Qualysec

Blog

Latest Articles

Page 1 of 151 · 1352 posts

BNM RMiT Penetration Testing Guidelines Mandates, Scope, and Vendor Selection Criteria

August 20, 2026

BNM RMiT Penetration Testing Guidelines: Mandates, Scope, and Vendor Selection Criteria

If you run a bank, insurer, e-wallet, or fintech in Malaysia, Bank Negara Malaysia’s Risk Management in Technology (RMiT) rules are not optional. This is the basic standard that decides whether your systems pass BNM checks. Auditors no longer accept one-time security tests that claim everything is fine for a year. They want clear proof […]

FDA PCCP Guidance for AIML Medical Devices 2026 Submission & Change Control Guide

August 20, 2026

FDA PCCP Guidance for AI/ML Medical Devices: 2026 Submission & Change Control Guide

Quick Summary: A Predetermined Change Control Plan (PCCP) allows medical device manufacturers to pre-specify and validate future AI/ML algorithm modifications within a marketing submission, such as 510(k), PMA, or De Novo. When planned changes remain within the FDA-authorized PCCP boundaries and follow the approved modification protocol, manufacturers can implement those updates without submitting a new premarket […]

The Complete Guide to AI Governance & Compliance in 2026

August 20, 2026

The Complete Guide to AI Governance & Compliance in 2026

Key Takeaways EU AI Act penalties for prohibited practices have been in effect since February 2025, up to €35 million or 7% of global turnover, with GPAI enforcement and transparency duties landing on August 2, 2026. Gartner found 43% of organisations can’t even produce a full AI inventory, which is usually step one for any […]

DESC Cyber Force Penetration Testing: Complete Guide for UAE

August 19, 2026

DESC Cyber Force Penetration Testing: Complete Guide for UAE

Key Takeaways DESC Cyber Force is a certification for providers, not a special type of test. Only Dubai government, semi-government and CII entities must use certified providers. The testing itself is just solid professional penetration testing done by approved companies. Most organisations still find basic problems like weak passwords, missing patches and poor access control. […]

What Is DESC Cyber Force? Requirements & Compliance Guide

August 19, 2026

What Is DESC Cyber Force? Requirements & Compliance Guide

Dubai has built one of the most structured cybersecurity oversight systems in the region. At the center of this system is the Dubai Electronic Security Center, known as DESC, which is a government authority that operates under Digital Dubai. Its mandate comes from Dubai Law No. 11 of 2014. Many people use the term DESC […]

Featured image for FDA Cybersecurity Documentation Requirements for Medical Device Submissions

August 19, 2026

FDA Cybersecurity Documentation Requirements for Medical Device Submissions

Submitting a connected medical device to the FDA involves more than attaching a few cybersecurity reports to your application. You need to show how your team identified security risks, tested the device, applied controls, and planned to manage vulnerabilities after release. This level of evidence matters because weaknesses in connected devices can lead to serious […]

What Documentation is Required to Pass a GDPR Data Privacy Audit

August 18, 2026

What Documentation is Required to Pass a GDPR Data Privacy Audit?

A GDPR audit may begin with a documentation review, but missing or outdated records can quickly turn the process into a compliance challenge. GDPR Enforcement Tracker has recorded a total of 3202 cases under GDPR till now, of which 156 cases have happened in the year 2026, with a fine of €6.31B. Security tests are […]

LLM Red Teaming A Complete Guide to Testing and Securing AI Applications

August 17, 2026

LLM Red Teaming: A Complete Guide to Testing and Securing AI Applications

Your AI model can pass every internal safety test, but you can’t guarantee full safety when a real user tries to break it. A hacker will manage to manipulate the algorithm and bypass the preloaded instruction set. That would give the hacker access to important information as well as the opportunity to perform prohibited actions. […]

Complete PAIA Compliance Checklist Manuals & Requirements

August 16, 2026

Complete PAIA Compliance Checklist: Manuals & Requirements

Someone requests information about your organization and nobody knows how to respond because you’ve never properly documented what information you hold or where it is stored. Your management team realizes you probably need something called a PAIA manual, but nobody’s certain what that means. You wonder whether the Promotion of Access to Information Act even […]

"Don't compromise between depth and speed. Own both. Connect with Swagat, Your trusted penetration testing advisor."

Swagat Kumar Dash

Swagat Kumar Dash

Head Of Business Development