<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Intelligence Blog on PROTISEC — AI-Powered Enterprise Cybersecurity</title><link>https://protisec.com/blog/</link><description>Recent content in Security Intelligence Blog on PROTISEC — AI-Powered Enterprise Cybersecurity</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 10 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://protisec.com/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>NIS2 in Spain: What SMEs Need to Do Before August 2026</title><link>https://protisec.com/blog/nis2-spanish-smes-2026/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://protisec.com/blog/nis2-spanish-smes-2026/</guid><description>&lt;p&gt;The EU Network and Information Security Directive (NIS2) entered into force across EU member states in October 2024. Spain transposed it via the &lt;strong&gt;Ley de Seguridad de las Redes y Sistemas de Información&lt;/strong&gt; (LSSI-NIS2). For Spanish SMBs in affected sectors, the clock is running.&lt;/p&gt;
&lt;h2 id="who-is-actually-affected"&gt;Who Is Actually Affected&lt;/h2&gt;
&lt;p&gt;NIS2 expanded the scope dramatically compared to its predecessor. In Spain, the following sectors are now covered:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Energy (electricity, oil &amp;amp; gas, district heating)&lt;/li&gt;
&lt;li&gt;Transport (road, rail, air, maritime)&lt;/li&gt;
&lt;li&gt;Banking and financial market infrastructure&lt;/li&gt;
&lt;li&gt;Health (hospitals, pharma manufacturing, R&amp;amp;D)&lt;/li&gt;
&lt;li&gt;Drinking water and wastewater&lt;/li&gt;
&lt;li&gt;Digital infrastructure (DNS, cloud, data centres, CDN providers)&lt;/li&gt;
&lt;li&gt;ICT service management (MSPs, MSSPs)&lt;/li&gt;
&lt;li&gt;Public administration&lt;/li&gt;
&lt;li&gt;Space&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;strong&gt;size threshold matters&lt;/strong&gt;: medium enterprises (50+ employees or €10M+ revenue) in essential sectors fall under NIS2. Some critical entities regardless of size are also in scope. If you are an MSP or MSSP, you are almost certainly in scope.&lt;/p&gt;</description></item><item><title>How LockBit Penetrates ICS/OT Networks: An Anatomy</title><link>https://protisec.com/blog/lockbit-icsot-anatomy/</link><pubDate>Thu, 05 Mar 2026 00:00:00 +0000</pubDate><guid>https://protisec.com/blog/lockbit-icsot-anatomy/</guid><description>&lt;p&gt;The Colonial Pipeline attack in 2021 cost $4.4M in ransom and shut down fuel supply to the US East Coast for six days. The compromise vector: a legacy VPN account with no MFA. The attackers never touched OT systems — they did not need to. The company shut down operations proactively out of fear.&lt;/p&gt;
&lt;p&gt;This is the new reality of industrial ransomware. The attack does not need to compromise your PLC to be devastating.&lt;/p&gt;</description></item><item><title>Private LLMs vs OpenAI API: The Enterprise Security Case</title><link>https://protisec.com/blog/private-llms-vs-openai-enterprise/</link><pubDate>Sat, 28 Feb 2026 00:00:00 +0000</pubDate><guid>https://protisec.com/blog/private-llms-vs-openai-enterprise/</guid><description>&lt;p&gt;In 2023, Samsung employees leaked proprietary source code by pasting it into ChatGPT. The incident is now a standard case study in enterprise AI risk. Two years later, most large European companies have an AI usage policy. Very few have an AI architecture that actually enforces it.&lt;/p&gt;
&lt;p&gt;The fundamental problem: cloud LLM APIs process your data on infrastructure you do not control, governed by terms of service that change, subject to regulatory jurisdictions that may not align with your compliance obligations.&lt;/p&gt;</description></item></channel></rss>