News & Analysis as of

Third-Party Service Provider Incident Response Plans

A&O Shearman

Managing cyber risk under escalating threat and enforcement pressure

A&O Shearman on

Cyber law and practice have continued to evolve over the past 12 months. New laws and regulations have been unveiled or come into force, while enforcement authorities have sharpened their focus on issues including board...more

Freeman Mathis & Gary

A first look at NIST’s new cyber AI framework

Freeman Mathis & Gary on

The National Institute of Standards and Technology (NIST) recently released their initial preliminary draft of NIST IR 8596, also known as the Cybersecurity Framework Profile for Artificial Intelligence. This new...more

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Mitratech Holdings, Inc

Third-Party Data Breaches: What You Need to Know

A third-party data breach occurs when malicious actors compromise a vendor, supplier, contractor, or other organization to gain access to sensitive information or systems of the victim’s customers, clients, or business...more

Ropes & Gray LLP

On the Seventh Day of Data… The Growing Pains of Regulation S-P in 2025

Ropes & Gray LLP on

Financial regulators including the Securities and Exchange Commission (“SEC”) continued to focus on data protection and cybersecurity issues throughout 2025....more

Constangy, Brooks, Smith & Prophete, LLP

Warm up your defenses against cyber holiday risks

Each year, there is a holiday surge in cyberattacks employing a wide range of attack vectors. This heightened activity can make organizations more vulnerable to legal and regulatory scrutiny. This is a good time to check your...more

Foley & Lardner LLP

Amended Regulation S-P: Here to Stay and Being Examined in 2026

Foley & Lardner LLP on

Last month, the U.S. Securities and Exchange Commission (SEC) Division of Examinations released its Fiscal Year 2026 “Examination Priorities.” In this year’s release, the SEC announced that it will begin examining covered...more

Mayer Brown

China's Cybersecurity Incident Reporting Measures Come into Effect

Mayer Brown on

The Cyberspace Administration of China (the "CAC") released the Measures on the Management of Cybersecurity Incident Reporting (the "Incident Reporting Measures") which came into force on 1 November 2025. The Measures provide...more

Wiley Rein LLP

’Tis the Season to Evaluate Cyber Readiness and Resilience

Wiley Rein LLP on

The holiday season is a time of celebration, but it’s also a prime opportunity for cyber threat actors. With many employees on leave and organizations operating with reduced staffing, malicious activity can go unnoticed....more

Morrison & Foerster LLP

Data, Cyber + Privacy Predictions for 2026

Morrison & Foerster LLP on

The Morrison Foerster Data, Cyber + Privacy team provides creative, practical advice across every stage of the information lifecycle, from navigating complex privacy laws and managing breach response to litigating data...more

Mayer Brown

We Have Been Hacked: Now What? Lessons for the Boardroom

Mayer Brown on

The almost daily prevalence of cyber-attacks has brought the issue of cybersecurity as a core governance responsibility to the front of mind of company boards. In 2024 alone, over 15 million cyberattacks were recorded...more

Jones Day

NY Department of Financial Services Signals Increased Scrutiny of Third-Party Technology Risk Management

Jones Day on

On October 21, 2025, the New York Department of Financial Services ("NYDFS") sent a letter to the executives and information security personnel at covered entities with new guidance for managing technology and data risks...more

Orrick, Herrington & Sutcliffe LLP

SEC announces examination priorities for fiscal year 2026

On November 17, the SEC’s Division of Examinations published its 2026 examination priorities, outlining key areas of regulatory focus for the upcoming year. ...more

Ropes & Gray LLP

Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Recently, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some action items...more

Paul Hastings LLP

Deadline to Comply With Regulation S-P Amendments Is Here for Larger Entities

Paul Hastings LLP on

The deadline for “Larger Entities” to comply with the new data privacy and security requirements in the amendments to Regulation S-P is December 3, 2025. As we have detailed previously, the U.S. Securities and Exchange...more

Tonkon Torp LLP

Compliance with Regulation S-P Amendments Required by December 3, 2025

Tonkon Torp LLP on

In May 2024, the Securities and Exchange Commission (SEC) adopted significant amendments to Regulation S-P (the “Amendments”). These Amendments expand requirements related to safeguarding customer information, incident...more

Constangy, Brooks, Smith & Prophete, LLP

Minor Breaches, Major Trouble: Why minor cyber incidents can lead to major legal fallout

When cyberattacks strike global giants, it’s front-page news. But what about the smaller breaches -- the ones that don’t make headlines? Increasingly, they’re making waves in courtrooms and regulatory enforcement agencies. ...more

StoneTurn

AI and LLMs in Corporate Cybersecurity: Choosing the Right Solution for Your Organization

StoneTurn on

This article examines how cybersecurity teams can leverage AI and LLM technologies like Microsoft Copilot and Open WebUI while managing associated security risks through proper logging and monitoring practices. It provides...more

Constangy, Brooks, Smith & Prophete, LLP

Cybersecurity resolutions for 2026

As 2025 comes to an end, there have been some valuable cybersecurity lessons for businesses. These involve vendor oversight, internal coordination, and incident response plans. Businesses should vow to address them in 2026 if...more

Constangy, Brooks, Smith & Prophete, LLP

Asahi cyberattack highlights risks to “operational technology”

Another type of cyber attack. Operations for Japan-based beverage giant Asahi Group Holdings recently shut down after a cyberattack, causing a ripple effect that extended far beyond its breweries. The incident forced...more

Shumaker, Loop & Kendrick, LLP

"Post Mortem Review of AT&T Breaches"

Data breaches occur when an unauthorized individual or entity gains access to confidential or protected information. This information may include personal data such as Social Security numbers or medical records, financial...more

Shumaker, Loop & Kendrick, LLP

Client Alert: Regulation S-P Deadline: RIAs Must Finalize Incident Response Programs

The U.S. Securities and Exchange Commission's (SEC's) May 2024 amendments to Regulation S-P established concrete, near-term compliance deadlines for registered investment advisers (RIAs) to adopt, implement, and maintain...more

McDermott Will & Schulte

NYDFS clarifies expectations for third-party cybersecurity risk management

On October 21, 2025, the New York State Department of Financial Services (NYDFS) issued an industry letter highlighting risks associated with third-party service providers – such as providers of cloud computing, file transfer...more

Foley & Lardner LLP

Securing Digital Supply Chains: Confronting Cyber Threats in Logistics Networks

Foley & Lardner LLP on

On the Rise: Cyberattacks through the supply chain have increased by over 400% in recent years. Leaders need to take action. Enhance Third-Party Cybersecurity: Regularly audit suppliers’ cybersecurity practices and limit...more

Paul Hastings LLP

NYDFS Puts Third-Party Service Providers Under Regulatory Spotlight

Paul Hastings LLP on

The New York Department of Financial Services (NYDFS) issued an industry letter titled “Guidance on Managing Risks Related to Third-Party Service Providers” (Guidance) for Covered Entities engaging third-party service...more

75 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide