← Back to SION Radar

Weekly briefing

Data, locations and systems to check

Review for 2–8 September: Ireland’s paper-records decision, a Zimbra alert and Microsoft updates. The shared question: who checks, and where is the evidence? Prepared on 8 September 2026.

Data protection also starts at the archive door

What changed

On 2 September, Ireland’s DPC announced its HSE decision concerning paper records in external storage. The inquiry followed breaches reported in 2023; these are not new September incidents.

Editorial interpretation and suggested checks

Why it matters

Our editorial conclusion: connect data-protection rules to the physical locations where records remain. A location–access–responsibility–control-evidence link helps frame a risk review. This does not claim that any particular software would have prevented the breaches.

What to check

  • List active and off-site record-storage locations and check who is responsible for each one.
  • Compare authorised access, premises condition, retention periods and inspection records; assign an action and completion evidence to each identified gap.

Applicable organizations and jurisdictions

European Union

Sources

Source titles are retained in their original language.

Explore the related example in SION GRC

Zimbra: ask the service provider for verification evidence too

What changed

On 3 September, Serbia’s National CERT warned of active exploitation of CVE-2026-73570 in Zimbra Collaboration. The alert concerns installations with zimbra-snmp and enabled SNMP notifications.

Editorial interpretation and suggested checks

Why it matters

Our editorial assessment: even with outsourced email, the organisation needs an answer about its own service. A general assurance about the supplier does not replace verification of the specific version and configuration. The news alone does not prove compromise.

What to check

  • Ask the administrator or provider to confirm whether the advisory applies to your instance.
  • Link the response and evidence of action to the contract, service owner and open action; treat a suspected incident separately from a routine update request.

Applicable organizations and jurisdictions

Serbia, International

Sources

Source titles are retained in their original language.

Explore the related example in SION GRC

September updates: decision, ownership and confirmation

What changed

On 8 September, Serbia’s National CERT recommended the new Microsoft security updates. Some of the addressed vulnerabilities could allow a remote attacker to take control of a system.

Editorial interpretation and suggested checks

Why it matters

Our editorial recommendation: distinguish a downloaded patch, an installed patch and a verified state. This overview does not assert that every system is affected or prescribe one change window for all organisations.

What to check

  • Have the responsible technical team identify affected systems and plan changes, considering the impact on key services.
  • Retain post-change verification for each system group; record deferred changes as exceptions with ownership and a review date.

Applicable organizations and jurisdictions

Serbia, International

Sources

Source titles are retained in their original language.

Explore the related example in SION GRC

An informational overview, not individual legal advice. Applicability depends on the organization and jurisdiction; check the original documents before making decisions.