News & Analysis as of

Third-Party Service Provider Cybersecurity

Robinson+Cole Data Privacy + Security Insider

SolarWinds Web Help Desk Vulnerability Targeted by Threat Actors

Security researchers at Huntress Labs have identified a vulnerability in SolarWinds’s Web Help Desk that threat actors are exploiting to allow them to execute code remotely....more

Foley Hoag LLP - Security, Privacy and the...

HIPAA Enforcement: A Look Ahead at 2026 Informed by 2025's Inflection Points

The healthcare ecosystem has closed the book on a volatile 2025, and HIPAA enforcement has moved into 2026 with sharper edges, wider apertures, and higher stakes. Regulators spent 2025 refining the tools they use, broadening...more

Mayer Brown

FCC Urges Communications Providers to Strengthen Ransomware Defenses

Mayer Brown on

On January 29, 2026, the Federal Communications Commission’s (“FCC” or the “Commission”) Public Safety and Homeland Security Bureau issued a Public Notice (DA 26-96) to highlight best practices that communications providers...more

Bond Schoeneck & King PLLC

Countdown to Data Privacy Day 2026 - Protect Your Business – Cybersecurity Provisions in Contracts

Cybersecurity and data privacy provisions should be a central consideration whenever parties negotiate contracts involving third‑party service providers who will access or process business data. This applies across a broad...more

Blake, Cassels & Graydon LLP

What Can Service Providers to the Public Sector Learn From the PowerSchool Privacy Incident?

On November 17, 2025, Ontario’s Information and Privacy Commissioner (ON IPC) and Alberta’s Office of the Information and Privacy Commissioner (AB OIPC) each released their findings from their investigations into a...more

A&O Shearman

Managing cyber risk under escalating threat and enforcement pressure

A&O Shearman on

Cyber law and practice have continued to evolve over the past 12 months. New laws and regulations have been unveiled or come into force, while enforcement authorities have sharpened their focus on issues including board...more

The Volkov Law Group

Reviewing the 5 Major AI Risks (Part II of II)

The Volkov Law Group on

Here are the five primary risk areas when a company uses AI in a supportive or assistance-based role as opposed to an algorithmic-based use case....more

The Volkov Law Group

Soothing the AI-Risk Hysteria: A Focused Approach to AI Risks (Part I of II)

The Volkov Law Group on

From my perspective, hopefully a reasonable one, there is a little too much AI-Risk Hype. Not to belittle the experts or ignore potential risk concerns but this is getting a little carried away....more

Freeman Mathis & Gary

A first look at NIST’s new cyber AI framework

Freeman Mathis & Gary on

The National Institute of Standards and Technology (NIST) recently released their initial preliminary draft of NIST IR 8596, also known as the Cybersecurity Framework Profile for Artificial Intelligence. This new...more

Wiley Rein LLP

FedRAMP Issues Final Proposed Changes to Cloud Authorization Process, Seeks Comments from Industry

Wiley Rein LLP on

WHAT: The FedRAMP Program Management Office (PMO) has released a “final set” of proposed changes to the FedRAMP process for authorizing and assessing the security of cloud services for federal consumption. The final proposed...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

A&O Shearman

ESAs And UK Regulators Sign MoU On Oversight Of Critical ICT Third-Party Service Providers Under DORA

A&O Shearman on

The European Supervisory Authorities (comprising the European Securities and Markets Authority, the European Insurance and Occupational Pensions Authority and the European Banking Authority) have entered into a Memorandum of...more

Parker Poe Adams & Bernstein LLP

New Industry Letter Provides Guidance for Companies Using Third-Party Service Providers

As organizations increasingly rely on third-party service providers (TPSPs) for critical services, including cloud computing, IT management, and fintech solutions, the scale and complexity of cyber risks have grown. A recent...more

Ropes & Gray LLP

NYDFS Regulated Entities Face Stronger Cybersecurity Regulations

Ropes & Gray LLP on

The New York Department of Financial Services (“NYDFS”) implemented the final phases of amendments to its NYDFS Cybersecurity Regulation (23 NYCRR Part 500) in May and November....more

Orrick, Herrington & Sutcliffe LLP

NCUA publishes list of federal resources for credit unions using AI

Recently, the NCUA published a list of resources aimed toward guiding credit unions implementing AI or partnering with AI third-party vendors. The publication noted that while AI presented significant opportunities for...more

Jackson Lewis P.C.

The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party...

Jackson Lewis P.C. on

As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and...more

Wiley Rein LLP

Updates to NIST Cybersecurity Guidance Show Continued Focus on Cloud Services

Wiley Rein LLP on

Recent draft cybersecurity guidance from the National Institute of Standards and Technology (NIST) provides an opportunity for government contractors who provide IT services to federal agencies to weigh in on implementation...more

Cooley LLP

The Most Common AI “Risk Factor” Categories

Cooley LLP on

With the news that over 70% of S&P 500 companies provide some sort of AI-related risk factors in their SEC disclosures, it’s a good time to review the type of risk factors that you might want to consider – of course,...more

Troutman Pepper Locke

NCUA Issues Updated AI Resource Hub

Troutman Pepper Locke on

On December 22, the National Credit Union Administration (NCUA) updated its Artificial Intelligence (AI) resource page to consolidate key technical and policy references for federally insured credit unions. The page sits...more

Pierce Atwood LLP

First Circuit Rejects Post-Data Breach Indemnification Claims Against Technology Vendor

Pierce Atwood LLP on

The First Circuit recently affirmed a District of Massachusetts decision granting summary judgment in litigation arising from a 2018 data breach involving protected health information (PHI). In Axis Insurance Co. v. Barracuda...more

Mitratech Holdings, Inc

Third-Party Data Breaches: What You Need to Know

A third-party data breach occurs when malicious actors compromise a vendor, supplier, contractor, or other organization to gain access to sensitive information or systems of the victim’s customers, clients, or business...more

Ropes & Gray LLP

On the Tenth Day of Data… Looking Back at 2025 and Ahead to NYDFS Enforcement Priorities in 2026

Ropes & Gray LLP on

While 2025 may have brought questions about the level of enforcement we would see from federal regulators, there was no question that state regulators would continue to be active, especially in the financial privacy space....more

Ropes & Gray LLP

On the Seventh Day of Data… The Growing Pains of Regulation S-P in 2025

Ropes & Gray LLP on

Financial regulators including the Securities and Exchange Commission (“SEC”) continued to focus on data protection and cybersecurity issues throughout 2025....more

Constangy, Brooks, Smith & Prophete, LLP

Warm up your defenses against cyber holiday risks

Each year, there is a holiday surge in cyberattacks employing a wide range of attack vectors. This heightened activity can make organizations more vulnerable to legal and regulatory scrutiny. This is a good time to check your...more

Robinson+Cole Data Privacy + Security Insider

Auto Credit Check Company Breach Affects 5.6 Million

700Credit, a Michigan-based company that runs credit checks and identification verification services for automobile dealerships nationwide, has announced that an “integrated partner” was compromised, allowing a bad actor to...more

364 Results
 / 
View per page
Page: of 15

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide