Advocate Shoeb Hakim

Advocate Shoeb Hakim Criminal + Cyber Law | Ex-Corp Counsel | Exposing digital scams, defending rights & educating the public. Law isn’t scary—ignorance is.

Digital Forensics & Cybercrime Expert | AML Compliance Advisor | Criminal Defense Counsel | Training Police & Government Officials Since 1996 | I train the people who protect India. | Mumbai India

Wilful blindness is not just a cultural failing—it is a liability multiplier. Under GDPR, DPDP, and NIS, if a board cann...
28/08/2026

Wilful blindness is not just a cultural failing—it is a liability multiplier. Under GDPR, DPDP, and NIS, if a board cannot prove it actively sought risk information, regulators can infer negligence.

The 'ostrich defence' has been rejected by courts.
🔗 Original post:

New podcast episode available now. Tune in to hear from leadership expert and author Margaret Heffernan, Professor Genevieve Liveley, Director of the Research Institute for Sociotechnical Cyber Security (RISCS), and Kathryn, Head of Social Sciences at NCSC as they explore why organisations often rec...

28/08/2026

AI smart glasses can record bystanders without consent. The DPDP Act requires consent—but how do you obtain it from someone who doesn't know they're being recorded?

Section 66E IT Act only protects images of "private areas"—a public street does not qualify. Section 77 BNSS requires a "woman's private act"—a casual recording of a crowd does not meet that threshold. The enforcement gap is the real challenge.

Banning devices in sensitive zones: toilets, changing rooms, clinics, confidential meetings.

🔗 Original post:
https://lnkd.in/p/dsnk2H57

EDF operated 12 servers without valid certificates for 18 months. Insecure DNS. Exploitation pathway rated 9/10. This is...
28/08/2026

EDF operated 12 servers without valid certificates for 18 months. Insecure DNS. Exploitation pathway rated 9/10.

This is not just a technical failure—it is a regulatory breach under NIS2 (€10M fine) and a GDPR liability. When will regulators act?

🔗 Original post:

EDF's 18-Month Exposure – 12 Servers, No Security, Millions of exposed customers. For over 18 months, EDF has operated 12 servers linked to edfenergy.com without a valid digital certificate. The DNS also remains insecure, with 13 RRsets and 4 delegations in an insecure state. This is nothing to do...

Holiday Inn won an ex-parte order against a Goa hotel—in Delhi. But the jurisdictional foundation is vulnerable. In Vikr...
28/08/2026

Holiday Inn won an ex-parte order against a Goa hotel—in Delhi. But the jurisdictional foundation is vulnerable. In Vikrant Chemico (Aug 2025), Delhi HC held that 'listing goods on a website accessible in Delhi is not enough to prove jurisdiction.

Holiday Inn obtained this ex-parte order without the defendant being present to contest jurisdiction.

When Jerome Fernandes appears—and he will, through counsel—he can cite Vikrant Chemico to argue that the Delhi High Court has no jurisdiction over a hotel physically located in Goa.

If the Court accepts this argument, the entire ex-parte order could be vacated.

🔗 Original post:

The Delhi High Court's ex-parte order against "Hotel Jerome's Holiday Inn" is a tactical win for Holiday Inn. But it exposes a jurisdictional vulnerability that could unravel the entire case. Justice Anup Jairam Bhambhani granted the ex-parte ad-interim injunction on August 17, 2026, restraining Jer...

28/08/2026

Regulators are no longer asking 'do you have the data?' They are asking 'can you prove your compliance system works?'

The RelyComply-LSEG partnership is a response to that shift. Explainable AI is the key differentiator. 🔗 Original post:

A Maldivian woman police commander completed the UK's most prestigious police leadership programme. But the real story i...
28/08/2026

A Maldivian woman police commander completed the UK's most prestigious police leadership programme.

But the real story is the institutional gap: only 18.5% of Maldives Police are women. She is breaking glass ceilings—and creating a pipeline.

🔗 Original post:

Commander Nashwa Fathimath's completion of the UK Executive Leaders Programme is a significant milestone, not just for her, but for the Maldives Police Service. The ELP, which replaced the Strategic Command Course in 2023, is the most prestigious programme for executive leaders in policing. It is a....

Attack Surface Management gaps are no longer technical oversights. Expired certs and missing HSTS are now litigation-gra...
28/08/2026

Attack Surface Management gaps are no longer technical oversights. Expired certs and missing HSTS are now litigation-grade evidence of governance failure. The Board's new question: 'What can a regulator prove?' Not just 'What can an attacker see?' 🔗 Original post:

Andy Jenkinson's post asks the right question: "What can an attacker see, reach, and exploit?" But the legal question is: "What can a regulator prove?" The post frames Attack Surface Management as a technical discipline—replace fragmented tools, get one executive view, kill the exposure. That is n...

One operator. One device. 20 SIMs. AI-generated chat. And banks still trust SMS OTP as identity. SIM swap fraud surged 3...
28/08/2026

One operator. One device. 20 SIMs. AI-generated chat. And banks still trust SMS OTP as identity. SIM swap fraud surged 327% in 2025. Europol dismantled a network powering 49M fake accounts.

The regulator's question: 'Did you verify the customer?' Not 'Did you send an OTP?'
🔗 Original post:

The post describes the plumbing of fraud farms. The compliance and legal implications are what happens when the water reaches the bank. One operator. One device. 20 SIMs. AI-generated chat. WhatsApp Business accounts that all look like different customers. The hardware is cheap—a 20-slot SIM board...

Neglecting foundational controls like DNS and PKI is not just a governance failure—it's a legal liability. DPDP Act pena...
28/08/2026

Neglecting foundational controls like DNS and PKI is not just a governance failure—it's a legal liability. DPDP Act penalties: ₹250 crore. SEC rules: material weakness. GDPR: accountability principle. The legal exposure is real. 🔗 Original post:

Andy Jenkinson's post is a sharp critique of the cybersecurity industry's governance failures. But the legal implications are even sharper. The post correctly identifies the problem: foundational controls like DNS and PKI are neglected, and the cycle of breaches and blame continues. But it stops sho...

AUSTRAC is training Pacific FIUs to detect financial crime. But they lack the legal frameworks to act on the intelligenc...
28/08/2026

AUSTRAC is training Pacific FIUs to detect financial crime. But they lack the legal frameworks to act on the intelligence. Intelligence without action is a report, not a prosecution. 🔗 Original post:

AUSTRAC is strengthening financial crime-fighting capabilities across the Pacific through training programmes in Papua New Guinea and the Solomon Islands. Supported by Australia’s Department of Foreign Affairs and Trade, the initiatives focus on financial intelligence analysis, cryptocurrency trac...

Address

Thane

Opening Hours

Wednesday 2pm - 6pm
Thursday 2pm - 6pm
Friday 2pm - 6pm
Saturday 2pm - 6pm
Sunday 2pm - 6pm
7pm - 10:50pm

Alerts

Be the first to know and let us send you an email when Advocate Shoeb Hakim posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Advocate Shoeb Hakim:

Shortcuts

Share