Latest Publications

Share:

DoD Publishes Organization-Defined Parameters for NIST SP 800-171 Rev. 3

The U.S. Department of Defense (DoD) recently issued a memorandum signaling that defense contractors soon will be required to comply with new cybersecurity compliance requirements. The memorandum establishes...more

Undeterred by the SolarWinds Storm: SEC Charges Victims of Compromised Software

The SEC on Oct. 22, 2024, announced charges against four companies for allegedly making materially misleading disclosures concerning the impact of cybersecurity incidents associated with the compromised SolarWinds' Orion...more

SEC Cyber Enforcement Update: Which Way Are the SolarWinds Blowing? (Update)

This Holland & Knight blog post is the second installment in a two-part series that examines the challenges to the U.S. Securities and Exchange Commission's (SEC) charges in its landmark case against SolarWinds Corp....more

Court in SolarWinds Case Blows Down SEC's Cyber Enforcement Authority

The U.S. District Court for the Southern District of New York on July 18, 2024, dismissed most of the SEC's landmark cyber enforcement litigation against SolarWinds Corp. (SolarWinds or the Company) and the Company's Chief...more

SEC Expands Scope of Internal Accounting Controls in Cybersecurity Breach Settlement

The SEC continues to expand its cybersecurity enforcement authority to include allegations that a company's failure to monitor its managed security service providers (MSSP) amounts to violations of federal securities laws....more

SEC Cyber Enforcement Update: Which Way Are the SolarWinds Blowing?

The SEC has been aggressively pursuing cybersecurity investigations and enforcement actions against public companies and foreign private issuers. In these actions, the SEC often alleges one of two theories: 1) that the...more

New Tennessee Law Creates Heightened Liability Requirement for Class Action Data Breach Lawsuits

As courts have recognized, "[t]he fact that a company has suffered a security breach does not demonstrate that the company did not place significant emphasis on maintaining a high level of security."1 Nevertheless, companies...more

SEC Corporation Finance Director Voluntarily Weighs in on Cybersecurity Incident Disclosures

The U.S. Securities and Exchange Commission's (SEC) Division of Corporation Finance Director Erik Gerding released a statement on May 21, 2024, addressing Disclosure of Cybersecurity Incidents Determined to be Material and...more

White House, U.S. Coast Guard Seek to Address Maritime Cyber Espionage and Cybersecurity Risks

Topic Links Maritime trade is essential to America's economic viability and national security interests. The U.S. Marine Transportation System (MTS) – comprising an intricate system of ports, terminals, vessels, waterways and...more

SEC Cybersecurity Rules: Considerations for Incident Response Planning

The new Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rules (Final Rules) adopted by the U.S. Securities and Exchange Commission (SEC) were published in the Federal Register on Aug. 4, 2023, and...more

SEC Finalizes Cybersecurity Incident and Governance Disclosure Obligations for Public Companies

The long-awaited U.S. Securities and Exchange Commission (SEC) cybersecurity rules for public companies have finally arrived. On July 26, 2023, a divided SEC adopted new rules requiring each public company to, among other...more

Cyber Incident Reporting Requirements for Critical Infrastructure Sectors Signed into Law

After years of debate, Congress has passed bipartisan legislation requiring owners and operators of critical infrastructure to report cyber incidents to the U.S. Department of Homeland Security (DHS) Cybersecurity and...more

SEC Proposes Cybersecurity Incident and Governance Disclosure Obligations for Public Companies

Less than a month after the U.S. Securities and Exchange Commission (SEC) proposed substantial new cybersecurity requirements for investment advisers and registered investment companies, the commission unveiled a new slate of...more

SEC Proposes Substantial New Cybersecurity Requirements for Investment Advisers and Companies

Following U.S. Securities and Exchange Commission (SEC) Chairman Gary Gensler's recent speech directing the agency to expand cybersecurity requirements on regulated entities, the SEC on Feb. 9, 2022, voted to propose new...more

SEC Chair Gensler Remarks Indicate 2022 Action Expanding Cyber Requirements

U.S. Securities and Exchange Commission (SEC) Chair Gary Gensler made remarks on Jan. 24, 2022, at Northwestern University Pritzker School of Law's Annual Securities Regulation Institute regarding the SEC's work to improve...more

CMMC 2.0 Simplifies Requirements But Raises Risks for Government Contractors

With the announcement of a revamped Cybersecurity Maturity Model Certification (known as CMMC 2.0),1 for the third time in five years, the U.S. Department of Defense (DOD) announced new, comprehensive cybersecurity standards...more

False Claims Act Meets Cybersecurity: DOJ's New Civil Cyber-Fraud Unit

Earlier this week, the U.S. Department of Justice (DOJ) announced the launch of its new Civil Cyber-Fraud Initiative — an effort designed to harness the department's knowledge in civil fraud enforcement, government...more

Holland & Knight's China Practice Newsletter: September-October 2021

Holland & Knight invites you to read our China Practice Newsletter, in which our authors discuss pertinent Sino-American topics. HIGHLIGHTS: - Non-Fungible Tokens and Intellectual Property Law: Key Considerations...more

TSA's Pipeline of Cybersecurity Requirements

The Transportation Security Administration (TSA) on July 20, 2021, reversed two decades of pipeline cybersecurity policies. Having previously advocated for voluntary pipeline cybersecurity standards, the TSA quickly issued...more

SEC Issues First-Ever Penalties for Deficient Cybersecurity Risk Controls

The U.S. Securities and Exchange Commission (SEC) has launched a stunning salvo across the bows of public companies with its announcement of civil monetary penalties and a cease-and-desist order against First American...more

22 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide