The SEC Moves to Rescind Pay to Play (09/04/2026)
- › The SEC proposed rescinding the pay-to-play rule barring advisers from paid work for a government client for two years after a political contribution.
- › The G7 Cyber Security Working Group and CISA issued a joint advisory telling organizations to begin the post-quantum cryptography move now.
- › Midwest Spine and Brain Institute and three other practices disclosed breaches traced to ransomware at a shared vendor.
- › Resource Center of Dallas notified 12,500 patients of a cyber incident, one of several provider disclosures this week.
- › A cloud security index found the dominant risks on AWS barely overlap with those on Google Cloud, and Azure differs from both.
One regulator proposed removing an obligation today while three other sources added them, which is the ordinary texture of a compliance calendar and worth watching as a pattern. The pay-to-play rescission is the headline, and the item that will cost operators actual money this quarter is the one about a vendor’s ransomware landing on four medical practices at once.
Top 5 Critical Compliance Alerts
1. The SEC Proposes Rescinding Its Pay-to-Play Rule
The Securities and Exchange Commission issued a proposal to rescind the rule prohibiting investment advisers from providing compensated advisory services to a government client for two years after a covered political contribution. Firms have built contribution pre-clearance workflows, employee attestations, and lookback tracking around that two-year period, and a proposal is not a repeal. Keep running the controls through the comment period, because the enforcement risk during the interim sits entirely with the firm that relaxed early. SEC has the proposal.
Operator Note: File a note in your compliance calendar for the comment deadline and another for the final rule, and change nothing in between.
2. The G7 and CISA Say Start the Post-Quantum Move Now
The G7 Cyber Security Working Group and the Cybersecurity and Infrastructure Security Agency issued a joint advisory telling organizations to begin moving to post-quantum cryptography, alongside a call for governments to launch national transition strategies. The instruction people hear is buy new cryptography, and the instruction that actually starts the work is inventory where you use the old kind. Most organizations cannot currently name which of their systems, vendors, and embedded devices depend on the algorithms being retired. The Record has the advisory and Infosecurity Magazine covers the national strategy call.
Operator Note: The first deliverable is a cryptographic inventory, and it takes a quarter, which is why starting it after the deadline is announced is starting it late.
3. One Vendor’s Ransomware Lands on Four Practices
Midwest Spine and Brain Institute disclosed a breach traced to a ransomware attack at a shared vendor, alongside disclosures from Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center, and others affected through the same provider. Each of those practices now owns a notification obligation, a patient population to inform, and a regulator conversation, arising from an incident inside a company none of their patients chose. This is what concentration risk looks like in practice at the small end of healthcare. HIPAA Journal has the affected entities.
Operator Note: Ask your business associates how many other clients sit on the same infrastructure you do, because that number is your real blast radius and it is never in the agreement.
4. Resource Center of Dallas Notifies 12,500 Patients
Resource Center of Dallas told 12,500 patients about a cyber incident, in one of several provider disclosures published this week alongside Kern Psychiatric Health and Wellness Center, The Asthma Center, and others. Organizations at this size rarely have a dedicated security function, and they hold exactly the same category of protected health information as a hospital system does. The obligation attached to that information does not scale down with the size of the staff holding it. HIPAA Journal has the notification detail.
5. Cloud Risk Does Not Transfer Between Providers
A 2026 cloud security index found that the issues dominating on Amazon Web Services barely overlap with those on Google Cloud, and that Microsoft Azure looks different again. Teams running multiple providers tend to carry one mental model of cloud risk and apply it everywhere, which leaves whole categories unexamined on the platforms that fail differently. A control set validated on one provider is evidence about that provider. Cloud Security Alliance has the comparison.
Additional Compliance Alerts
Regulatory Updates
- Grid interconnection cybersecurity requirements are tightening: Amendments to interconnection technical requirements are strengthening cybersecurity obligations for equipment with IP communication functions used in solar and battery storage facilities, which reaches operators who have never treated themselves as regulated for security. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.