Latest Posts › Cybersecurity

Share:

NYDFS Updates Regulated Firms on Upcoming Cyber Requirements

Financial firms doing business in New York should be mindful of a recent e-blast sent by the state’s financial regulator concerning cybersecurity requirements that become effective in less than two months. The New York...more

Privacy, Cybersecurity and Data Innovation Law — 2024 Year in Review

2024 saw continued expansion of laws, regulations and enforcement actions concerning privacy and data security. With no overarching federal privacy law, states continue to expand their enforcement. Four new comprehensive...more

Texas Positions Itself as a Privacy Enforcement Leader

Since the Texas Data Privacy and Security Act (TDPSA) took effect in July 2024, Texas has emerged as a leader in privacy enforcement. The Texas attorney general (AG) recently announced: “Any entity abusing or exploiting...more

SEC Announces Penalties Against Four Companies for Downplaying Severity of SolarWinds Cybersecurity Breach in Disclosures

On Oct. 22, 2024, the Securities and Exchange Commission announced that it charged four technology companies with making materially misleading disclosures about the effect the SolarWinds cyberattack had on these issuers. To...more

NY Department of Financial Services Releases AI Cybersecurity Guidance

The New York Department of Financial Services (DFS) issued guidance recently concerning cybersecurity risks associated with artificial intelligence (AI) and measures that covered entities (generally, banks, insurers and other...more

Southern District of New York Dismisses Most Claims in SEC Cybersecurity-Related Enforcement Action Against SolarWinds

On July 18, 2024, U.S. District Judge Paul A. Engelmayer of the Southern District of New York dismissed most of the charges that the Securities and Exchange Commission brought against SolarWinds and its chief information...more

SEC Division of Corporation Finance Clarifies Form 8-K Disclosures of Material Cybersecurity Incidents

On May 21, 2024, the director of the SEC’s Division of Corporation Finance, Erik Gerding, issued a statement regarding the new requirement to disclose material cybersecurity incidents on Form 8-K. The SEC’s latest...more

SEC Adopts Significant Cybersecurity Amendments to Regulation S-P

On May 16, 2024, the Securities and Exchange Commission (SEC) adopted final amendments to Regulation S-P, one year after issuing the proposed amendments (discussed here). Regulation S-P is a set of privacy rules that govern...more

Federal Privacy Bill Aims To Consolidate US Privacy Law Patchwork

On April 7, 2024, Sen. Maria Cantwell, chair of the Senate Commerce Committee, and Rep. Cathy McMorris Rodgers, chair of the House Energy and Commerce Committee, advanced a new federal privacy bill to the House floor titled...more

Privacy and Data Security Law 2023 Year in Review

The year 2023 saw continued expansion of public interest in privacy rights, data security and related legislation. Comprehensive privacy laws took effect in five states, while 12 more states enacted similar laws that will...more

AI Policies

Since the release of ChatGPT in late 2022, popular use of artificial intelligence (AI) has exploded. One survey reported that over 56% of employees already use AI at work, with 1 in 10 using it daily. However, only 26% of...more

NY Department of Financial Services Finalizes Significant Amendments to Its Cybersecurity Regulations

The New York State Department of Financial Services (NYDFS) adopted comprehensive amendments to its cybersecurity regulations (known as Part 500) on Nov. 1. The draft amendments were first published in July 2022 and finalized...more

California Passes the Delete Act, Establishing a Single Location for Consumers to Delete Their Personal Information From Data...

Gov. Gavin Newsom signed the Delete Act (the Act) on Oct. 11, making it easier for California consumers to instruct data brokers to delete their personal information or refrain from selling or sharing it. Consumers already...more

SEC Finalizes New Cybersecurity Disclosure Rules

By a 3-2 vote on July 26, the U.S. Securities and Exchange Commission (SEC) adopted final rules enhancing disclosure requirements regarding public companies’ cybersecurity risk management, strategy, governance and incident...more

US and EU Finalize New Data Privacy Framework

On July 10, the European Union and the United States finalized the EU-U.S. Data Privacy Framework (DPF), an agreement that allows for the transfer of personal data from residents of the EU to certified companies in the U.S....more

Corporate Governance: 2023 Midyear Review

The public and private focus on corporate governance continued apace in the first half of 2023. In recent months, there were notable developments in jurisprudence potentially impacting corporate diversity initiatives and in...more

Comparing the Six Comprehensive State Privacy Laws

Recently, Iowa became the sixth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado, Utah and Connecticut. Although privacy laws have existed in the U.S. for decades,...more

SEC Proposes Data Breach Notification and Incident Response Requirements

On March 15, 2023, the Securities and Exchange Commission (SEC) proposed three rule changes that demonstrate its continued focus on cybersecurity. One of these proposals, and the only one to be unanimously approved (the...more

SEC Issues $3 Million Penalty Against Blackbaud for Misleading Cybersecurity Incident Disclosures

On March 9, software company Blackbaud agreed to pay $3 million to the SEC as a result of alleged misleading disclosures arising out of a 2020 data breach that involved customer bank account information and Social Security...more

Cybersecurity in the Boardroom: ‘Caremark’ Liability for Boards’ Failure to Oversee Cybersecurity

In an era of increasing cyberattacks by varying threat actors, the board's oversight of cybersecurity risks remains a key responsibility. In two recent cases, the Delaware Court of Chancery (Chancery Court) dismissed Caremark...more

Cybersecurity, Privacy and Data Protection 2022 Year in Review

The year 2022 saw a groundswell of interest in privacy rights and related legislation. Five states enacted new laws or regulations aimed at protecting a general right to privacy, while the U.S. government came closer than...more

New York State Department of Financial Services To Amend Cybersecurity Regulations for Financial Services Companies

The New York State Department of Financial Services (NYDFS) has published proposed amendments to its Cybersecurity Requirements for Financial Services Companies (amendments). The amendments to the agency’s cybersecurity...more

Proposed FTC Order Targets Drizly and Its CEO for Allegedly Lax Information Security Standards Following Data Breach

On Oct. 24, the Federal Trade Commission (FTC) issued a proposed decision and order against Drizly LLC and its CEO regarding allegations that the company’s security failures led to a data breach exposing the personal...more

Federal Privacy Bill Shows Emerging Patterns in US Privacy Law

On July 20, 2022, the House Committee on Energy and Commerce advanced a new federal privacy bill titled the American Data Privacy and Protection Act (ADPPA) to the House floor. Although it is not yet law, many commentators...more

Comparing the 5 Comprehensive Privacy Laws Passed by US States

On May 10, 2022, Connecticut became the fifth state to enact a comprehensive privacy law to protect personal data, joining California, Virginia, Colorado and Utah. Although privacy and data security laws have existed in the...more

52 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide