Legal News
December 18, 2024
603 views 12 secs 0

CISA orders federal agencies to secure Microsoft cloud systems after ‘recent’ intrusions

For a while, it was just a recommendation. Now it’s mandatory. Federal civilian agencies were ordered to secure their Microsoft cloud systems after several recent cyber incidents.  The Cybersecurity and Infrastructure Security Agency (CISA) issued a binding directive on Tuesday giving federal agencies a series of deadlines to identify cloud systems, implement assessment tools and abide by […]

Legal News, Cyberattack, News
December 17, 2024
1282 views 3 mins 0

SEC Charges Flagstar for Misleading Investors About Cyber Breach

ADMINISTRATIVE PROCEEDINGFile No. 3-22360 December 16, 2024 – The Securities and Exchange Commission today filed settled charges against Flagstar Bancorp, Inc. (now known as “Flagstar Financial, Inc.”), for making materially misleading statements regarding a cybersecurity attack on Flagstar’s network in late 2021 (the “Citrix Breach”). The SEC’s order finds that Flagstar negligently made materially misleading statements […]

Commentaries and Analyses, Legal News, News
December 10, 2024
1379 views 35 secs 0

Should regulators do more naming and shaming?

The U.K. Information Commissioner’s Office did an interesting two-year trial and the results suggest that publicly reprimanding public sector entities over breaches and data leaks is an effective strategy — even without any monetary penalties. Infosecurity Magazine reports: The publication of reprimands following data leaks has been cited as an “effective” deterrent for public authorities. […]

Legal News, Malware Ransomware
December 03, 2024
1166 views 37 secs 0

Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested

The Hacker News reports that a notorious Russian cybercriminal wanted in the U.S. in connection with LockBit and Hive ransomware operations has been arrested: According to a news report from Russian media outlet RIA Novosti, Mikhail Pavlovich Matveev has been accused of developing a malicious program designed to encrypt files and seek ransom in return for a […]

Legal News, Healthcare
November 10, 2024
1234 views 56 secs 0

HIPAA Gets a Potential Counterpart in HISAA

Legislation proposed in September would mandate minimum cybersecurity requirements in the healthcare sector. Kevin Wood, the Chair of Winstead’s Healthcare Industry Group, writes: …. Senators Ron Wyden (D-OR) and Mark Warner (R-VA) introduced the Health Infrastructure Security and Accountability Act (HISAA) on September 26, 2024. Like HIPAA and HITECH before it, which established minimum levels […]