Latest Posts › Cybersecurity

Share:

DOD Progresses Toward CMMC 2.0 Implementation with New Proposed Rule

The US Department of Defense (DoD) has issued a new proposed rule for implementing the next iteration of the Cybersecurity Maturity Model Certification (CMMC) 2.0 program. This action drives forward the DoD’s plans to bolster...more

SEC Releases Interpretations on Ransomware Attacks and Payment Disclosures

The US Securities and Exchange Commission (SEC), Division of Corporation Finance on June 24, 2024 issued five Compliance and Disclosure Interpretations (C&DIs) on its website to address questions raised by its requirement for...more

SEC’s New Data Breach Requirement Increases Obligations for Financial Services Companies

The US Securities and Exchange Commission has adopted amendments to Regulation S-P requiring entities under its remit to provide notice to individuals affected by certain types of data breaches. This adds yet another...more

Global Privacy: Year in Review and a Look Forward, 2023–2024

The world is witnessing a flurry of activity surrounding issues of data protection, cybersecurity, artificial intelligence (AI), and consumer privacy. According to the National Conference of State Legislators, some 40 US...more

California Enacts the Delete Act

In October, California enacted its newest privacy legislation, commonly referred to as the “Delete Act” (California Senate Bill No. 362). The Delete Act will allow consumers to request that any data broker that maintains any...more

Navigating the Evolving Landscape of State Consumer Privacy Laws

With the flurry of new consumer privacy laws enacted in states across the country, it is vital for companies operating in multiple states to remain informed of this changing landscape in order to plan and execute their...more

Navigating The Global Data Privacy Landscape: What Multinational Corporations Should Consider When Doing Business

The ever-evolving data privacy landscape continues to become more complex as new developments play out on the global stage. In the United States, a number of individual state laws have come into force, with more following in...more

SEC Adopts Rules on Mandatory Cybersecurity Disclosures

The US Securities and Exchange Commission (SEC) adopted on July 26, 2023 final rules and amendments for mandating disclosure regarding cybersecurity risk management, strategy, governance, and incident reporting, including...more

US, UK, and EU Collective Actions in the Privacy and Cybersecurity Space

Unlike the United States, the United Kingdom and, so far, the EU Member States do not all have domestic class action regimes or a cross-border class action regime (as detailed below), and instead have collective actions....more

Data Privacy and AI Regulation in Europe, the UK, and US

Artificial intelligence (AI) magnifies the ability to analyze personal information in ways that may intrude on privacy interests, which can give rise to legal issues. Generally, there are two types of concerns with AI and...more

What Businesses Should Know About State Consumer Privacy Laws

With the lack of comprehensive federal consumer privacy legislation, states are charting an evolving course for businesses to follow when handling data and information about their customers. Led by California, several other...more

Global Privacy Year in Review - March 2023

The need for privacy and cybersecurity compliance measures has become a paramount consideration as businesses become more digitally driven, data breaches become more publicized, and regulation continues to increase. Morgan...more

European Commission Releases Draft Adequacy Decision for US Personal Data Transfers

The European Commission recently released a draft adequacy decision for the European Union and United States Transatlantic Data Privacy Framework (TDPF). If the decision is finalized, data transfers between the European Union...more

California Consumer Privacy Act: Employee and B2B Exemptions Expire January 1, 2023

The California Consumer Privacy Act (CCPA) exemptions for employee and business-to-business (B2B) personal information have not been extended, further complicating the privacy regulatory landscape for businesses in...more

SEC Proposes Mandatory Cybersecurity Disclosures

The US Securities and Exchange Commission has proposed new rules and amendments to mandate disclosure regarding cybersecurity risk management, strategy, governance, and incident reporting, including amendments to Form 8-K,...more

SEC Proposes Cybersecurity Risk Management Rules for Advisers and Funds

The US Securities and Exchange Commission (SEC) recently proposed a comprehensive framework of cybersecurity-related rules and amendments for investment advisers and investment companies. Although advisers and funds may have...more

New York Attorney General Releases Guide on Credential Stuffing Attacks

We have heard time and time again that we should not reuse passwords across accounts—if a cybercriminal were to obtain access to the password of one account, they could then use such password to access multiple accounts. This...more

Expanded Safeguards Rule Applicable to More Financial Institutions; Gives More Specificity on Security Requirements

The Federal Trade Commission recently finalized a long-discussed update to its cybersecurity Safeguards Rule that includes more specific criteria for what financial institutions must implement as part of their information...more

OFAC Issues Updated Advisory on Sanctions Risks for Facilitating Ransomware Payments

The US Department of the Treasury’s Office of Foreign Assets Control (OFAC) recently issued an “Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments.” This advisory continues prior advisory...more

UK Adequacy Decision for European Data Transfers

The European Commission has finally approved two decisions  on 28 June granting the United Kingdom the cherished status of having “adequate” data protection laws so that transfers of personal data from the European Union are...more

Ezra Church and the Impact of the CCPA

Welcome to the second post in our Spotlight series, where we talk with a leader in a particular field or emerging area of interest to technology and sourcing lawyers and professionals. ...more

Practical Advice on Privacy: COVID-19 Pandemic Will Not Delay July 1 CCPA Enforcement Date

Despite the coronavirus (COVID-19) pandemic, the California attorney general intends to enforce the California Consumer Privacy Act (CCPA) beginning July 1, 2020, pending the anticipated approval from the California Office of...more

CCPA: What Companies Need To Do Ahead Of July 1 Enforcement

With the July 1 enforcement of the California Consumer Privacy Act (CCPA) less than a month away, the state attorney general has finally submitted the final text of the proposed CCPA regulations to the California Office of...more

Practical Advice on Privacy: CCPA: What Companies Need to Do Ahead of July 1 Enforcement

With the July 1 enforcement of the California Consumer Privacy Act (CCPA) less than a month away, the state attorney general has finally submitted the final text of the proposed CCPA regulations to the California Office of...more

Data Breach Checklist

Since the global coronavirus (COVID-19) pandemic began, attempted cyberattacks have increased dramatically. It is no longer a question of whether bad actors will target a company; it’s a question of when a cyberattack will...more

30 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide