Latest Publications

Share:

Preparing for the California Cyber Audit Regulations

On September 23, 2025, the California Privacy Protection Agency confirmed that their cyber audit regulations will at long last go into effect on January 1, 2026. You can be forgiven for losing track since these were...more

DOJ Posts New FAQ for the “Bulk Data” Rule

The U.S. Department of Justice (DOJ) “Data Security Program” (DSP), also known as the “Sensitive Data Rule” or “Bulk Data Rule,” has prompted numerous questions about its scope and application....more

Cybersecurity Enforcement Intensifies: DoD Issues Final CMMC Rule and Updates DFARS

The U.S. Department of Defense recently issued a final rule to implement the Cybersecurity Maturity Model Certification Program, and defense contractors will be subject to a variety of cybersecurity obligations when the rule...more

US-Based Tech Startups at Risk of Exploitation Through International Pitch Competitions

U.S. and Canadian agencies have issued an advisory to alert tech startups that entities affiliated with the People’s Republic of China (PRC) government are exploiting international pitch competitions to advance the PRC’s tech...more

Salt Typhoon Cyberattacks: Updated Threat Assessment and Recommended Mitigations

U.S. federal agencies, including the Federal Bureau of Investigation (FBI), National Security Agency, and Cybersecurity and Infrastructure Security Agency (CISA), along with security and intelligence agencies from 12 partner...more

How the White House’s AI Action Plan Aims To Ensure American Leadership in AI

Key Takeaways - - The White House’s recently released AI Action Plan and accompanying executive orders aim to solidify the United States’ position as a global leader in AI and lay out key focus areas that will steer federal...more

DOJ’s Bulk Personal Data Rule Becomes Effective–Resources for Compliance

The new Department of Justice (DOJ) rule governing international transfers of Americans’ information, codified at 28 C.F.R. Part 202, became effective on April 8, 2025....more

New US Commerce Prohibitions on Chinese and Russian Connected Vehicle Technology

New security rules designed to protect the connected vehicle supply chain will take effect in March unless they are withdrawn. The U.S. Department of Commerce Bureau of Industry and Security (BIS) published the final rule...more

User’s Guide to DOJ & CISA Rules Implementing Executive Order 14117

Executive Order (EO) 14117 is a national security rule intended to mitigate national security risks posed by threat countries’ access to sensitive personal data and government-related data. The EO directed the U.S....more

Two Tools for Trump To Dismantle Biden-Era Rules: the Regulatory Freeze and the Congressional Review Act

President Donald Trump has issued a presidential memorandum, which has the effect of an Executive Order, titled “Regulatory Freeze Pending Review“ (the Regulatory Freeze). This Regulatory Freeze puts a hold on new agency...more

DOJ’s Final Rule on Data Transfers: Impacts Across Industries

As of January 23, 2025, the regulation discussed below has not been withdrawn by the Trump administration and is not subject to automatic withdrawal under President Trump’s Executive Order freezing regulations. It currently...more

Proposed DOJ FARA Rules Would Increase Uncertainty for Global Companies Amid Heightened Enforcement

The U.S. Department of Justice (DOJ) published a Notice of Proposed Rulemaking (NPRM) to update regulations under the Foreign Agents Registration Act of 1938 (FARA) on January 2, 2025. If adopted, DOJ’s proposed changes would...more

Treasury’s Final Rule on Outbound Investments Takes Effect January 2

On January 2, 2025, the U.S. Department of the Treasury’s (Treasury) regulation restricting U.S. outbound investments in certain advanced technology sectors in China (the Final Rule) takes effect. Thereafter, investments by...more

Department of Commerce Adopts Final Rule Restricting Tech and Telecom Supply Chain Transactions With Foreign Adversaries

The U.S. Department of Commerce’s Bureau of Industry and Security (BIS), issued its much anticipated Final Rule under Executive Order 13873, Securing the Information and Communications Technology and Services Supply Chain (EO...more

Salt Typhoon Cyberattacks: New Federal Cybersecurity Guidelines for Telecoms

U.S. federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) (in coordination with similar agencies in Australia,...more

DOJ’s Notice of Proposed Rulemaking on Sensitive Personal Data and Government-Related Data

In October 2024, the U.S. Department of Justice (DOJ) issued a 420-page Notice of Proposed Rulemaking (NPRM) to implement Executive Order (EO) 14117, which directed DOJ to issue implementing regulations and directed the U.S....more

CISA Security Requirements for Restricted Data Transactions Under New DOJ Rule

President Joe Biden issued Executive Order (EO) 14117 in February 2024 to mitigate national security risks posed by threat countries’ access to sensitive personal data and government-related data. The EO directed the U.S....more

‘Tis the Season… for Cybercriminals: A Holiday Reminder for Retailers

As the holiday shopping season kicks into high gear, it also becomes a prime opportunity for cybercriminals to target retailers, their suppliers, and their customers.  As The Hacker News reports, criminal use of artificial...more

Strike Force Cases Highlight Focus on National Security Priorities and Need for Strengthened Cybersecurity

The U.S. Department of Justice (DOJ) announced criminal charges in five cases in connection with the Disruptive Technology Strike Force (Strike Force) on September 16, 2024. Launched in February 2023, the Strike Force is...more

A New National Security Frontier: Executive Order and Coming Regulations Restricting US Technology Investments in China

President Biden issued a long-awaited executive order, “Addressing United States Investments in Certain National Security Technologies and Products in Countries of Concern” (the Executive Order or E.O.), on August 9, 2023,...more

New Risk-Based Security Requirements for Federally Funded Research at US Institutions of Higher Education

International cooperation and welcoming foreign academics are critical to the success and leadership of U.S. institutions of higher education. These interactions enhance fundamental scientific research and promote the...more

It’s Official: Cybersecurity Disclosure Is Coming This Year

The U.S. Securities and Exchange Commission (SEC) adopted final rules on July 26, 2023, requiring public companies to provide current disclosure, within what may be a short time window, about material cybersecurity incidents...more

Cybersecurity Implementation Plan Offers a Roadmap for Cyber Priorities

The Biden Administration recently reaffirmed its continued focus on cybersecurity by announcing an Implementation Plan for the National Cybersecurity Strategy (the Plan). The Plan provides a roadmap covering the policies and...more

Sector-Based Cybersecurity Requirements for Critical Infrastructure, From Our Water Systems to the Skies

Following the release of President Biden’s National Cybersecurity Strategy, Acting National Cyber Director Kemba Walden explained that the Biden Administration is “expecting more” from owners and operators in critical...more

DOJ Announces Shift Toward Corporate Enforcement for Sanctions and Export Control Violations

Deputy Attorney General (DAG) Lisa Monaco once again delivered groundbreaking remarks at the American Bar Association (ABA) National Institute on White Collar Crime (ABA White Collar Conference) on March 2, 2023, this time...more

37 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide