cyber regulation News

Microsoft’s Role in Email Breach to Be Part of Cyber Inquiry

A US cybersecurity advisory panel will investigate malicious targeting of cloud computing environments, including Microsoft Corp.’s role in a recent breach of government officials’ email accounts by suspected Chinese hackers, the Department of Homeland Security confirmed on Friday. The review …

SEC Set to Adopt New Cyber Rule, Unveils Brokerage AI Proposal

Wall Street’s top regulator on Wednesday was poised to adopt new rules requiring publicly traded companies to disclose hacking incidents, a measure officials said was being taken to help the investing public contend with the mounting cost and frequency of …

Law Firm Must Name Clients Affected by 2020 Cyberattack, Judge Says

Covington & Burling must identify some clients caught up in a 2020 hack on the law firm to the U.S. Securities and Exchange Commission, a federal judge in Washington ruled on Monday in a case that could impact future cyberattack …

New York Proposes Changes to Financial Services Cybersecurity Regulation

More small financial services businesses will be exempt, the rules will be tailored to reflect more diversity in businesses, and top executives of financial services firms will face heightened accountability under proposed changes to New York’s model financial services cybersecurity …

Firms Must Report Hacks to DHS in 72 Hours Under Law

The $1.5 trillion government funding package that President Joe Biden signed Tuesday includes sweeping cybersecurity legislation that will require critical infrastructure operators to quickly report data breaches and ransomware payments. The new law mandates that companies report hacks to the …

SEC Weighs Four-Day Deadline for Firms to Disclose Major Hacks

Companies would face more pressure to alert the public of hacks or other significant cybersecurity incidents under a new plan from the U.S. Securities and Exchange Commission. The SEC will consider a proposal on Wednesday that would require publicly-traded firms …

Pennsylvania Senate Passes Ransomware, Data Breach Bills

Pennsylvania’s state Senate passed a package of legislation on Wednesday aimed at preventing data security breaches and requiring victims and law enforcement officials to be notified when they do happen. The bills’ passage comes barely two weeks after the state’s …

New U.S. Rule Requires Banks to Promptly Report Cyber Incidents

U.S. banking regulators on Thursday finalized a rule that directs banks to report any major cybersecurity incidents to the government within 36 hours of discovery. Separately, the banking industry said it had successfully completed a massive cross-industry cyber security drill …

New York’s Cybersecurity Rules: What Insurance Professionals Should Know

The New York Department of Financial Services (DFS) has issued cybersecurity requirements for financial services companies (cyber rules) that went into effect March 1. The cyber rules, codified at 23 NYCRR ยง500, require insurance and insurance-related companies as well as …

Audit Hits Regulator for Not Testing Brokerage Firms’ Cyber Security Policies

The U.S. Commodity Futures Trading Commission failed to verify whether futures and swaps brokerage firms have adequate policies to help ward off cyber attacks, an internal CFTC audit found. The audit was completed in October by Brown & Company CPAS …