In the aftermath of a cyberattack, forensic investigations are often launched under intense pressure to identify what went wrong, why, and how to fix it. A common practice following such an investigation is the preparation of...more
On October 21, 2025, much of the internet stopped behaving as expected. The largest cloud provider in the world, Amazon Web Services (AWS), suffered a significant service disruption that rippled through countless businesses,...more
10/28/2025
/ Business Continuity Plans ,
Cloud Computing ,
Cloud Service Providers (CSPs) ,
Cybersecurity ,
Data Security ,
Incident Response Plans ,
NYDFS ,
Risk Management ,
Technology Sector ,
Third-Party Risk ,
Vendors
"It's the boogeyman… and he's been here all along." – Laurie Strode, Halloween (1978) - As Cybersecurity Awareness Month unfolds and Halloween looms, one of the most chilling threats haunting today's businesses isn't a hacker...more
A growing number of U.S. states are requiring businesses to offer mechanisms in their privacy policies or online interfaces to allow individuals to "opt out" of data collection. However, in increasing numbers, many states are...more
10/17/2025
/ California Consumer Privacy Act (CCPA) ,
California Privacy Rights Act (CPRA) ,
Consumer Privacy Rights ,
Data Controller ,
Data Privacy ,
Data Protection ,
Opt-Outs ,
Personal Data ,
Privacy Policy ,
Regulatory Requirements ,
State Privacy Laws ,
Websites
October is Cybersecurity Awareness Month – a perfect time to take stock of what's really driving today's cyber losses and how your business may be affected. NetDiligence's 2025 Cyber Claims Study, analyzing more than 10,000...more
Cyber threats don't wait for an invitation – and they certainly don't take a break when the calendar flips to October. As Cybersecurity Awareness Month 2025 begins, the stakes have never been higher. Every organization, from...more
10/2/2025
/ Artificial Intelligence ,
Business E-Mail Compromise (BEC) ,
Class Action ,
Cyber Threats ,
Cybersecurity ,
Data Breach ,
Data Security ,
Financial Services Industry ,
Healthcare ,
Incident Response Plans ,
Notification Requirements ,
Ransomware ,
Regulatory Requirements ,
Supply Chain ,
Web Tracking
IBM and the Ponemon Institute have released the 2025 Cost of a Data Breach Report. The report, which has become an annual late-summer tradition, highlights the evolving risks and costs associated with data breaches. This...more
8/26/2025
/ Artificial Intelligence ,
Corporate Counsel ,
Cyber Attacks ,
Cybersecurity ,
Data Breach ,
Data Protection ,
Data Security ,
Phishing Scams ,
Ransomware ,
Regulatory Requirements ,
Risk Management
As the race for real-time data access intensifies, organizations are confronting a growing legal and operational challenge: web scraping. What began as a fringe tactic by hobbyists has evolved into a sophisticated,...more
Microsoft has just disclosed a serious vulnerability in SharePoint (CVE-2025-53770) that allows unauthenticated attackers to remotely execute code in a SharePoint server hosted on-prem – no user interaction required....more
In the chaos following a cyberattack, forensic reports are often pulled together under intense pressure and can assist companies in responding to and remediating the incident. However, if you're not careful, these reports...more
5/20/2025
/ Attorney-Client Privilege ,
Class Action ,
Corporate Counsel ,
Cybersecurity ,
Data Breach ,
Discovery ,
e-Discovery ,
Evidence ,
Forensic Examination ,
Litigation Strategies ,
Risk Management
Wild, wild, west? Web tracking may be the new frontier in class action litigation. With thousands of lawsuits filed in California and increasingly in other states against organizations, including many who may not realize the...more
In late February, California lawmakers introduced new legislation that would impose sweeping restrictions on the use of location and tracking data. Known as the California Location Data Act (CLDA), this legislation goes a...more
Colorado waded into the deep end of AI regulation last year with the Colorado AI Act (Senate Bill 24-205), a sweeping law designed to rein in the risks of artificial intelligence (AI) and automated decision systems (ADS)....more
2/13/2025
/ Artificial Intelligence ,
Automated Decision Systems (ADS) ,
Colorado ,
Consumer Protection Laws ,
Corporate Counsel ,
Data Privacy ,
Enforcement ,
Machine Learning ,
New Legislation ,
Regulatory Reform ,
Risk Management ,
State Legislatures ,
Technology Sector
In today's digital landscape, data brokers are like modern-day gold miners, sifting through the intimate details of our lives – our addresses, financial records, Social Security numbers – and quietly turning that information...more
California is making waves with its new AI law, Assembly Bill 2013 (AB 2013), set to take effect in 2026. This groundbreaking legislation (again) puts the state at the forefront of tech regulation by tackling one of AI's...more
12/4/2024
/ Algorithms ,
Artificial Intelligence ,
Bias ,
California ,
Copyright ,
Corporate Counsel ,
Cybersecurity ,
Data Management ,
Deep Fake ,
Innovative Technology ,
Machine Learning ,
New Legislation ,
Popular ,
Technology Sector ,
Transparency
The conclusion of Cybersecurity Awareness Month is a reminder of the importance for organizations to implement robust security measures and promote good cyber hygiene. As we noted in our State of the Cyber Landscape webinar,...more
11/6/2024
/ Best Practices ,
Cyber Attacks ,
Cyber Threats ,
Cybersecurity ,
Cybersecurity Framework ,
Data Privacy ,
Data Protection ,
Data Security ,
Incident Response Plans ,
Risk Assessment ,
Risk Management
The U.S. Court of Appeals for the Second Circuit reinstated a proposed class action by Michael Salazar against a professional sports organization on October 15, 2024, alleging violations of the Video Privacy Protection Act...more
10/25/2024
/ Consent ,
Consumer Privacy Rights ,
Data Privacy ,
Data Protection ,
Online Platforms ,
Online Videos ,
Personally Identifiable Information ,
Subscribers ,
VPPA ,
Web Tracking ,
Websites
In this era of big data, smart devices, and constant connectivity, the clock's already ticking on your next data breach – it's just a matter of time. For companies of all sizes and across every industry, the stakes have never...more
The financial services industry has seen a litany of new data privacy and cybersecurity challenges through the first half of 2024. Financial institutions are facing unprecedented compliance hurdles resulting from the...more
6/3/2024
/ Artificial Intelligence ,
Continuing Legal Education ,
Cyber Incident Reporting ,
Cybersecurity ,
Cybersecurity Information Sharing Act (CISA) ,
Data Breach ,
Data Privacy ,
Disclosure Requirements ,
Enforcement Actions ,
Financial Institutions ,
Financial Services Industry ,
Incident Response Plans ,
New Guidance ,
New Regulations ,
New Rules ,
Notice of Proposed Rulemaking (NOPR) ,
Notification Requirements ,
Regulation S-P ,
Reporting Requirements ,
Risk Management ,
Securities and Exchange Commission (SEC) ,
State Privacy Laws ,
Third-Party Risk ,
Webinars
In recognition of International Privacy Day on January 28, we wanted to share some insights on the top privacy and cybersecurity issues for the new year. Data privacy and cybersecurity will continue to be one of the most...more
1/29/2024
/ Artificial Intelligence ,
Compliance ,
Consumer Privacy Rights ,
Cyber Threats ,
Cybersecurity ,
Data Privacy ,
Data Protection ,
Data Security ,
Deep Fake ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Incident Response Plans ,
Personal Information ,
Policies and Procedures ,
Popular ,
Ransomware ,
Reporting Requirements ,
Risk Management ,
Securities and Exchange Commission (SEC) ,
State Privacy Laws ,
Supply Chain
Fraudulent activity in the financial industry is nothing new. The techniques employed by fraudsters have ranged from fake check fraud and credit card fraud to identity theft and financial account takeovers. For years,...more
The era of generative AI is here. The surge in popularity of ChatGPT has created a massive disruption as companies balance the benefit of accelerated productivity against the potential risks. The tension between innovation...more
The Securities and Exchange Commission (SEC) continued its focus on cybersecurity regulations this month by announcing three new proposed rules and re-opening the comment period on an additional proposed rule from last year....more
It's no secret that plaintiffs' firms have been developing legal theories relating to third-party software technologies used on websites. This includes a recent spike in lawsuits alleging that websites running the Meta...more
The National Credit Union Administration (NCUA) has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a...more