Feds Push Cyber Insurance for Healthcare Industry

The HHS 405(d) Program (see below) is an industry group supported by the U.S. Department of Health and Human Services (HHS) that is attempting to improve cyber security in the health industry. See examples of its resources and projects here. (We’ve reported numerous stories on cyber insurance for healthcare organizations and hospitals.) The HHS program … Read more

Local Media Reports on Cyber Insurance Issues Involved in Hack of Oakland

Oakland was hit with a ransomware attack attack in May and the fall out continues, along with what to us is a surprising, and positive, focus by local media on the city’s cyber insurance coverage. The most recent reporting reveals the city has apparently failed to notify many citizens that their personal information was revealed … Read more

Amid Fear And Risk New GAO CyberSecurity Guide

The U.S. Government Accountability Office (GAO) has released a new cybersecurity guide in response to the increasing risks facing federal IT systems. The GAO Cybersecurity Program Audit Guide offers comprehensive guidance for conducting cybersecurity performance audits. This guide is designed with two basic objectives. First, assist Congress, federal departments, state and local auditors, private sector … Read more

Indian PM Cybercrime Collaboration Needed

In an exclusive interview with PTI, Indian Prime Minister Narendra Modi called for global collaboration to combat cybercrime, which he said is a “growing threat” to all countries. Modi said that cybercrime can be used to fund terrorism, spread misinformation, and disrupt critical infrastructure. “Cybercrime is a growing threat to all countries,” Modi said. “It … Read more

SEC Reveals Its Cyber Reporting Rule, Scrambling and Confusion Sure to Follow 

The U.S. Securities and Exchange Commission (SEC) has issued its new cybersecurity rule, which aims to enhance transparency and accountability in managing cyber risks. The rule requires businesses to promptly report any material cyber breaches within four business days. Additionally, companies are obligated to disclose their processes for managing cybersecurity risks. The SEC asserts this … Read more

×