Latest Publications

Share:

Overview of the National Cybersecurity Strategy

The Biden-Harris Administration has unveiled its highly anticipated National Cybersecurity Strategy — a sweeping and ambitious document calling for "fundamental changes to the underlying dynamics of the digital ecosystem."...more

NCUA Approves 72-Hour Cyber Incident Reporting Requirement

The National Credit Union Administration (NCUA) has approved a final rule requiring federally chartered and federally insured credit unions to notify NCUA of a "reportable cyber incident" "as soon as possible and no later...more

Federal Court Holds Financial Institution Liable for Business Email Compromise Loss

While ransomware attacks usually grab the headlines, business email compromise (BEC) attacks continue to cause massive financial losses for businesses. The FBI’s Internet Crime Complaint Center (IC3), reported BEC losses in...more

CPPA Solicits Comments on Cyber Audits, Risk Assessment and AI Tech

The California Privacy Protection Agency ("CPPA" or "Agency") is seeking preliminary comments on proposed rulemaking for risk assessments and cybersecurity audits for higher-risk data processing activities, and consumer...more

Recent Decisions Interpreting Illinois Biometrics Law Could Create "Ruinous Liability"

One can scarcely browse the internet without encountering a story on the use of Artificial Intelligence (AI) by businesses or websites. While recently most attention has focused on generative AI and the increasing use of chat...more

FCC Proposes New Rules for CPNI Data Breach Reporting

The Federal Communications Commission ("FCC" or "Commission") has released its long-awaited Notice of Proposed Rulemaking ("NPRM") proposing to revise data breach reporting requirements for telecommunications carriers and...more

SEC Looks to Finalize Proposed Cyber Rules, Issue New NPRM

The U.S. Securities and Exchange Commission (SEC) appears to have big plans for cybersecurity regulation in 2023....more

FedRAMP Codified: A New Law Aims to Streamline Federal Security Authorizations for Cloud Services

Since its inception in 2011, the Federal Risk and Authorization Management Program (FedRAMP) has sought to facilitate adoption of secure cloud computing services by federal government agencies. A newly enacted law, the...more

TSA Seeks Comment on Strengthening Cybersecurity and Resiliency in the Pipeline and Rail Sectors

The Transportation Security Administration (TSA) published an Advance Notice of Proposed Rulemaking (ANPRM) on November 30, 2022, seeking stakeholder comment on ways to strengthen cybersecurity and resiliency for pipeline and...more

New York Department of Financial Services Proposes Significant Amendments to its Cybersecurity Regulation

The New York Department of Financial Services (NYDFS) has proposed significant amendments (Proposed Amendments) to its Cybersecurity Requirements for Financial Services Companies (Cybersecurity Regulation)....more

New York Department of Financial Services' EyeMed Settlement Emphasizes Risk Assessments, Email Controls (UPDATED)

The New York Department of Financial Services (NYDFS) continues to be a major player in data security enforcement. On Oct. 18, 2022, NYDFS announced that it had entered into a consent order with EyeMed Vision Care LLC...more

FTC Extends Deadline to Comply with GLBA Safeguards Rule Until June 9, 2023

On November 15, 2022, the Federal Trade Commission (FTC) announced a six-month extension of the deadline to comply with most provisions of its new Safeguards Rule. Covered "financial institutions" under the Safeguards Rule,...more

New York Financial Services' EyeMed Settlement Emphasizes Risk Assessments, Email Controls

The New York Department of Financial Services (NYDFS) continues to be a major player in data security enforcement. On Oct. 18, 2022, NYDFS announced that it had entered into a consent order with EyeMed Vision Care LLC...more

NY Attorney General Settlement Highlights Challenges of Username and Password Breaches

October was a busy month in New York for cybersecurity enforcement. In addition to a $4.5 million settlement between the New York Department of Financial Services and EyeMed Vision Care (discussed in a forthcoming blog post),...more

A First Look at the Colorado Privacy Act Proposed Rules

The Colorado Attorney General's Office has published its much-anticipated proposed rules (Proposed Rules) implementing the Colorado Privacy Act (CPA), which, as we discussed in an earlier blog post, was enacted on July 7,...more

Carrot or Stick? FERC Grapples With How to Incentivize Electric Utility Cybersecurity Investments

The U.S. electric grid is a prime target for cyberattacks, including by both nation-state actors and organized crime. Electric utilities have been ahead of much of the rest of the energy sector in hardening their...more

CISA Issues RFI For Cyber Reporting Rules and Announces Public Listening Sessions

The federal Cybersecurity & Infrastructure Security Agency (CISA) has issued a request for information (RFI) seeking public input on its development of cyber incident and ransom payment reporting rules under the Cyber...more

CFPB Takes on Failure to Adopt "Common Data Security Practices"

A reminder to financial services firms: the Consumer Financial Protection Bureau (CFPB) is also a data security regulator....more

TSA Revises Cybersecurity Requirements for "Critical" Pipelines and LNG Facilities

The Transportation Security Administration (TSA) has revised and reissued its Security Directive on cybersecurity for critical pipelines and liquified natural gas (LNG) facilities. The new Security Directive takes a more...more

FTC Issues Advance Notice of Proposed Rulemaking on Commercial Surveillance and Data Security

The Federal Trade Commission (FTC) may have just taken its first steps towards the creation of generally applicable federal privacy and security rules. On Aug. 11, 2022, the FTC published an advance notice of proposed...more

FTC Blog: FTC Act Creates "De Facto" Breach Notification Requirement

TThe Federal Trade Commission (FTC) recently published a blog post asserting that Section 5 of the FTC Act may require companies to notify individuals of breaches of their personal data, even where there is no specific breach...more

The Cyber Incident Reporting for Critical Infrastructure Act of 2022: An Overview

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), signed into law by President Biden in March 2022 as part of the Consolidated Appropriations Act of 2022, will require companies operating in...more

Introducing PCI DSS 4.0: New Payment Card Security Standards

On March 31, 2022, the Payment Card Industry Security Standards Council published version 4.0 of its PCI Data Security Standard (PCI DSS). The updated standards provide significant new guidance on the scope and applicability...more

A Warning to Critical Infrastructure: Russia May Launch a Cyberattack Against U.S. Companies

On Monday, March 21, 2022, the White House issued a statement warning of "evolving intelligence" that the Russian government may launch cyberattacks aimed at the United States in response to sanctions arising from Russia's...more

SEC Proposes New Cyber Disclosure Rules for Public Companies

On March 9, 2022, the Securities and Exchange Commission (SEC) announced proposed rules requiring publicly listed companies to make several specific disclosures related to cybersecurity incidents and the registrant's...more

101 Results
 / 
View per page
Page: of 5

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide