News & Analysis as of

Third-Party Service Provider Today's Popular Updates

Skadden, Arps, Slate, Meagher & Flom LLP

Ransomware: What You Need to Know as Attacks, Regulation and Enforcement Increase

Ransomware attacks continue to evolve in sophistication, disrupting operations and commanding the urgent attention of regulators, law enforcement and government agencies....more

Jackson Lewis P.C.

The Hidden Legal Minefield: Compliance Concerns with AI Smart Glasses, Part 4: Data Security, Breach Notification, and Third-Party...

Jackson Lewis P.C. on

As we have discussed in prior posts, AI-enabled smart glasses are rapidly evolving from niche wearables into powerful tools with broad workplace appeal — but their innovative capabilities bring equally significant legal and...more

Troutman Pepper Locke

Legal AI in Practice: Firm Governance, Build vs. Buy Decisions, and Vendor Due Diligence — The Good Bot Podcast

Troutman Pepper Locke on

In this episode of The Good Bot, Brett Mason sits down with Leigh Zeiser, director of AI and automation at Troutman Pepper Locke, to unpack how the firm operationalizes AI responsibly. They discuss the firm's AI portfolio —...more

Mitratech Holdings, Inc

Third-Party Data Breaches: What You Need to Know

A third-party data breach occurs when malicious actors compromise a vendor, supplier, contractor, or other organization to gain access to sensitive information or systems of the victim’s customers, clients, or business...more

Troutman Pepper Locke

Key Takeaways from FINRA’s 2026 Annual Regulatory Oversight Report

Troutman Pepper Locke on

The Financial Industry Regulatory Authority’s (FINRA) 2026 Annual Regulatory Oversight Report is the most current and comprehensive statement of FINRA’s priorities and expectations for member firms. It does not create new...more

Morrison & Foerster LLP

Data, Cyber + Privacy Predictions for 2026

Morrison & Foerster LLP on

The Morrison Foerster Data, Cyber + Privacy team provides creative, practical advice across every stage of the information lifecycle, from navigating complex privacy laws and managing breach response to litigating data...more

McGuireWoods LLP

FINRA’s 2026 Annual Regulatory Oversight Report: Same Priorities, New Focus on AI and Cybersecurity

McGuireWoods LLP on

SERC’ling Up is your resource for staying ahead in today’s fast-evolving financial landscape. This newsletter delivers perspectives on the latest enforcement trends, regulatory updates and high-stakes developments affecting...more

Mitratech Holdings, Inc

Third‑Party AI: The Blind Spot in Governance

Ask any board if AI is on the agenda, and the answer is yes. Ask how confident they feel about their vendors’ use of AI, and the answer is less clear....more

Sheppard Mullin Richter & Hampton LLP

The Ghost of Employees Past: The Data Breach Risks from User-Credential Management

A recent settlement with an education service provider and three states – California, Connecticut, and New York – serves as a reminder to deactivate the credentials of departed employees. The case arose following a data...more

Ropes & Gray LLP

Responding to the SitusAMC Data Breach

Ropes & Gray LLP on

Recently, major media reported that a key financial services provider, SitusAMC, suffered a substantial data security incident. This Alert summarizes what we know so far, the possible legal implications, and some action items...more

Constangy, Brooks, Smith & Prophete, LLP

Asahi cyberattack highlights risks to “operational technology”

Another type of cyber attack. Operations for Japan-based beverage giant Asahi Group Holdings recently shut down after a cyberattack, causing a ripple effect that extended far beyond its breweries. The incident forced...more

Shumaker, Loop & Kendrick, LLP

"Post Mortem Review of AT&T Breaches"

Data breaches occur when an unauthorized individual or entity gains access to confidential or protected information. This information may include personal data such as Social Security numbers or medical records, financial...more

Fenwick & West LLP

Cracks in the Data Door: Celonis v. SAP and the Antitrust Risk of Restricting Data Access

Fenwick & West LLP on

In Celonis SE v. SAP SE, a federal court ruled that Celonis could proceed with its claim alleging SAP monopolized a standalone “data access” aftermarket, potentially paving the way for monopolization theories focused on acts...more

McDermott Will & Schulte

NYDFS clarifies expectations for third-party cybersecurity risk management

On October 21, 2025, the New York State Department of Financial Services (NYDFS) issued an industry letter highlighting risks associated with third-party service providers – such as providers of cloud computing, file transfer...more

Foley & Lardner LLP

Securing Digital Supply Chains: Confronting Cyber Threats in Logistics Networks

Foley & Lardner LLP on

On the Rise: Cyberattacks through the supply chain have increased by over 400% in recent years. Leaders need to take action. Enhance Third-Party Cybersecurity: Regularly audit suppliers’ cybersecurity practices and limit...more

Fisher Phillips

NY Dept of Financial Services Issues Guidance to Covered Entities on Overseeing Third-Party Service Providers: 4 Areas of Focus

Fisher Phillips on

The New York Department of Financial Services (NYDFS) just sent a stark reminder to covered entities (which includes financial institutions, insurance companies, and any other businesses regulated by the NYDFS) that they are...more

Cooley LLP

Regulation S-P Amendments: What ‘Large’ Registered Fund Managers Need to Do by December 3, 2025

Cooley LLP on

The Securities and Exchange Commission (SEC) adopted amendments to Regulation S-P in May 2024, significantly expanding privacy, data security and breach notification obligations for “covered institutions,” which includes...more

Baker Botts L.L.P.

Shai-Hulud Worm: Key Considerations for Businesses Following npm Supply Chain Attack

Baker Botts L.L.P. on

A new cyber threat, the "Shai-Hulud" worm, has compromised the Node Package Manager (npm) ecosystem, which is widely used by organizations for JavaScript development. This attack has resulted in widespread theft of...more

HaystackID

Inside the Salesloft Drift Breach: Critical Lessons for SaaS Security and Governance

HaystackID on

The Salesloft Drift breach that unfolded between August 8 and 18, 2025, represents one of the most significant supply chain attacks targeting Software-as-a-Service (SaaS) platforms in recent years. This sophisticated...more

McDermott Will & Schulte

Salesloft Drift supply chain attack leads to widespread data theft

Threat actors stole authentication tokens for Salesloft Drift, a popular marketing automation tool, leading to widespread data exfiltration from Salesforce customer instances that occurred mostly between August 8 and 18,...more

Lowenstein Sandler LLP

Salesforce Users: Organizations Using the Salesloft Drift AI Chat Agent with Salesforce Must Check Their Presence for Compromise

Lowenstein Sandler LLP on

Salesloft issued a security notification on August 26 regarding its Drift application. It appears to be a broad opportunistic attack on Salesloft/Drift instances integrated with Salesforce tenants. Salesloft issued updates...more

McDermott Will & Schulte

Data breach litigation targets wine company: Lessons for alcohol industry players

On July 30, 2025, a wine producer was sued in connection with a cyberattack that allegedly compromised the data of at least 26,000 customers. Among other things, the complaint alleges that the company failed to implement...more

IR Global

Client Beware: The Utilization of Artificial Intelligence Platforms and the Potential Waiver of Attorney-Client Privilege

IR Global on

The rapid evolution of digital technologies has ushered in a new era for the legal profession—one characterized by both unprecedented promise and intricate new hazards. As practitioners and clients alike become more reliant...more

Secretariat

Five Key Recommendations to Strengthen Cybersecurity in Latin America and the Caribbean

Secretariat on

Cybersecurity is now a core element of legal, regulatory, and business risk management. In Latin America and the Caribbean, organizations face mounting pressure to demonstrate proactive compliance with evolving data...more

King & Spalding

Fed Follows Earlier OCC, FDIC, and NCUA Orders Allowing Banks to Collect TIN Information from Third Parties

King & Spalding on

On July 31, 2025, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued an exemptive order in coordination with the Board of Governors of the Federal Reserve System (the “Fed”) that allows...more

176 Results
 / 
View per page
Page: of 8

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide