Latest Posts › Cybersecurity

Share:

SEC Issues New Statement on Cybersecurity Incident Disclosure

Last week, Erik Gerding, Director of the SEC’s Division of Corporation Finance (the Division), issued a statement providing clarification regarding the disclosure of cybersecurity incidents by reporting companies. This...more

Further Updates to the CPPA Proposed Regulations: Risk Assessments and Automated Decisionmaking Technology

After years of internal discussion, the Board of the California Privacy Protection Agency (CPPA), at their March 8th meeting, voted to progress toward formalizing the proposed regulations on risk assessments and automated...more

Major Win for California Privacy Protection Agency: Enforcement of Regulations Can Begin Immediately

If you have been relying on last year’s court order staying the ability of the California Privacy Protection Agency (CPPA) to enforce regulations promulgated under the California Privacy Rights Act (CPRA) to also stay your...more

Draft Cybersecurity Audit and Risk Assessment Regulations Issued by CPPA

The California Privacy Protection Agency (CPPA) has released its agenda for the September 8 board meeting, which includes (among other topics) presentation of a draft Cybersecurity Audit Regulation and a draft Risk Assessment...more

SEC Adopts Final Cybersecurity Rules for Public Companies

In a narrow 3-2 decision on July 26, the SEC adopted its final rule concerning cybersecurity risk management, strategy, governance, and incident disclosure (the “Final Rule”).  Below we highlight some of the principal changes...more

Texas Has Been Busy Ramping up Privacy Protections with New Comprehensive Data Privacy Law and Stricter Data Breach Notification...

Texas has joined the growing list of states enacting comprehensive consumer data privacy laws. On June 18, 2023, Governor Abbott (R) signed H.B.4, otherwise known as the Texas Data Privacy and Security Act (“TDPSA”). The...more

Judge Delays CPRA Regulation Enforcement

Judge James Arguelles has sided with California businesses in holding that the California Privacy Protection Agency (CPPA) cannot start enforcement of regulations promulgated under the California Privacy Rights Act (CPRA) for...more

May Madness: Montana’s New Consumer Data Privacy Law Follows the Leaders ... and we’re not talking about California!

Our May Madness series is getting you caught up on comprehensive privacy legislation passing state legislatures across the nation.  In April, governors signed legislation in Tennessee and Indiana, and this month ahead of...more

Mintz May Madness: Comprehensive Data Privacy Laws Sweeping the Nation

Indiana's New Law is on the Books - Last month, three more state legislatures passed comprehensive data privacy laws. Just this week, Indiana’s governor signed one of them - the Indiana Consumer Data Privacy Act (“ICDPA’) -...more

SEC Notice to Public Companies: Less-than-forthcoming Breach Disclosures Can Cost You

Just ahead of the expected April release of the final SEC cybersecurity regulations, the SEC has fined Blackbaud, a donor data management platform used widely by nonprofits, $3 million dollars for "misleading disclosures" in...more

Healthcare Hacks: Weak links

The FBI and the Cybersecurity & Infrastructure Security Agency have been warning the healthcare sector for years about vulnerabilities and ransomware gangs targeting those vulnerabilities. With millions of records -- and...more

Preparation for 2022 Fiscal Year-End SEC Filings and 2023 Annual Shareholder Meetings

Public companies initiating the year-end reporting process will need to consider, and in many cases take steps to address, a number of significant developments and issues. To assist companies in this process, Mintz has...more

“Ding Dong” -- FTC-Drizly Data Breach Settlement Will follow CEO Personally for a Decade

The Federal Trade Commission (“FTC”) announced on Monday that it is settling a case against Drizly and its CEO stemming from a 2020 data breach that impacted roughly 2.5 million consumers. The proposed order not only...more

Health Care Organizations Warned of Aggressive Ransomware Threat

Ransomware is the “business pandemic.” Warnings have been issued by multiple agencies around the world to alert businesses to increase their protection and awareness. Most recently, the Department of Health and Human...more

President Says Russia “Exploring” Cyberattacks Against U.S.

On Monday, President Biden warned U.S. companies to be on guard against Russian cyberattacks, citing intelligence as a call to action. “I have previously warned about the potential that Russia could conduct malicious...more

SEC Proposes New Cybersecurity Rules for Public Companies

Following closely on its proposal for substantial new cybersecurity requirements for investment advisers and registered investment companies, the Securities and Exchange Commission (SEC) unveiled a new slate of proposed...more

SEC Chair Gensler Wants Public Companies to Upgrade “Cyber Hygiene”

Data Privacy Week kicked off with a major message for US publicly-traded companies: the Securities and Exchange Commission will be looking at cybersecurity. SEC Chairman Gary Gensler said in a speech to a virtual securities...more

Preparation for 2021 Fiscal Year-End SEC Filings and 2022 Annual Shareholder Meetings

As public companies embark on the year-end reporting process, they will need to consider, and in some cases take steps to address, a number of significant developments and issues. As in past years, Mintz has prepared a...more

FTC Warns Companies to Remediate Log4j Security Vulnerability

Before the holidays, we warned of a critical vulnerability in a widely-used Java logging utility that could affect tens of thousands of companies. Since that original alert, multiple US and foreign government cybersecurity...more

CRITICAL ALERT: Log4Shell

We want to make our readers and your security operations aware of a critical vulnerability that is actively being exploited in the wild. CVE-2021-44228 can easily be exploited to gain complete access to the targeted...more

12/14/2021  /  Cybersecurity , Exploitation , Networks

Time to Update Your Incident Response Plans

It’s been a busy 2021 legislative session for changes to data breach laws, and that means it is time to review and update your incident response plans. Several states have shortened data breach notification timelines or...more

What We’re Reading – September 2021 - 2

Welcome to Fall 2021! We’re trying to curate some of the week’s privacy and cybersecurity news to keep you up-to-date: CONTI RANSOMWARE ON THE RISE — Another week, another US agency joint advisory on ransomware. The...more

FBI Warning: Ransomware Attackers Don’t Take Holidays

There is a pattern here. Long holiday weekends make for ransomware attacks and data breaches. It is well-known that malicious actors take advantage of understaffed IT resources on holidays. In fact, it’s become such a common...more

What We’re Reading - August 2021 - 2

There is a glut of information out there regarding privacy and cybersecurity these days. Our new feature “What We’re Reading” provides a curated list of articles, blogs, newsletters, and books that you may find interesting...more

229 Results
 / 
View per page
Page: of 10

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide