Legal News
December 14, 2023
1221 views 48 secs 0

Feds brace for implementation of SEC cyber disclosure rules

The Record reports: The U.S. government is readying to implement contentious new disclosure rules for digital attacks that could both create headaches for the private sector and law enforcement and shed invaluable light on the state of ransomware and online threats. On December 18, a rule passed earlier this year by the Securities and Exchange […]

Legal News
December 12, 2023
1163 views 56 secs 0

Navigating the complexities of regulatory data incident investigations

From the law firm of Troutman Pepper Hamilton Sanders LLP: It is indeed a tangled regulatory web woven to potentially trap an organization in the wake of a data incident. Navigating this web can involve significant resources, time, and stress. As we discussed in part two of this series, “Your organization has suffered a data incident: […]

Legal News, News
December 08, 2023
1144 views 2 secs 0

FBI explains how companies can delay SEC cyber incident disclosures

The Record reports: The FBI has published guidance on how companies can request a delay in disclosing cyber incidents to the Securities and Exchange Commission (SEC). The document is a followup to new rules that the SEC approved in June requiring companies to quickly disclose “material” cybersecurity incidents and share the details of their cybersecurity risk management, […]

Legal News, Commentaries and Analyses, Critical Infrastructure
December 05, 2023
689 views 10 secs 0

Update on Cyber Incident Reporting for Critical Infrastructure Act of 2022

Constangy, Brooks, Smith & Prophete, LLP writes: As we near the end of another year, it is time to look ahead to developments in the information security and privacy landscape. One area of particular importance is the development of regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022. CIRCIA, which was signed into […]

Legal News, Insurance News, News
November 29, 2023
1364 views 2 mins 0

DFS Announces $1 Million Cybersecurity Settlement With First American Title Insurance Company

On November 28, the New York State Department of Financial Services (DFS) issued a press release about a settlement stemming from a 2019 data breach: The New York State Department of Financial Services (DFS) today announced that First American Title Insurance Company (First American) will pay a $1 million penalty to New York State for […]

Legal News
November 29, 2023
1267 views 48 secs 0

Queensland passes mandatory data breach notice laws

InnovationAus reports: Queensland has become only the second state to legislate a mandatory data breach notification scheme for public sector entities, as an almost identical scheme comes into effect in New South Wales. The Information Privacy and Other Legislation Amendment Bill 2023 passed through the Queensland state Parliament on Wednesday, less than two months after the bill […]

Legal News
November 19, 2023
1227 views 3 secs 0

FCC adopts new rules to protect consumers from SIM-swapping attacks

Bleeping Computer reports: The Federal Communications Commission (FCC) has revealed new rules to shield consumers from criminals who hijack their phone numbers in SIM swapping attacks and port-out fraud. FCC’s Privacy and Data Protection Task Force introduced the new regulations in July. They are geared toward thwarting scammers who seek to access personal data and information […]

News, Legal News
November 17, 2023
1396 views 3 mins 0

Morgan Stanley agrees to pay $6.5 million to settle charges by six states over two data security incidents

TALLAHASSEE, Fla.—Attorney General Ashley Moody, along with five other attorneys general, secured a $6.5 million agreement with Morgan Stanley Smith Barney LLC, also known as Morgan Stanley. The action comes after an investigation found that Morgan Stanley compromised the personal information of its customers due to negligent internal data-security practices. Morgan Stanley potentially exposed millions […]

Legal News, Malware Ransomware, News
November 16, 2023
826 views 3 mins 0

A ransomware gang files an SEC complaint against its victim for not reporting the breach to the SEC within 4 days

“They did WHAT??” Ransomware gangs will often test ways to pressure victims to pay. But today, threat actors associated with the AlphV (BlackCat) group tested a new approach that is raising eyebrows in the cybersecurity community. When a victim, MeridianLink, didn’t pay them quickly and didn’t even start to negotiate any payment with them, AlphV […]