Latest Posts › Cybersecurity

Share:

District Court Dismisses Majority of SEC Complaint Against SolarWinds and Its CISO

The U.S. District Court for the Southern District of New York has dealt a significant blow to the cybersecurity enforcement efforts of the U.S. Securities and Exchange Commission (SEC or Commission). In its July 18, 2024,...more

FCC Adopts a Three-Year $200 Million Schools and Libraries Pilot Program for Enhanced Cybersecurity

On June 11, the Federal Communications Commission ("FCC") issued a Report and Order creating the Schools and Libraries Cybersecurity Pilot Program ("Pilot Program") to provide funding for K-12 schools, libraries, and...more

SEC Clarifies Reporting of Material vs. Immaterial Cybersecurity Incidents

The U.S. Securities and Exchange Commission's (SEC) Division of Corporate Finance (Division) published a statement on May 21, 2024, regarding how public companies may disclose cyber incidents they determined to be immaterial....more

SEC Adopts Amendments to Regulation S-P That Require Reporting Breaches of "Sensitive Customer Information"

On May 15, the Securities and Exchange Commission adopted amendments to Regulation S-P, which covers broker-dealers, registered investment advisors (RIAs), and investment companies (funds). These entities are now required to...more

Commerce Department Proposes Cybersecurity/AI Reporting and "KYC" Requirements for Certain Cloud Providers

The U.S. Department of Commerce's ("Commerce") Bureau of Industry and Security ("BIS") has issued a proposed rule (the "Proposed Rule") that would impose significant diligence, reporting, and recordkeeping requirements on...more

DOJ, FBI Issue Guidance for Public Companies Seeking to Delay Disclosure of Material Cybersecurity Incidents

As we discussed in our prior blog post, the Securities and Exchange Commission (SEC) recently finalized its Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule for public companies (the "Rule")....more

CISA, UK NCSC, and 17 Other Countries Issue Landmark Joint Guidelines for Secure AI System Development

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (UK NCSC), along with partner agencies from 17 nations, have released Guidelines for Secure AI System Development (the...more

CISA Releases Revised Draft of Secure Software Development Self-Attestation Form

The Cybersecurity and Infrastructure Security Agency (CISA) has released a revised draft of its Secure Software Development Attestation Common Form ("Form"). The Form, once finalized, will obligate vendors providing software...more

FTC Adds Data Breach Notification Requirement to Safeguards Rule

The Federal Trade Commission (FTC or Commission) has amended its Standards for Safeguarding Customer Information, commonly known as the "Safeguards Rule," to require non-bank financial institutions to report certain data...more

Deadline Extended: ONCD Seeking Public Feedback on Ways to Harmonize Cybersecurity Regulations

The Office of the National Cyber Director (ONCD) has extended the deadline to respond to its Request for Information (RFI) seeking public comment on "opportunities for and obstacles to harmonizing" cybersecurity regulations....more

FCC Proposes Voluntary Cybersecurity Labeling Program for Internet of Things Devices

The Federal Communications Commission (FCC) has published its notice of proposed rulemaking (the NPRM) detailing the proposed creation of a voluntary cybersecurity labeling program for Internet of Things (IoT) or "smart"...more

TSA Updates Cybersecurity Requirements for "Critical" Pipelines and LNG Facilities

On July 26, 2023, the Transportation Security Administration (TSA) issued a revised Security Directive governing the cybersecurity practices of owners and operators of critical liquid and natural gas pipelines and liquified...more

California Regulator Previews Intentions for Cybersecurity, Privacy, and Automated Decisionmaking Regulations

The CPPA kicked off a first round of rulemaking in May 2022 and finalized that set of rules in March of this year. At the latest California Privacy Protection Agency (CPPA) meeting, the CPRA Rules Subcommittee (Rules...more

SEC Adopts Cybersecurity Rule for Public Companies

On July 26, 2023, the U.S. Securities and Exchange Commission (SEC or Commission) finalized its Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule for public companies (the "Final Rule") by a...more

New Iowa Legislation Creates Cybersecurity Safe Harbor

Iowa becomes the fourth U.S. state to provide an affirmative defense for companies that adopt a cybersecurity framework - Iowa is the fourth state—following Ohio, Connecticut, and Utah—to provide a statutory incentive for...more

SEC Delays Proposed Cybersecurity Rules

According to its Spring 2023 rulemaking agenda, the U.S. Securities and Exchange Commission (SEC) has delayed issuance of two sets of cybersecurity requirements that previously were expected to be finalized in April 2023. The...more

Data Breach Notification Law Update: Texas

Texas amended its data breach notification law to significantly tighten the deadline for notifying the state attorney general (AG) of a data breach affecting 250 or more state residents. Senate Bill 768, which amended Section...more

REMINDER: Compliance Deadline for FTC's GLBA Safeguards Rule Is Around the Corner

A reminder to non-bank financial institutions subject to the Gramm-Leach-Bliley Act (GLBA): the deadline to comply with the Federal Trade Commission's (FTC) revised Standards for Safeguarding Customer Information, commonly...more

Indiana Governor Signs Comprehensive Privacy Law

INCDPA takes business-friendly approach to data privacy, following Virginia, Utah, and Iowa - Indiana has become the seventh state to enact a "comprehensive" data privacy law, joining California, Virginia, Colorado,...more

FERC Authorizes Targeted Utility Incentive Rate Options for Advanced Cybersecurity Investments

With Order No. 893, Commission Continues to Prioritize Regulations to Improve Electric Grid Reliability - Cyberattacks continue to threaten the reliability of the electric grid. In response to a congressional directive to...more

FedRAMP Updates 3PAO Standards for Cloud Service Provider Assessments

The Project Management Office (PMO) for the Federal Risk and Authorization Management Program (FedRAMP) has issued an updated version of FedRAMP's 3PAO Obligations and Performance Standards (3PAO Standards), which sets forth...more

CCPA Regulations Approved in California, But Challenges Remain

March 2023 was a consequential month for data privacy law. The California Office of Administrative Law (OAL) formally approved regulations issued by the California Privacy Protection Agency (CPPA) implementing the California...more

Now We Are Six: Iowa Becomes the Sixth State to Enact a Comprehensive Privacy Law

With the unanimous passage of Senate File 262 by the Iowa House and Senate and the Governor's signature Tuesday, the Hawkeye State joins California, Colorado, Connecticut, Virginia, and Utah as one of six states with a...more

Data Breach Notification Law Update: Utah and Pennsylvania

For businesses subject to data breach notification requirements in Utah and Pennsylvania, a series of significant amendments will soon go into effect in both states. ...more

67 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide