LATEST POST
Changes to Notification and Security Requirements Continue at the Federal Level
In October 2023, Perkins & Coie published an update to existing federal breach notification laws. They write: Following last year’s passage of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (rulemaking for which should formally commence in 2024), the major action on the federal front this year came from the SEC, which formalized disclosure […]
Updates to state laws on security requirements
In October 2023, Perkins & Coie published an update to state laws for data security requirements: In addition to revisions to breach notification statutes, states are making a variety of changes to substantive data security obligations. Changes applicable to private companies include: For details on the above, see the Perkins & Coie article on their […]
Changes to Breach Notification Requirements Continue at State Level
In October 2023, Perkins Coie published an update to existing state breach notification laws. Pennsylvania The first major update to Pennsylvania’s Breach of Personal Information Notification Act was passed earlier this year. The updates include a range of changes consistent with those adopted in other states in the last several years, so these updates are unlikely […]
Okta’s latest hack fallout hits Cloudflare, 1Password
TechCrunch reports: Network and security giant Cloudflare and password manager maker 1Password said hackers briefly targeted their systems following a recent breach of Okta’s support unit. Both Cloudflare and 1Password said their recent intrusions were linked to the Okta breach, but that the incidents did not affect their customer systems or user data. “We immediately terminated […]
Phishing Guidance: Stopping the Attack Cycle at Phase One
Posted by CISA.gov, this guidance also has tips for small and medium businesses: This guide was created by the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) to outline phishing techniques malicious actors commonly use and to provide guidance for […]
Okta shares fall 11% after company says client files were accessed by hackers via its support system
Stock prices often fall after a major breach is announced. Many will rebound quickly, but not all do. Here is an example from this past week of a firm taking a significant stock hit shortly after a breach was announced. CNBC reports: Shares of cybersecurity firm Okta closed down 11.5% after the company said an unidentified hacking group had […]
Why are cyber experts concerned about data security in India?
For those readers who think India is not of great interest or importance to them, remember that many non-Indian firms and entities outsource some or all of their functions to firms in India — and often without your knowledge. The Week reports: Digital transformation and development of advanced technologies are progressing at full pace in […]
Top US Cyber Agency Pushing Toward First Hack Reporting Rule
As seen on Bloomberg Law: A new US notification requirement for victims of malicious hacks could push in-house counsel to disclose cyberattacks when faced with ransomware and other network compromises. Among the first-ever cyber regulations to be enforced by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, the top US cyber authority, the […]