Latest Posts › Cybersecurity

Share:

California Senate Approves Landmark California Age-Appropriate Design Code Act

On August 29, 2022, the California Senate passed the landmark Assembly Bill 2273, which would enact the California Age-Appropriate Design Code Act (the “Act”). If signed into law by Governor Newsom, the Act could have...more

First CCPA Enforcement Action: “There Are No More Excuses” for Companies Who Do Not Comply

On August 24, 2022, California Attorney General Rob Bonta (AG) announced a proposed settlement with beauty retailer Sephora USA, Inc. to resolve claims that Sephora violated the California Consumer Privacy Act (CCPA). Under...more

DOJ’s Cyber Review and Aerojet $9 Million Settlement Signal Continuing FCA Enforcement for Cybersecurity Violations by Government...

On Tuesday, the Department of Justice (DOJ) released its Comprehensive Cyber Review report (the “Review”) summarizing its review of the Department’s cyber-related activities and its recommendations around the Department’s...more

CPPA Issues Its First Draft of CPRA Regulations

Companies are now on the clock for comments on the new proposed California Privacy Rights Act (CPRA) regulations. On July 8, 2022, the California Privacy Protection Agency (CPPA) filed a Notice of Proposed Action, triggering...more

Lawmakers Unveil Landmark Bipartisan Privacy Proposal

Key Points - Three of the four bipartisan leaders of the House and Senate committees with jurisdiction over data privacy have struck a deal on a comprehensive federal bill, the American Data Privacy and Protection Act,...more

[Podcast] 2021 CCPA Litigation Report – Overview and Findings

In this episode, Natasha Kohne and Michelle Reed, who head Akin Gump’s cybersecurity, privacy and data protection practice, and counsel Lauren York discuss the firm’s new CCPA Litigation Annual Report – 2021 Trends and...more

Fourth Circuit Rules Omission of Marriott’s Data Vulnerabilities Not Actionable Because Challenged Statements Were Not False When...

Key Points - Fourth Circuit points to SEC guidance on “less is more” approach to cybersecurity disclosures, while finding such disclosures did not violate federal securities laws. Omissions of data vulnerabilities were...more

DOT Amends Safety Standards to Account for Autonomous Vehicles

On March 10, 2022, the U.S. Department of Transportation’s (DOT) National Highway Traffic and Safety Administration (NHTSA) issued a first-of-its-kind final rule updating occupant safety requirements to account for vehicles...more

Utah Consumer Privacy Act: What Businesses Need to Know

With the recent signing of the Utah Consumer Privacy Act (UCPA) by Gov. Spencer J. Cox on March 24, 2022, Utah has become the fourth state to enact a comprehensive law addressing consumer data privacy, joining California,...more

Colorado AG Issues Guidance on Data Security Best Practices

Colorado requires businesses to take reasonable steps to protect consumer data under both the Colorado Consumer Protection Act and its landmark new data privacy law, the Colorado Privacy Act (CPA). The CPA comes into force on...more

President Biden Signs Sweeping Cyber Legislation into Law

Under legislation signed into law today by President Joe Biden, certain companies will be required to report cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours. Within 24...more

Disclosing Cyber Incidents and Risks: SEC Proposes Rules to Enhance and Standardize Cyber Disclosures and Incident Reporting by...

Key Points - Proposed amendments bolster cyber disclosure and incident reporting requirements to better inform investors about a company’s risk management, strategy and governance relative to cyber issues. Under the...more

CPRA Update: California Privacy Protection Agency Board Meeting Reports That Regulations Delayed

On February 17, 2022, the California Privacy Protection Agency (CPPA) Board held its first Board meeting of 2022. Notably, CPPA Executive Director Ashkan Soltani delivered an update on the CPPA’s rulemaking activities and...more

SEC Proposes Rules to Enhance and Standardize Cyber Disclosures and Incident Reporting by Public Companies

Key Points - Proposed amendments bolster cyber disclosure and incident reporting requirements to better inform investors about a company’s risk management, strategy and governance relative to cyber issues. ...more

FTC Issues Stern Warning to Companies to Address Known Cybersecurity Vulnerability

The Federal Trade Commission (FTC) issued a surprisingly strong warning to companies that they may face potential regulatory action if they fail to address known vulnerabilities, focusing in particular on the Log4j...more

California AG Sweeps Business Loyalty Programs for CCPA Noncompliance

On January 28, 2022, the California Attorney General (AG) announced an “investigative sweep” of businesses operating loyalty programs in the state, which it launched by sending multiple businesses notice of noncompliance with...more

Draft EU Artificial Intelligence Act: Call for Contributions from the Public

The ground-breaking draft European Union Act on Artificial Intelligence (AI), which has far-reaching implications beyond Europe, is currently going through the legislative procedure of the European Parliament and Council. The...more

SEC Chair Gensler Warns of a New Era of Cyber-Securities Laws

Gary Gensler, Chair of the U.S. Securities and Exchange Commission (SEC), signaled a new era of cybersecurity law (and accompanying enforcement) in his keynote address “Cybersecurity and Securities Laws” on January 24, 2022,...more

CPPA Releases Public Comments for CPRA Regulations

Public comments to recently published regulations governing compliance with the California Privacy Rights Act (CPRA) show that stakeholders sharply disagree on multiple areas of the CPRA. Seventy submissions totaling nearly...more

Treasury to Companies: Time to Take Ransomware Reporting Seriously

On September 21, 2021, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) published an updated sanctions advisory, providing guidance to companies on sanctions compliance obligations related to ransomware...more

NIST Seeks Public Comment on Eight Emerging Technology Areas to Advance More Productive Tech Economy

The National Institute of Standards and Technology (NIST) issued a request for public comment to help guide the development of the current and future state of technology in eight emerging technology areas. Those areas include...more

Changes Coming to DOD’s Cybersecurity Maturity Model Certification under CMMC 2.0

On November 17, 2021, the U.S. Department of Defense (DOD) published an Advanced Notice of Proposed Rulemaking (ANPRM) previewing significant changes to its Cybersecurity Maturity Model Certification (CMMC) program.1 The...more

Lloyd v Google UK Supreme Court Class Action Judgment — End of the Road for Some, Open Door for Others

On 10 November 2021, the Supreme Court dismissed the United Kingdom’s first ever “opt-out” class action brought outside of the competition law sector, in Lloyd v Google LLC. The claim, seeking an award of damages of around £3...more

Infrastructure Investment and Jobs Act Summary of Key Programs and Provisions

[co-author: Christina Barone] The Infrastructure Investment and Jobs Act (the “bill”) is historic bipartisan legislation that will make available $1.2 trillion in funding for infrastructure programs across the...more

175 Results
 / 
View per page
Page: of 7

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide