT present in 71 percent of UK enterprise IT environments and Microsoft Copilot in 68 percent. The governance question is no longer about adoption. It is about whether the framework underneath can account for what those tools are doing

Comments Off on AI Tools Are Inside Your Organization. Is Your Governance Framework Ready?

When a Hotel Wi-Fi Attack Hits Your Organization: The Governance and eDiscovery Implications

By |2026-08-11T10:10:32-04:00August 11th, 2026|Cyber-Security, Email security|

Most organizations think about credential theft as an IT problem. Contain the endpoint, reset the password, revoke the session token. That is where the response starts, but it is not where it ends.  The CaptiveCrunch campaign, disclosed by Microsoft on July 31, 2026, has compromised Wi-Fi infrastructure at hotels and conference venues worldwide, delivering malware and stealing Microsoft 365 session tokens from business and individual travelers. When those credentials belong to employees in regulated industries, or to organizations with active litigation or regulatory investigations, the incident creates obligations that extend well beyond the security team.  How Do Stolen Credentials Create a Legal Hold Problem? 

Comments Off on When a Hotel Wi-Fi Attack Hits Your Organization: The Governance and eDiscovery Implications

The State of U.S. Data Privacy Laws in 2026 

By |2026-07-17T08:34:10-04:00July 17th, 2026|Privacy|

How many U.S. states have comprehensive data privacy laws in 2026?  At least 20 now have comprehensive consumer privacy laws in effect, following new statutes in Indiana, Kentucky, and Rhode Island that took effect January 1, 2026. There is still no comprehensive federal privacy law. Compliance runs state by state, and it shows.   The Federal Vacuum: Why States Are Writing Their Own Rules   Congress has debated a national privacy standard for years without passing one. Meanwhile, states kept moving. What started with California's CCPA back in 2018 has become a genuine patchwork, and the differences between laws are widening, not converging. Newer

Comments Off on The State of U.S. Data Privacy Laws in 2026 

AI and Machine Learning in eDiscovery: What Portable AI Models Mean for Legal Teams 

By |2026-06-10T05:20:29-04:00June 10th, 2026|AI, eDiscovery|

AI and machine learning in eDiscovery refer to the use of trained algorithms to automate document classification, relevance prediction, privilege detection, and pattern recognition across large volumes of electronically stored information. Portable AI models extend that capability by allowing organizations to train a model in one matter or environment and redeploy it across different platforms, cases, or data sets without rebuilding from scratch each time. For organizations that litigate frequently or face recurring regulatory investigations, that is a meaningful shift in how review economics work.  How Portable AI Models Work  For most of eDiscovery's history, AI models were platform-bound. You

Comments Off on AI and Machine Learning in eDiscovery: What Portable AI Models Mean for Legal Teams 

Information Governance vs Records Management: What Is the Difference? 

By |2026-06-10T05:21:04-04:00June 10th, 2026|Information Governance and Management|

Information governance is the broader strategic framework that defines how an organization manages all of its data assets across their entire lifecycle. Records management is a subset of that framework, focused specifically on the identification, classification, retention, and disposal of official business records. One contains the other.  Getting that distinction wrong has consequences. Organizations that treat records management as a standalone compliance function, disconnected from a wider governance strategy, tend to find out the hard way that it is not enough.  How Do You Define Records Management?  Records management is one of the oldest disciplines in organizational administration. At its core, it answers a

Comments Off on Information Governance vs Records Management: What Is the Difference? 

Data Security Compliance: All You Need to Know in 2026

By |2026-05-27T03:50:38-04:00May 27th, 2026|Data Compliance, eDiscovery|

Data security compliance is the process by which organizations implement policies, controls, and governance frameworks to protect sensitive information in accordance with applicable laws, regulations, and industry standards. In 2026, that process spans an increasingly complex landscape of overlapping requirements, from GDPR and HIPAA to SEC cybersecurity disclosure rules, state privacy laws, and sector-specific frameworks such as CMMC for defense contractors and PCI DSS for payment card environments.  No single framework covers everything. Most organizations are subject to several simultaneously.  The cost of getting it wrong has climbed steadily. IBM's 2024 Cost of a Data Breach Report put the global average cost

Comments Off on Data Security Compliance: All You Need to Know in 2026

How AI Transforms Document Review in eDiscovery

By |2026-05-13T05:37:50-04:00May 13th, 2026|AI, eDiscovery|

AI-powered document review in eDiscovery uses machine learning and natural language processing to analyze large volumes of electronically stored information, classify documents by relevance, privilege, and responsiveness, and surface the most significant content for human review. It reduces the time and cost of first-pass review dramatically while improving consistency across document sets that no human team could process at the same speed or scale.  That is the case for AI in eDiscovery in one paragraph. The fuller picture is more nuanced.  Document review has historically been the most expensive phase of litigation and regulatory response. In large matters, review costs routinely account

Comments Off on How AI Transforms Document Review in eDiscovery
Go to Top