News & Analysis as of

Third-Party Service Provider Data Breach

Bond Schoeneck & King PLLC

Countdown to Data Privacy Day 2026 - Protect Your Business – Cybersecurity Provisions in Contracts

Cybersecurity and data privacy provisions should be a central consideration whenever parties negotiate contracts involving third‑party service providers who will access or process business data. This applies across a broad...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Jackson Lewis P.C.

The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party...

Jackson Lewis P.C. on

As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and...more

Pierce Atwood LLP

First Circuit Rejects Post-Data Breach Indemnification Claims Against Technology Vendor

Pierce Atwood LLP on

The First Circuit recently affirmed a District of Massachusetts decision granting summary judgment in litigation arising from a 2018 data breach involving protected health information (PHI). In Axis Insurance Co. v. Barracuda...more

Mitratech Holdings, Inc

Third-Party Data Breaches: What You Need to Know

A third-party data breach occurs when malicious actors compromise a vendor, supplier, contractor, or other organization to gain access to sensitive information or systems of the victim’s customers, clients, or business...more

Ropes & Gray LLP

On the Seventh Day of Data… The Growing Pains of Regulation S-P in 2025

Ropes & Gray LLP on

Financial regulators including the Securities and Exchange Commission (“SEC”) continued to focus on data protection and cybersecurity issues throughout 2025....more

Robinson+Cole Data Privacy + Security Insider

Auto Credit Check Company Breach Affects 5.6 Million

700Credit, a Michigan-based company that runs credit checks and identification verification services for automobile dealerships nationwide, has announced that an “integrated partner” was compromised, allowing a bad actor to...more

Foley & Lardner LLP

Amended Regulation S-P: Here to Stay and Being Examined in 2026

Foley & Lardner LLP on

Last month, the U.S. Securities and Exchange Commission (SEC) Division of Examinations released its Fiscal Year 2026 “Examination Priorities.” In this year’s release, the SEC announced that it will begin examining covered...more

Mayer Brown

China's Cybersecurity Incident Reporting Measures Come into Effect

Mayer Brown on

The Cyberspace Administration of China (the "CAC") released the Measures on the Management of Cybersecurity Incident Reporting (the "Incident Reporting Measures") which came into force on 1 November 2025. The Measures provide...more

Cadwalader, Wickersham & Taft LLP

When Privacy Rules Meet Fund Finance, December 2025 - The New Regulation S-P Amendments and What They Mean for Lenders in Fund...

The SEC's 2024 amendments to Regulation S-P introduce the most comprehensive update to federal privacy and data security standards for SEC-regulated institutions since the rule was adopted. While the amendments are directed...more

Sheppard Mullin Richter & Hampton LLP

The Ghost of Employees Past: The Data Breach Risks from User-Credential Management

A recent settlement with an education service provider and three states – California, Connecticut, and New York – serves as a reminder to deactivate the credentials of departed employees. The case arose following a data...more

Ropes & Gray LLP

Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Recently, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some action items...more

Paul Hastings LLP

Deadline to Comply With Regulation S-P Amendments Is Here for Larger Entities

Paul Hastings LLP on

The deadline for “Larger Entities” to comply with the new data privacy and security requirements in the amendments to Regulation S-P is December 3, 2025. As we have detailed previously, the U.S. Securities and Exchange...more

Tonkon Torp LLP

Compliance with Regulation S-P Amendments Required by December 3, 2025

Tonkon Torp LLP on

In May 2024, the Securities and Exchange Commission (SEC) adopted significant amendments to Regulation S-P (the “Amendments”). These Amendments expand requirements related to safeguarding customer information, incident...more

Constangy, Brooks, Smith & Prophete, LLP

Minor Breaches, Major Trouble: Why minor cyber incidents can lead to major legal fallout

When cyberattacks strike global giants, it’s front-page news. But what about the smaller breaches -- the ones that don’t make headlines? Increasingly, they’re making waves in courtrooms and regulatory enforcement agencies. ...more

Epstein Becker & Green

NYDFS Cybersecurity Crackdown: New Requirements Now in Force, and "Covered Entities" Include HMOs, CCRCs—Are You Compliant?

Epstein Becker & Green on

As cybersecurity breaches grow more complex and frequent, regulators are increasingly focused on organizational compliance....more

Ropes & Gray LLP

Initial Guidance on Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Over the last weekend, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some...more

Constangy, Brooks, Smith & Prophete, LLP

Cybersecurity resolutions for 2026

As 2025 comes to an end, there have been some valuable cybersecurity lessons for businesses. These involve vendor oversight, internal coordination, and incident response plans. Businesses should vow to address them in 2026 if...more

Constangy, Brooks, Smith & Prophete, LLP

Asahi cyberattack highlights risks to “operational technology”

Another type of cyber attack. Operations for Japan-based beverage giant Asahi Group Holdings recently shut down after a cyberattack, causing a ripple effect that extended far beyond its breweries. The incident forced...more

Shumaker, Loop & Kendrick, LLP

"Post Mortem Review of AT&T Breaches"

Data breaches occur when an unauthorized individual or entity gains access to confidential or protected information. This information may include personal data such as Social Security numbers or medical records, financial...more

Shumaker, Loop & Kendrick, LLP

Client Alert: Regulation S-P Deadline: RIAs Must Finalize Incident Response Programs

The U.S. Securities and Exchange Commission's (SEC's) May 2024 amendments to Regulation S-P established concrete, near-term compliance deadlines for registered investment advisers (RIAs) to adopt, implement, and maintain...more

Stark & Stark

SEC Regulation S-P Amendments: New Incident Response Program Requirements

Stark & Stark on

In May 2024, the U.S. Securities and Exchange Commission (SEC) adopted amendments to Regulation S-P, requiring registered investment advisers (RIAs) to adopt written incident response program policies and procedures. ...more

Cooley LLP

Regulation S-P Amendments: What ‘Large’ Registered Fund Managers Need to Do by December 3, 2025

Cooley LLP on

The Securities and Exchange Commission (SEC) adopted amendments to Regulation S-P in May 2024, significantly expanding privacy, data security and breach notification obligations for “covered institutions,” which includes...more

Smith Anderson

Is Your Cyber Insurance Ready for AI and Data Privacy Risks?

Smith Anderson on

As artificial intelligence (AI) and data-driven decision-making become central to business operations, companies face a rapidly evolving landscape of cybersecurity and data privacy risk. Yet, many existing cyber insurance...more

Polsinelli

$19M in Settlements Underscore Cybersecurity Risks for TPAs and Insurers

Polsinelli on

Key Takeaways - Two recent data breach class action settlements involving third party administrators and their insurer co-defendants have resulted in nearly $20 million in combined payments....more

160 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide