Latest Posts › Risk Management

Share:

How Bad Is It Out There? Our Thoughts on Verizon’s 2024 Data Breach Investigations Report (DBIR)

Verizon released its Data Breach Investigations Report (DBIR) for 2024, an annual treat that highlights some trends companies should be aware of as they manage their cybersecurity programs and respond to and anticipate new...more

Darned if You Do, Darned if You Don’t: Recent Lessons from the SEC On Cyber Reporting

The Security and Exchange Commission (SEC) Director of the Division of Corporate Finance, Erik Gerding, released a statement on May 21, 2024 that may have regulated entities scratching their heads about compliance and the...more

New White House Policy Previews Increased Cybersecurity Oversight and Regulation

On April 30, 2024 the White House updated the foundational U.S. government policy that defines critical infrastructure (CI) sectors and establishes a coordination structure within the federal government to support owners and...more

NIST Cybersecurity Framework 2.0 Reveals Major Shifts in Federal Guidance

On February 26, 2024, the National Institute of Standards and Technology (NIST) released the Cybersecurity Framework version 2.0 (CSF 2.0). CSF 2.0 is a generational update to NIST’s foundational cybersecurity guidance, which...more

Cyber Incident Reporting Guidance: DOJ Explains How It Will Determine if a Public Disclosure Poses Substantial National Security...

The cyber reporting landscape is rapidly shifting. Many agencies are developing rules, and a major player has been the U.S. Securities and Exchange Commission (SEC), with important questions arising about implementation of...more

Biden Administration Looks at Harmonizing Cyber Regulations Amidst Flurry of New Activity

Cybersecurity continues to be top of mind for federal and state policymakers. This advisory identifies and analyzes some major recent developments that present opportunities and challenges in the coming months for a broad...more

SEC Adopts Controversial New Cybersecurity Disclosure Rules for Public Companies

Public companies will soon face new cybersecurity disclosure requirements from the Securities and Exchange Commission (SEC), which voted last week to approve a controversial new cybersecurity rule. The final rule—which is...more

A New White House Project on Responsible AI Sends a Message to the Private Sector, Including Contractors

It is hardly news that artificial intelligence (AI) has captured attention across the federal government. Wiley’s multidisciplinary AI team has been involved in efforts at the National Institute for Standards and Technology...more

The Private Sector Should Watch NIST’s Broad Work on Privacy and Cybersecurity Guidance

NIST continues to work on several cybersecurity and privacy workstreams of interest to the private sector. While NIST has traditionally supported federal agencies’ IT security, over the past several years it has taken on (and...more

[Webinar] Privacy and Security in Transactional Due Diligence - May 25th, 12:00 pm - 1:00 pm EDT

Join us to discuss effective approaches to managing due diligence on privacy and cybersecurity issues across transactions. Companies considering acquisitions or joint ventures will need to engage in effective management of...more

NIST Moves to Update its Cybersecurity Framework, Seeks Public Comment

The National Institute of Standards and Technology (NIST) has kicked off the process for revamping its flagship cybersecurity guidance document – the Framework for Improving Critical Infrastructure Cybersecurity (CSF), which...more

SEC Proposes Cybersecurity Rules for Publicly Traded Companies

What: Publicly traded companies may soon be subject to additional cybersecurity reporting requirements. On March 9, 2022, the Securities and Exchange Commission (SEC) proposed rules and amendments to enhance and standardize...more

President’s Telecom Advisors Promote Zero Trust Architecture in Key Report

What: On February 23, 2022, the National Security Telecommunications Advisory Committee (NSTAC) approved a final draft of its forthcoming report to the President on Zero Trust and Trusted Identity Management. ...more

Cyber Proposals Should Reject Impractical Obligations and Victim Shaming

There is a growing clamor in Congress and the Executive Branch to do something after the Colonial Pipeline incident and other high-profile cyber-attacks. Rushing to impose broad new obligations is perilous. Policymakers...more

2021 Preview: How the Private Sector Will be Impacted by IoT Cybersecurity Work at NIST

The National Institute of Standards and Technology (NIST) has been an active driver of Internet of Things (IoT) cybersecurity efforts for several years, convening stakeholders from the federal government and the private...more

The Information and Communications Technology Supply Chain Risk Management Task Force Issues Its Year Two Report

On December 17, 2020, the Information and Communications Technology (ICT) Supply Chain Risk Management (SCRM) Task Force (“the Task Force”)—a public-private partnership whose membership includes industry representatives from...more

Government and Industry Report: COVID Pandemic Illustrates Need for Resilience in ICT Supply Chains

In the midst of the ongoing COVID-19 pandemic, the federal government and private sector used ongoing supply chain partnerships to examine how the crisis exposed vulnerabilities in critical sectors that underpin our national...more

18 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide