Latest Publications

Share:

CISA 2015 Has Sunset. Now What?

The Cybersecurity Information Sharing Act of 2015 (CISA 2015), an important law used by governmental and private-sector entities to share "cyber threat indicators" and "defensive measures," has sunset. Although Congress was...more

CISA Delays Cyber Incident Reporting Rules Until May 2026

The Cybersecurity & Infrastructure Security Agency (CISA) has delayed publication of its cyber incident reporting rule for critical infrastructure operators. According to an entry on the Office of Management and Budget's...more

Department of Defense Issues Final Rule to Implement Cybersecurity Maturity Model Certification (CMMC) Program

After more than six years of deliberations, significant revisions, and volumes of commentary from defense contractors, the Department of Defense (DoD) has finalized its Cybersecurity Maturity Model Certification (CMMC)...more

Sixth Circuit Upholds FCC Data Breach Order: Analyzing the Implications for Telecom Carriers and the FCC

The U.S. Court of Appeals for the Sixth Circuit recently upheld data breach reporting requirements issued by the Federal Communications Commission (FCC or Commission) in 2023 (Data Breach Order) in its August 13, 2025 2-1...more

Trump Reverses Key Directives of Biden Cyber Executive Order, Maintains Others

During his last few days in office, on January 16, 2025, President Biden issued Executive Order 14144, "Strengthening and Promoting Innovation in the Nation's Cybersecurity" (EO 14144). Building heavily on the May 2021...more

NSA Issues Cybersecurity Guidance and Best Practices for AI Systems

The National Security Agency (NSA), in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI) and cybersecurity agencies from Australia, New Zealand, and the...more

5th Circuit Holds That Jarkesy Invalidates FCC Forfeiture Order Against AT&T

The U.S. Court of Appeals for the 5th Circuit held that the Federal Communications Commission (FCC or Commission) violated AT&T's Seventh Amendment right to a jury trial and right to adjudication by an Article III court when...more

FedRAMP 20x Initiative Promises Major Changes for Federal Cloud Service Providers

Major changes are coming again to the Federal Risk and Authorization Management Program ("FedRAMP"), the federal government's cybersecurity authorization program for cloud service providers ("CSPs")....more

DOJ Issues Guidance on Foreign Data Access Rule, Announces Conditional 90-Day Enforcement Pause for "Good Faith Efforts"

The Department of Justice (DOJ) has issued guidance on its recently effective rule targeting foreign adversaries that "use commercial activities to access, exploit, and weaponize U.S. Government-related data and Americans'...more

Deadline Approaching: Covered Entities Must File Certifications of Compliance With Amended NYDFS Cyber Regulation by April 15

In November 2023, the New York Department of Financial Services (NYDFS) issued its second amendment to its "Cybersecurity Requirements for Financial Services Companies (the Cybersecurity Regulation or Part 500). This was the...more

Regulatory Reset? U.S. Cyber Incident Reporting Rules Face Congressional Scrutiny

Lawmakers expressed bipartisan support for significantly amending or eliminating some cybersecurity incident notification requirements during a recent hearing of the U.S. House Committee on Homeland Security's Subcommittee on...more

PCI SSC Clarifies Obligations for Ecommerce Merchants That Outsource Payment Card Processing

The Payment Card Industry Security Standards Council (PCI SSC) has issued an FAQ for ecommerce merchants that outsource their payment card processing to a vendor using an embedded payment page or form (such as an "iframe")....more

Analyzing President Biden's Ambitious Cybersecurity Executive Order

In his final days in office, President Biden signed an ambitious executive order to improve the federal government's approach to cybersecurity. Executive Order 14114 ("Executive Order"), issued January 16, 2025, titled...more

DOJ Issues Final Rule Targeting Foreign Access to Americans’ Sensitive Data

The U.S. Department of Justice (DOJ) has issued a comprehensive final rule (the "Rule") targeting foreign access to sensitive U.S. data, including Americans' "bulk" sensitive personal data....more

District Court Dismisses Majority of SEC Complaint Against SolarWinds and Its CISO

The U.S. District Court for the Southern District of New York has dealt a significant blow to the cybersecurity enforcement efforts of the U.S. Securities and Exchange Commission (SEC or Commission). In its July 18, 2024,...more

FCC Adopts a Three-Year $200 Million Schools and Libraries Pilot Program for Enhanced Cybersecurity

On June 11, the Federal Communications Commission ("FCC") issued a Report and Order creating the Schools and Libraries Cybersecurity Pilot Program ("Pilot Program") to provide funding for K-12 schools, libraries, and...more

SEC Clarifies Reporting of Material vs. Immaterial Cybersecurity Incidents

The U.S. Securities and Exchange Commission's (SEC) Division of Corporate Finance (Division) published a statement on May 21, 2024, regarding how public companies may disclose cyber incidents they determined to be immaterial....more

SEC Adopts Amendments to Regulation S-P That Require Reporting Breaches of "Sensitive Customer Information"

On May 15, the Securities and Exchange Commission adopted amendments to Regulation S-P, which covers broker-dealers, registered investment advisors (RIAs), and investment companies (funds). These entities are now required to...more

Commerce Department Proposes Cybersecurity/AI Reporting and "KYC" Requirements for Certain Cloud Providers

The U.S. Department of Commerce's ("Commerce") Bureau of Industry and Security ("BIS") has issued a proposed rule (the "Proposed Rule") that would impose significant diligence, reporting, and recordkeeping requirements on...more

CFTC Approves Two Rulemaking Proposals and a DCO Application

The Commodity Futures Trading Commission ("CFTC" or "Commission") issued two proposed rules on December 18, 2023, both of which are now open for public comment. The first proposed rule would create an "Operational Resilience...more

DOJ, FBI Issue Guidance for Public Companies Seeking to Delay Disclosure of Material Cybersecurity Incidents

As we discussed in our prior blog post, the Securities and Exchange Commission (SEC) recently finalized its Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule for public companies (the "Rule")....more

CISA, UK NCSC, and 17 Other Countries Issue Landmark Joint Guidelines for Secure AI System Development

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (UK NCSC), along with partner agencies from 17 nations, have released Guidelines for Secure AI System Development (the...more

CISA Releases Revised Draft of Secure Software Development Self-Attestation Form

The Cybersecurity and Infrastructure Security Agency (CISA) has released a revised draft of its Secure Software Development Attestation Common Form ("Form"). The Form, once finalized, will obligate vendors providing software...more

FTC Adds Data Breach Notification Requirement to Safeguards Rule

The Federal Trade Commission (FTC or Commission) has amended its Standards for Safeguarding Customer Information, commonly known as the "Safeguards Rule," to require non-bank financial institutions to report certain data...more

108 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide