Latest Posts › Cybersecurity

Share:

Iowa Becomes Sixth State to Enact a Comprehensive Data Privacy Law

On March 28, 2023, Iowa—following California, Colorado, Connecticut, Utah, and Virginia—became the sixth state to adopt a comprehensive consumer data privacy law. On March 28, 2023, Iowa Governor Kim Reynolds signed "An...more

SEC Advances Three Cybersecurity Rule Proposals to Public Comment

If adopted, these proposed rules would (i) enhance protection of customer information under Regulation S-P, (ii) add new requirements addressing cybersecurity risk to the U.S. securities markets, and (iii) expand the types of...more

SEC Fines Company $3 Million for Allegedly Misleading Cyberattack Disclosures

Asserting that the company misstated the scope of data stolen in the cyberattack, the SEC provides a clear reminder that cybersecurity disclosures remain an agency priority....more

Consumer Health Information and Increased Scrutiny: FTC Brings First Action Under Health Breach Notification Rule

The Federal Trade Commission ("FTC") has brought its first enforcement action for violations of the Health Breach Notification Rule ("HBNR"), signaling heightened federal agency scrutiny of digital health platforms,...more

U.S. National Institute of Standards and Technology Releases AI Risk Management Framework

The National Institute of Standards and Technology ("NIST") has released its AI Risk Management Framework ("AI RMF") as a resource to reportedly assist individuals, organizations, and society identify risks associated with...more

Australian Government Serious About Data Privacy: Substantial Increases in Fines and Enhanced Regulatory Powers

In Short - The Situation: Following a number of high-profile cyber incidents resulting in significant data breaches, the Australian Government has doubled down on its efforts to strengthen privacy laws and cybersecurity...more

Rising Global Regulation for Artificial Intelligence

Across multiple continents and industries, artificial intelligence ("AI") is a topic of intense focus by governments, research institutions, investors, and corporations—from start-ups to well-established industry players. As...more

California Privacy Protection Agency Modifies its Proposed Regulations

In Short - The Situation: The California Privacy Protection Agency ("CPPA" or "Agency") has modified its proposed regulations implementing many key California Privacy Rights Act ("CPRA") requirements....more

United States Signs Executive Order to Implement EU-U.S. Trans-Atlantic Data Privacy Framework

On October 7, 2022, President Biden signed an executive order on "Enhancing Safeguards for United States Signals Intelligence Activities," outlining the measures that the United States will take to implement its commitments...more

European Commission Proposes New Liability Rules on Products and AI

On September 28, 2022, the European Commission published two proposals—the Revised Product Liability Directive and the AI Liability Directive—aimed at adapting liability rules to the green and digital transition within the...more

European Commission Proposes Legislation Imposing New Cybersecurity Requirements on Digital Products

On September 15, 2022, the European Commission ("EU") published a proposal for a Cyber Resilience Act, the first EU-wide legislation introducing a single set of cybersecurity rules for hardware and software products placed in...more

California Attorney General Signals CCPA Enforcement Priorities in $1.2 Million Sephora Settlement

On August 24, 2022, California Attorney General Rob Bonta announced his office's first privacy enforcement action and settlement against a publicly disclosed entity, Sephora, Inc., for violations of the CCPA, including the...more

Federal Privacy and Data Security Regulation on the Horizon: The FTC Announces Proposed Rulemaking

The Federal Trade Commission announced on August 11, 2022, that it is seeking public comment regarding its Advanced Notice of Proposed Rulemaking on commercial surveillance and data security. The Federal Trade Commission...more

Utah Becomes Fourth State to Enact a Comprehensive Data Privacy Law

On March 24, 2022, Utah followed California, Virginia, and Colorado in adopting a comprehensive consumer data privacy law. On March 24, 2022, Utah Governor Spencer Cox signed the Consumer Privacy Act ("Act"), making Utah...more

President Biden Signs Cyber Incident Reporting for Critical Infrastructure Act

On March 15, 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (the "Act"), creating new requirements for organizations operating in critical infrastructure sectors to...more

SEC Proposes Amendments Regarding Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure

As part of the SEC's broader rulemaking initiative, on March 9, 2022, the SEC proposed amendments to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting by...more

Department of Commerce Seeks Comment on Regulation of IaaS Providers

Regulations will mandate more robust customer identity verification procedures and special measures to combat malicious cyber activities. On September 24, 2021, the Department of Commerce ("Commerce") published an Advance...more

Connecticut Expands Data Breach Notification Requirements and Establishes a Cybersecurity "Safe Harbor"

Connecticut has become the third state to enact a cybersecurity safe harbor statute. On June 16 and July 6, 2021, Connecticut Governor Ned Lamont signed two new cybersecurity laws that continue the national trend of...more

Colorado Becomes Third State to Enact Comprehensive Data Privacy Law

Introduction  Colorado has joined California and Virginia as the third state with a comprehensive data privacy law. On July 7, 2021, Colorado Governor Polis signed the Act into law, following the Colorado Senate's passage of...more

New York Department of Financial Services Announces New Guidance on Ransomware Prevention

On June 30, 2021, the New York Department of Financial Services ("NYDFS") identified key cybersecurity measures to prevent and prepare for ransomware attacks. ...more

Litigation and Regulatory Considerations and Risks for Financial Market Participants in a Post-Pandemic Society

More than a year ago the world fell victim to a global pandemic that would change life in ways that could never have been predicted. In the early stages of the pandemic, we published a White Paper directed at financial...more

Autonomous Vehicles: Legal and Regulatory Developments in the United States

The evolution of autonomous vehicle technology and its forthcoming widespread use have the potential for many societal benefits, including safer roads, greater economic productivity, and better fuel economy. Along with the...more

GSA's Use of DoD Cybersecurity Language for Future Contracts Signals Increased Security Requirements in Civilian Contracts

The General Services Administration ("GSA") is including language regarding cybersecurity requirements in requests for proposals relating to certain IT governmentwide acquisition contracts ("GWACs"). Certain requirements will...more

Fintech: Proposed Banking Cyber-Incident Notification Rules Could Apply to You, Too

The Situation: As we advised in our recent Commentary, federal banking regulators have proposed rules requiring a banking organization to provide its primary federal regulator with prompt notification of any...more

89 Results
 / 
View per page
Page: of 4

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide