Policy & Regulation: Page 2


  • Michael Regan stands at a podium and speaks.
    Image attribution tooltip
    Kevin Dietsch via Getty Images
    Image attribution tooltip

    More warnings emerge about state-linked cyber threats to water infrastructure

    The White House and EPA set an urgent virtual meeting with state homeland security and other top officials, citing efforts to boost the resiliency of drinking and wastewater treatment systems.

    By March 20, 2024
  • Photo illustration of a VF Corp. SEC filing.
    Image attribution tooltip

    Photo illustration: Industry Dive; US Securities and Exchange Commission

    Image attribution tooltip

    How companies describe cyber incidents in SEC filings

    The words businesses use in cybersecurity disclosures matter. They can channel confidence in the recovery process, potential impacts and legal liabilities.

    By March 19, 2024
  • U.S. Vice President Kamala Harris looks on as President Joe Biden signs an executive order.
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip
    Opinion

    Threat environment is changing for individuals and SMBs, White House order shows

    An executive order is trying to prevent the large-scale transfer of Americans’ data, as countries seek troves of U.S. data for blackmail, AI training and analysis, among a multitude of other purposes. 

    By Michael Kosak • March 18, 2024
  • Close up of Gary Gensler speaking during a senate hearing
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    What’s material to the SEC, 3 months into cyber disclosure rules?

    As attacks become more sophisticated and destructive, companies are struggling to find conclusive estimates of the financial impact of cyberattacks.

    By March 18, 2024
  • The seal of the Federal Communications Commission.
    Image attribution tooltip
    Mark Wilson / Getty Images via Getty Images
    Image attribution tooltip

    Stronger FCC data breach reporting rules for telecom go live

    The updated rules expand the scope of breach disclosure requirements to cover all PII and carriers have to notify customers within 30 days of determining a breach occurred.

    By March 15, 2024
  • A person uses a wall-mounted smart home interface to answer a call in the kitchen.
    Image attribution tooltip
    Courtesy of Brilliant
    Image attribution tooltip

    FCC approves voluntary cyber labeling program for smart home IoT devices

    The Biden administration wants the U.S. Cyber Trust Mark program to incentivize higher security standards in future IoT product development.

    By March 15, 2024
  • The exterior of the Department Health and Human Services headquarters.
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    HHS opens investigation into Change Healthcare cyberattack

    The Office for Civil Rights will focus on whether protected health information was breached and if UnitedHealth complied with privacy and security requirements. 

    By Emily Olsen • March 14, 2024
  • Computer language script and coding on screen.
    Image attribution tooltip
    themotioncloud via Getty Images
    Image attribution tooltip

    White House adds teeth to secure software development requirements

    CISA and OMB released an attestation form to ensure compliance with secure development practices.

    By March 13, 2024
  • The White House in Washington, D.C.
    Image attribution tooltip
    TriggerPhoto via Getty Images
    Image attribution tooltip

    White House meets with UnitedHealth, industry groups on Change Healthcare cyberattack fallout

    Officials called on payers to cut red tape and offer financial support to providers, including advanced payments. 

    By Emily Olsen • March 13, 2024
  • A birds-eye picture of a stethoscope and piggy bank against a blue background
    Image attribution tooltip
    erdikocak via Getty Images
    Image attribution tooltip

    CMS rolls out provider flexibilities amid fallout from Change cyberattack

    Provider groups said the government should go further to financially bolster providers during the outage at Change Healthcare.

    By Emily Olsen • March 5, 2024
  • The exterior of the U.S. Capitol on Jan. 3, 2024.
    Image attribution tooltip
    Colin Campbell/Cybersecurity Dive
    Image attribution tooltip

    Provider groups urge HHS, Congress to mitigate damage from Change cyberattack

    The American Hospital Association and the American Medical Association pushed the federal government to offer more financial support as the Change outage limits providers’ ability to receive payment.

    By Emily Olsen • March 5, 2024
  • Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    NIST makes it official: governance is a critical part of cybersecurity

    A collection of resources accompany CSF 2.0 to make the guidance easier for businesses to use and put into practice across their operations.

    By Feb. 29, 2024
  • A utility worker checks a power line after a tornado.
    Image attribution tooltip
    photovs via Getty Images
    Image attribution tooltip

    Utility regulators take steps to raise sector’s cybersecurity ‘baselines’

    The voluntary cyber recommendations are intended to serve as a resource for state public utility commissions, utilities and distribution operators and aggregators.

    By Robert Walton • Feb. 29, 2024
  • Exterior of MGM Grand Hotel & Casino in Las Vegas
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    MGM Resorts’ cyberattack headache continues as regulators launch investigations

    The company said it could face fines in connection with regulatory inquiries stemming from the social engineering attack.

    By Feb. 26, 2024
  • The exterior of the Department Health and Human Services headquarters.
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    HHS reaches second-ever ransomware settlement

    A mental healthcare provider didn’t have sufficient protections in place before a ransomware attack exposed the protected health information of more than 14,000 people, according to the HHS’ Office for Civil Rights.

    By Emily Olsen • Feb. 22, 2024
  • Drone shot of a massive container ship arriving in the Port of Long Beach, California.
    Image attribution tooltip
    halbergman via Getty Images
    Image attribution tooltip

    Biden administration issues executive order on port cybersecurity

    The order will transfer crane manufacturing back to the U.S., amid concerns about potential cyber risk to port facilities, maritime transportation and threats from China.

    By Feb. 21, 2024
  • Image attribution tooltip
    Anna Moneymaker via Getty Images
    Image attribution tooltip

    LockBit operations dismantled following international takedown

    An international group of law enforcement partners seized the infrastructure of the prolific ransomware group, obtaining decryption keys along the way. 

    By Feb. 20, 2024
  • Grunge flags illustration of three countries with conflict and political problems (cracked concrete background) | USA, China and Russia
    Image attribution tooltip
    Barks_japan via Getty Images
    Image attribution tooltip

    FBI-led operation disrupts botnet controlled by state-linked Forest Blizzard

    Russia’s GRU-backed group exploited hundreds of vulnerable routers to conduct spear phishing and credential harvesting attacks against U.S. targets.

    By Feb. 16, 2024
  • Creative image depicting a ransomware attack.
    Image attribution tooltip
    iStock / Getty Images Plus via Getty Images
    Image attribution tooltip

    State Department puts $10M bounty on AlphV ransomware group

    The prolific ransomware group and its affiliates are behind some of the most high-profile attacks in the last year.

    By Feb. 15, 2024
  • Sphere venue in Las Vegas.
    Image attribution tooltip
    Greg Doherty via Getty Images
    Image attribution tooltip

    CISA blitzes Super Bowl with cyber campaign as businesses fumble security

    CISA brought its Secure Our World initiative to Las Vegas, for the biggest annual event in sports. Will anyone heed the advice?

    By Feb. 9, 2024
  • National Cyber Director Harry Coker speaks in Washington.
    Image attribution tooltip
    Permission granted by Information Technology Industry Council
    Image attribution tooltip

    National cyber director urges private sector collaboration to counter nation-state cyber threat

    Harry Coker said the Biden administration is exploring plans to hold manufacturers accountable for poor security, while also working to harmonize regulations.

    By Feb. 9, 2024
  • A picture of the exterior of the US Department of Health and Human Services. In front of the building is a black sign designating the building's name.
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    HHS settles cybersecurity investigation with Montefiore Medical Center

    The nonprofit will pay $4.75 million to settle allegations that data security failures allowed an employee to steal and sell the protected health information of thousands of patients.

    By Emily Olsen • Feb. 8, 2024
  • FBI Director Chris Wray speaks at a House Select Committee hearing on Volt Typhoon. CISA Director Jen Easterly and NSA Director Gen. Paul Nakasone look on.
    Image attribution tooltip
    Kevin Dietsch via Getty Images
    Image attribution tooltip

    CISA, FBI confirm critical infrastructure intrusions by China-linked hackers

    Federal agencies urged critical infrastructure providers and tech manufacturers to take immediate action to protect against malicious threat activity from Volt Typhoon.

    By Feb. 7, 2024
  • Coin stack on international banknotes with house model on table.
    Image attribution tooltip
    Zephyr18 via Getty Images
    Image attribution tooltip

    Mortgage industry attack spree punctuates common errors

    Attacks against Mr. Cooper Group, Fidelity National Financial, First American Financial and loanDepot impacted operations and put customers in a bind.

    By Feb. 6, 2024
  • Close up of Gary Gensler speaking during a senate hearing
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    Business, technology groups back SolarWinds motion to dismiss SEC charges

    Former U.S. cybersecurity officials and a group of current and former CISOs warned the fraud suit against SolarWinds could chill intel sharing from the private sector.

    By Feb. 5, 2024