News & Analysis as of

Multi-Factor Authentication Cybersecurity

Orrick, Herrington & Sutcliffe LLP

NYDFS’ amendments go into effect on November 1

On November 1, NYDFS’ expanded requirements for multi-factor authentication (MFA) and IT asset management went into effect, as part of the NYDFS’ Second Amendment to the Cybersecurity Regulation (Part 500). Details regarding...more

Lasher Holzapfel Sperry & Ebberson PLLC

AI-Powered Scams Are on the Rise: What You Need to Know and How to Protect Yourself

Artificial intelligence (“AI”) continues to transform society in ways beyond imagination. It is rapidly becoming clear that AI pervades every aspect of society, and criminal activity has been no exception. AI is now...more

Goodwin

Beyond the Perimeter: Securing OAuth Tokens and API Access to Thwart Modern Cyber Attackers

Goodwin on

OAuth tokens streamline access but create new vulnerabilities that threat actors are exploiting. Learn how to secure token infrastructure through robust monitoring, governance, and vendor management....more

Constangy, Brooks, Smith & Prophete, LLP

Cybersecurity Awareness Month: Protecting people, data, business integrity

October is National Cybersecurity Awareness Month, which is celebrating its 21st year. Spearheaded, organized and led by the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance, the...more

Herbert Smith Freehills Kramer

New York’s Department of Financial Services Fines Eight Auto Insurance Companies Over $19M for Cybersecurity Violations

On October 14, 2025, New York’s Department of Financial Services (DFS) fined eight auto insurance companies for violating its cybersecurity regulations (known as “Part 500”). The fines come as recent amendments to Part 500...more

BakerHostetler

Paxton Sues PowerSchool

BakerHostetler on

Nearly a year after PowerSchool’s December 2024 data breach, the cloud-based software provider is facing a lawsuit initiated by Texas Attorney General Ken Paxton. PowerSchool is a leading global provider of technology...more

K2 Integrity

Cybersecurity Awareness Month: Identifying And Avoiding Phishing Attacks

K2 Integrity on

Cybersecurity Awareness Month was established to provide resources to organizations and their employees to help them stay safer and more secure online. It is an opportunity to focus on four key behaviors: creating strong...more

Hogan Lovells

NYDFS: Final set of cybersecurity requirements under amended Part 500 take effect November 1, 2025

Hogan Lovells on

On November 1, 2025, additional cybersecurity requirements introduced by the Second Amendment to the New York Department of Financial Services (NYDFS) Cybersecurity Regulation (23 NYCRR Part 500) (the “Second Amendment”) will...more

Lowenstein Sandler LLP

On-Premises Oracle EBS Systems at Risk Due to CL0P Exploit

Lowenstein Sandler LLP on

A recent campaign by the CL0P ransomware group has targeted on-premises, customer-managed Oracle E-Business Suite (EBS) systems, resulting in the potential for widespread data exfiltration and extortion attempts. The...more

Baker Donelson

Cybersecurity Awareness Month 2025: Seven Foundational Pillars of Good Personal Cyber Hygiene

Baker Donelson on

Deepfakes, social engineering, and urgent texts or calls from your IT department all continue to be effective methods hackers use to gain access to your most important accounts and assets. October is Cybersecurity Awareness...more

Robinson+Cole Data Privacy + Security Insider

Privacy Tip #463 – How a Weak Password Can Take a Whole Company Down

Passwords are the key to your digital kingdom. Passwords, also known as “credentials,” provide the user with access to all information and data that the user has been authorized to access, whether in a personal or...more

Shumaker, Loop & Kendrick, LLP

Cybersecurity Tips for Businesses

Why It Matters Reputation at Risk: - Customers lose trust quickly after a breach. - Legal & Financial Consequences: Fines, lawsuits, and regulatory penalties add up fast. - Operational Disruption: Downtime and...more

Gray Reed

Impacts of Cyber Threat Landscape on Insurers and Policyholders

Gray Reed on

As cyber threats continue to evolve and increase, insurers are responding by imposing stricter requirements on policyholders to obtain and maintain coverage. This shifts how businesses should implement, manage, and oversee IT...more

Clark Hill PLC

October is Cybersecurity Awareness Month - It’s a good time to update your training program

Clark Hill PLC on

This month is the 22nd annual Cybersecurity Awareness Month, cosponsored by the Cybersecurity and Infrastructure Agency (CISA) and the National Cybersecurity Alliance. CISA’s theme this year is “Building a Cyber Strong...more

Harris Beach Murtha PLLC

Final Phase for NY Cybersecurity Regulation: Is Your Financial Institution in Compliance?

Eight years in the making, the final phase of New York’s groundbreaking Cybersecurity Regulation Part 500 amendments take effect Nov. 1 and businesses involved in the financial services sector must be prepared to comply with...more

Hinshaw & Culbertson - Privacy, Cyber & AI...

Key Takeaways from FinCyber Femmes Meeting on Navigating AI and Cybersecurity Laws

Hinshaw partner Cathy Mulrow-Peattie recently participated in a panel discussion during the Q3 2025 FinCyber Femmes Meeting, hosted at IBM’s office in New York City. The FinCyber Femmes bring together leading professionals in...more

Bressler, Amery & Ross, P.C.

Final Phase of the NY DFS Cyber Security Regulations to be Implemented

On March 1, 2017, New York’s Department of Financial Services (DFS) enacted a regulation establishing what was then one of the most stringent cybersecurity measures in the country. The goal was to enhance cybersecurity...more

EDRM - Electronic Discovery Reference Model

Inside the Salesloft Drift Breach: Critical Lessons for SaaS Security and Governance

ComplexDiscovery Editor’s Note: The Salesloft Drift breach, which affected over 700 organizations between August 8–18, 2025, marks a defining moment in the evolution of SaaS-related supply chain attacks. With attackers...more

Pillsbury Winthrop Shaw Pittman LLP

NYDFS Imposes $2M Penalty for Violations of its Cybersecurity Regulation

The New York State Department of Financial Services (NYDFS) announced on August 14, 2025, resolution of civil enforcement action requiring Healthplex, Inc., a licensed insurance agent and independent adjuster, to pay a $2...more

Paul Hastings LLP

You’ve Got Mail: NYDFS Enforcement Action Highlights Cybersecurity Risk of Over-Retention and Other Risks

Paul Hastings LLP on

On Aug. 14, 2025, the New York Department of Financial Services (NYDFS) issued a Consent Decree announcing that Healthplex, Inc. (Healthplex) has agreed to pay a $2 million fine, as a result of an investigation into a 2021...more

Shook, Hardy & Bacon L.L.P.

Ransomware Attacks Target SonicWall Firewall Vulnerability

Ransomware group Akira is believed to be behind a large number of attacks that appear to be tied to SonicWall firewalls with SSLVPN enabled. Over the past week, a large number of attacks by the ransomware group Akira have...more

Parker Poe Adams & Bernstein LLP

Can Employees Refuse to Use Personal Smartphones for Work Tasks?

Recently, we had interesting questions from a client that was implementing two-factor authentication for employees to access the company’s information systems. The process requires employees to install the authentication app...more

Morrison & Foerster LLP

Key Takeaways from the White House Crypto Report

On July 30, 2025, the White House released a 166-page report titled “Strengthening American Leadership in Digital Financial Technology” (the “Report”).[1] Authored by a working group of cabinet members and federal agency...more

Mayer Brown

Reducing Legal Risks From Ransomware Attacks: Lessons from Scattered Spider

Mayer Brown on

Leading businesses continue to suffer cyber attacks at the hands of sophisticated ransomware groups. For example, the threat group “Scattered Spider” (also known as UNC3944, Octo Tempest, 0ktapus) is once again making...more

Robinson+Cole Data Privacy + Security Insider

FBI Warns Airline and Transportation Sectors About Scattered Spider

On June 27, 2025, the Federal Bureau of Investigation (FBI) issued a warning on X to the airline and transportation sectors that the notorious cyber criminal ring Scattered Spider is attacking those sectors....more

163 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide