Spanish regulators have imposed a nearly $3 million fine on genetic testing company 23andMe for cybersecurity shortcomings that led to a significant data breach in 2023, affecting 6.9 million individuals worldwide, including over 2,600 Spanish citizens1. The Agencia Española de Protección de Datos (AEPD) determined that 23andMe's inadequate security measures enabled the breach, resulting in the exposure of sensitive user data. This decision underscores the importance of robust cybersecurity protocols, particularly for companies handling sensitive personal information. The fine serves as a reminder that regulatory bodies are increasingly holding organizations accountable for failing to protect user data. So what matters to practitioners is that this fine highlights the need for proactive investment in cybersecurity measures to prevent similar breaches and avoid hefty penalties.