cyber regulation News

Companies Are Still Trying to Figure Out How to Comply With SEC Cyber Rules

Some public companies are still trying to figure out how to comply with new rules from the US Securities and Exchange Commission requiring speedy disclosure of significant cyberattacks. Those rules, which kicked in Monday, require companies to report cyber incidents …

Microsoft’s Role in Email Breach to Be Part of Cyber Inquiry

A US cybersecurity advisory panel will investigate malicious targeting of cloud computing environments, including Microsoft Corp.’s role in a recent breach of government officials’ email accounts by suspected Chinese hackers, the Department of Homeland Security confirmed on Friday. The review …

SEC Set to Adopt New Cyber Rule, Unveils Brokerage AI Proposal

Wall Street’s top regulator on Wednesday was poised to adopt new rules requiring publicly traded companies to disclose hacking incidents, a measure officials said was being taken to help the investing public contend with the mounting cost and frequency of …

Law Firm Must Name Clients Affected by 2020 Cyberattack, Judge Says

Covington & Burling must identify some clients caught up in a 2020 hack on the law firm to the U.S. Securities and Exchange Commission, a federal judge in Washington ruled on Monday in a case that could impact future cyberattack …

New York Proposes Changes to Financial Services Cybersecurity Regulation

More small financial services businesses will be exempt, the rules will be tailored to reflect more diversity in businesses, and top executives of financial services firms will face heightened accountability under proposed changes to New York’s model financial services cybersecurity …

Firms Must Report Hacks to DHS in 72 Hours Under Law

The $1.5 trillion government funding package that President Joe Biden signed Tuesday includes sweeping cybersecurity legislation that will require critical infrastructure operators to quickly report data breaches and ransomware payments. The new law mandates that companies report hacks to the …

SEC Weighs Four-Day Deadline for Firms to Disclose Major Hacks

Companies would face more pressure to alert the public of hacks or other significant cybersecurity incidents under a new plan from the U.S. Securities and Exchange Commission. The SEC will consider a proposal on Wednesday that would require publicly-traded firms …

Pennsylvania Senate Passes Ransomware, Data Breach Bills

Pennsylvania’s state Senate passed a package of legislation on Wednesday aimed at preventing data security breaches and requiring victims and law enforcement officials to be notified when they do happen. The bills’ passage comes barely two weeks after the state’s …

New U.S. Rule Requires Banks to Promptly Report Cyber Incidents

U.S. banking regulators on Thursday finalized a rule that directs banks to report any major cybersecurity incidents to the government within 36 hours of discovery. Separately, the banking industry said it had successfully completed a massive cross-industry cyber security drill …

New York’s Cybersecurity Rules: What Insurance Professionals Should Know

The New York Department of Financial Services (DFS) has issued cybersecurity requirements for financial services companies (cyber rules) that went into effect March 1. The cyber rules, codified at 23 NYCRR §500, require insurance and insurance-related companies as well as …