New York State Announces New Cyber Regulations; Exempts Itself

New York’s legislature has announced two new amendments and a clarification to the State’s cyber law involving data breaches, highlighting important changes in cyber regulations, reports the indispensable JD Supra. Businesses now have a 30-day deadline to notify residents impacted by covered breaches and, if the hack involves financial matters, the New York Department of … Read more

SEC Cyber Disclosure Rule Criticized in Recent Reports

We’ve reported extensively on the SEC cyber disclosure rule that requires public companies to submit 8-K filings when they’re hit with cyber attacks. For some reason, the rule has attracted criticism from several media outlets in recent days. Earlier this week Bloomberg Law provided a critical review (under paywall) of how companies have responded to … Read more

CyberCatch Launches No-Application Cyber Insurance for CMMC Compliance

CyberCatch Partners with CMR to Offer Cyber Insurance for CMMC Compliance CyberCatch Holdings, Inc. has introduced a no-application cyber insurance policy for businesses using its cybersecurity solution. The initiative targets small- and medium-sized businesses (SMBs) in the U.S. defense sector that must comply with Cybersecurity Maturity Model Certification (CMMC) Level 1. CMMC Compliance and Cyber … Read more

SEC Cyber Incident Disclosures Show Confusion on “Materiality,” Limited Info on Cyber Insurance and Unexpected Whistleblowers

It’s been a year since public companies had to start complying with new SEC cyber incident disclosure rules requiring Form 8-Ks for “material” cyber events. Law firm Paul Hastings has now released a study of 75 disclosures from 45 companies between December 2023 and October 2024. It shows a 60% increase in the number of … Read more

EU Countries Blow Off New Cyber Security Regulations & European Commission Is Not Pleased

The European Commission has launched “infringement procedures” against a majority of its member states for failing to meet an October deadline to enact EU cyber security regulations. The regulations come in two packages: the NIS2 Directive, aimed at enhancing cyber security and the Critical Entities Resilience (CER) Directive, focused on safeguarding critical infrastructure. “The Commission … Read more

×