Services Standards Process Weekly Review Contact
Weekly Review

Governance & Compliance Review

Developments in technology governance, cybersecurity standards, and regulatory compliance.

Week of July 6 to 17, 2026
This is an archived edition. View the latest review →
Lead Story
CyberSecure Canada & CPCSC
CybersecurityVulnerability

Actively Exploited SharePoint Server Zero Day, CVE 2026 56164, Added to the CISA Known Exploited Vulnerabilities Catalog the Day Patches Shipped

A missing authentication vulnerability in on premises Microsoft SharePoint Server, tracked as CVE 2026 56164, is being actively exploited, letting an unauthenticated attacker escalate privileges over the network without user interaction. Microsoft shipped a fix on July 14, and the United States Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the same day, setting a three day remediation deadline for federal civilian agencies. The Canadian Centre for Cyber Security published a corresponding advisory in its July security guidance. Attackers have been observed chaining the flaw with older SharePoint weaknesses to steal server machine keys, establish persistence, and deploy malware.

Although Microsoft rated the flaw moderate at a CVSS score of 5.3, the National Vulnerability Database independently scored it 9.8 critical, reflecting unauthenticated network exploitability. The gap underlines why organizations should treat active exploitation and CISA catalog inclusion, not vendor severity labels alone, as the trigger for emergency patching of internet facing SharePoint.

  • CVE 2026 56164 is an actively exploited, unauthenticated privilege escalation flaw in on premises SharePoint Server
  • Microsoft patched it on July 14; CISA added it to the Known Exploited Vulnerabilities catalog the same day with a three day federal deadline
  • The Canadian Centre for Cyber Security issued a corresponding advisory in its July guidance
  • Attackers are chaining the flaw with older SharePoint bugs to steal machine keys and persist

Implications

On premises SharePoint remains a high value target, and unauthenticated privilege escalation warrants emergency change handling. Prioritize patching of internet facing SharePoint, enable Antimalware Scan Interface integration, and rotate machine keys where compromise is possible. Map the response to ISO/IEC 27001:2022 A.8.8 management of technical vulnerabilities, A.8.9 configuration management, A.8.16 monitoring activities, and A.5.7 threat intelligence, and treat the CISA catalog and the Canadian Centre for Cyber Security advisories as authoritative prioritization inputs. Organizations should confirm that emergency patch service levels apply to collaboration platforms, not only perimeter devices.

Source: CSO Online
CybersecurityPatch Management

Microsoft Breaks Its Monthly Patch Record Again, Fixing More Than Six Hundred Vulnerabilities and Multiple Exploited Zero Days in July

Microsoft's July Patch Tuesday, released July 14, addressed a record volume of vulnerabilities for the second consecutive month, surpassing six hundred CVEs and including multiple flaws under active attack. The scale, spanning SharePoint, Active Directory Federation Services, and Windows, raises the operational stakes for vulnerability triage, since defenders must separate the small number of exploited or imminently exploitable flaws from a very large monthly backlog. The Canadian Centre for Cyber Security issued its standard monthly rollup advisory recommending prompt application of the updates.

Record patch volumes are becoming the norm rather than the exception, a structural shift that makes risk based prioritization and reliable patch deployment a continuous governance requirement. Organizations that treat Patch Tuesday as a monthly project rather than an always on process will struggle to keep pace as monthly CVE counts climb.

  • Microsoft's July 14 Patch Tuesday exceeded six hundred CVEs, a monthly record for the second month running
  • The release included multiple actively exploited zero days across SharePoint, AD FS, and Windows
  • The Canadian Centre for Cyber Security published its monthly rollup advisory urging prompt patching
  • Rising patch volumes make risk based prioritization a continuous, not periodic, requirement

Implications

Governance teams should ensure vulnerability management is resourced for sustained high volume triage, with clear criteria that escalate exploited and internet facing flaws ahead of routine patches. Align the program to ISO/IEC 27001:2022 A.8.8 management of technical vulnerabilities and A.8.32 change management, and use exploitation status, asset exposure, and the CISA Known Exploited Vulnerabilities catalog to drive priority. A documented, tested, and measured patch process, rather than best effort monthly deployment, is the control that keeps record patch volumes from translating into unmanaged risk.

Source: The Record by Recorded Future
CPCSCCanada

Canada's CPCSC Level 1 Moves Into Select Defence Contracts This Summer, Requiring Annual Self Assessment Against Thirteen Controls

The Canadian Program for Cyber Security Certification reaches an operational milestone this summer as Level 1 begins appearing in select federal defence contracts. Level 1 requires suppliers to self assess, on an annual basis, their implementation of thirteen baseline security controls, with certification required upon contract award rather than throughout the bidding process during the initial phase. The program uses the same underlying technical controls as the United States Cybersecurity Maturity Model Certification, minimizing duplication for suppliers that work across both markets while maintaining Canadian data residency requirements.

Level 2, which introduces third party assessment conducted by accredited assessors on a recurring basis, is scheduled to be incorporated into select contracts beginning in 2027. Commentators have flagged a capacity gap: few Canadian organizations are currently accredited to perform Level 2 assessments, leaving limited runway for the assessor ecosystem to mature before higher assurance requirements take effect.

  • CPCSC Level 1 enters select defence contracts this summer; certification required on contract award in the initial phase
  • Level 1 requires annual supplier self assessment against thirteen baseline controls
  • Controls align with the United States CMMC framework to reduce duplication for cross border suppliers
  • Level 2 third party assessment is scheduled from 2027; Canadian assessor capacity remains a noted constraint

Implications

Defence suppliers and their subcontractors should treat CPCSC as a near term procurement gate, not a future consideration. Begin a gap assessment against the thirteen Level 1 controls now, document evidence of implementation, and build the self assessment into the annual compliance calendar. Because Level 1 mirrors the CyberSecure Canada baseline and aligns with CMMC, an existing ISO/IEC 27001:2022 information security management system provides substantial coverage, particularly A.5.1 policies for information security, A.8.8 management of technical vulnerabilities, A.8.2 privileged access rights, and A.8.7 protection against malware. Firms anticipating Level 2 should plan early for third party assessment given limited assessor availability.

Source: Government of Canada
AI Governance & Regulation
AIRegulationGovernance

EU AI Act Enforcement Against General Purpose AI Providers Begins August 2, 2026, With Fines up to Three Percent of Global Turnover

The European Commission's supervision and enforcement powers over providers of general purpose AI models enter into application on August 2, 2026. While obligations for these providers have applied since August 2025, from this date the Commission can request documentation, conduct model evaluations, require compliance and risk mitigation measures, and impose fines of up to three percent of global annual turnover or fifteen million euros, whichever is higher. Providers of general purpose models placed on the market before August 2025 have until August 2, 2027, to bring existing models into compliance.

The shift from obligation to enforcement raises the stakes for any organization that builds on, distributes, or deploys general purpose AI models with a European footprint. Downstream deployers should expect providers to pass through documentation, transparency, and copyright related requirements, changing what enterprises must obtain and retain from their AI suppliers.

  • EU AI Act enforcement powers over general purpose AI model providers apply from August 2, 2026
  • The Commission can request documentation, evaluate models, require mitigations, and impose fines
  • Penalties can reach three percent of global annual turnover or fifteen million euros, whichever is higher
  • Models placed on the market before August 2025 have until August 2, 2027, to comply

Implications

Organizations with European operations or customers should confirm whether they act as providers or deployers of general purpose AI and document the corresponding obligations before enforcement begins. Update AI vendor due diligence to require model documentation, training data transparency summaries, and copyright compliance evidence, and retain that evidence under an AI management system aligned to ISO/IEC 42001:2023. Map contractual flow down and record keeping to ISO/IEC 27001:2022 A.5.31 legal, statutory, regulatory and contractual requirements and A.5.19 information security in supplier relationships, and treat the August milestone as a fixed compliance deadline rather than a future risk.

Source: European Commission
AICanadaSovereignty

Federal Government Directs $13.9 Million to Sixty Three Quebec Organizations Under the Regional AI Initiative as Sovereign Compute Programs Advance

On July 15, the Minister responsible for Artificial Intelligence announced close to $13.9 million in federal contributions to sixty three Quebec organizations under the Regional Artificial Intelligence Initiative, supporting AI adoption projects across small and medium sized enterprises. The funding sits alongside broader sovereign compute commitments, including the AI Sovereign Compute Infrastructure Program, which is providing roughly $890 million to build AI optimized capacity on Canadian soil, and continuing federal talks to back domestic data centre buildout. Together the measures signal a policy environment that pairs adoption incentives with Canadian data residency.

For governance leaders, the significance is the coupling of public funding with sovereignty conditions. As federal money flows into AI adoption and domestic compute, procurement preferences and grant terms increasingly carry data residency, provenance, and governance expectations that organizations will need to evidence.

  • Close to $13.9 million announced July 15 for sixty three Quebec organizations under the Regional AI Initiative
  • Funding supports AI adoption among small and medium sized enterprises
  • The AI Sovereign Compute Infrastructure Program is providing roughly $890 million for Canadian AI capacity
  • Federal policy pairs adoption incentives with Canadian data residency and sovereignty conditions

Implications

Organizations pursuing federal AI funding or selling into government should prepare to evidence data residency, model provenance, and governance as conditions of eligibility. Establish an AI governance baseline aligned to ISO/IEC 42001:2023, documenting where data and compute reside and how AI systems are risk assessed and overseen. Supporting controls map to ISO/IEC 27001:2022 A.5.23 information security for use of cloud services and A.5.31 legal, statutory, regulatory and contractual requirements. Treating sovereignty as a documented control, not a marketing claim, positions organizations for grant terms and procurement criteria that increasingly test it.

Source: Government of Canada
Frameworks & Standards
ISOAIGovernance

ISO/IEC 42001 Certifications Accelerate as Enterprises Extend ISO/IEC 27001 Programs to AI Governance Ahead of the EU AI Act Milestone

Certification activity against ISO/IEC 42001, the international standard for AI management systems, continued to accelerate in July, with organizations publicly announcing certification of their artificial intelligence management systems within days of one another. The pattern is consistent: firms that already hold ISO/IEC 27001 for information security, and often ISO/IEC 27701 for privacy, are adding ISO/IEC 42001 to evidence structured governance of how they build and use AI. The momentum is reinforced by the European Union AI Act, which reaches a significant enforcement milestone on August 2, 2026, and by customers demanding assurance that AI is governed rather than merely deployed.

Organizations already certified to ISO/IEC 27001 are positioned to reach ISO/IEC 42001 conformity more efficiently, since the two standards share a common management system structure covering context, leadership, planning, operation, and continual improvement. The AI specific work lies in impact assessment for AI systems, data governance, transparency, and documented human oversight.

  • Multiple organizations announced ISO/IEC 42001 certification of their AI management systems in July
  • Certifying firms typically already hold ISO/IEC 27001, and often ISO/IEC 27701, and are layering AI governance on top
  • The EU AI Act enforcement milestone on August 2, 2026, is reinforcing demand for demonstrable AI governance
  • A shared management system structure lets ISO/IEC 27001 certified organizations adopt ISO/IEC 42001 more efficiently

Implications

Organizations developing or deploying AI should treat ISO/IEC 42001:2023 as the governance framework that complements existing security certifications and evidences responsible AI to customers and regulators. Those already holding ISO/IEC 27001:2022 can reuse leadership, risk, and continual improvement processes, then add AI specific controls for impact assessment, data quality, transparency, and human oversight. As certified vendors become the norm, buyers should begin asking suppliers for AI management system evidence in due diligence, and organizations exposed to the European market should document a conformity roadmap now rather than after enforcement sharpens.

Source: ISO
NISTAIGovernance

NIST Advances Its Cyber AI Profile, Extending the Cybersecurity Framework to Securing AI Systems and Using AI for Defence

The United States National Institute of Standards and Technology is advancing its Cybersecurity Framework Profile for Artificial Intelligence, known as the Cyber AI Profile, as a priority standards effort this summer. Built on the voluntary Cybersecurity Framework 2.0, the profile organizes AI related cybersecurity into focus areas that address securing AI systems as they are integrated into organizations, defending with AI to strengthen security operations, and managing the cybersecurity risks that AI introduces. NIST published reflections from its second Cyber AI Profile workshop, where participants supported continued development toward an initial public draft.

The Cyber AI Profile gives security and governance teams a common vocabulary to connect established cybersecurity practice with the specific risks of AI adoption, from model and data pipeline security to the governance of AI used inside security tooling. It complements management system standards by translating AI risk into the familiar identify, protect, detect, respond, and recover functions.

  • NIST is advancing the Cyber AI Profile as a priority effort this summer, built on Cybersecurity Framework 2.0
  • Focus areas cover securing AI systems, using AI to strengthen defence, and managing AI introduced risk
  • NIST published reflections from its second Cyber AI Profile workshop supporting continued development
  • The profile maps AI risk onto the framework's identify, protect, detect, respond, and recover functions

Implications

Security leaders should track the Cyber AI Profile as the emerging bridge between cybersecurity and AI governance, and begin mapping AI systems into existing Cybersecurity Framework practices rather than treating AI risk as a separate silo. Pair the profile with ISO/IEC 42001:2023 for AI management and ISO/IEC 27001:2022 for information security, using A.8.8 management of technical vulnerabilities and A.5.7 threat intelligence to cover the security of AI pipelines. Organizations using AI within security operations should document human oversight and monitoring so that AI assisted defence is itself governed.

Source: NIST
Previous Reviews

Get the Weekly Briefing

Governance, compliance, and cybersecurity developments delivered to your inbox every Monday. No noise, just what matters.