Policy & Regulation: Page 4


  • Microsoft's visitor center at its Redmond campus.
    Image attribution tooltip
    Stephen Brashear via Getty Images
    Image attribution tooltip

    Microsoft overhauls cyber strategy to finally embrace security by default

    The plan follows major backlash Microsoft experienced earlier this year for charging customers for additional security features. 

    By Nov. 3, 2023
  • Federal Trade Commission
    Image attribution tooltip
    Carol Highsmith. (2005). "The Apex Building" [Photo]. Retrieved from Wikimedia Commons.
    Image attribution tooltip

    Non-bank financial institutions must report data security breaches: FTC

    The amendment to the FTC’s Safeguards Rule requires non-banking financial institutions to disclose data breaches within 30 days.

    By Rajashree Chakravarty • Nov. 2, 2023
  • Close up of Gary Gensler speaking during a senate hearing
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    For the SEC, the fraud case against SolarWinds is a cybersecurity warning shot

    Legal, risk management and cybersecurity experts say companies are now on notice to prioritize internal controls, investor transparency and material disclosure requirements.

    By Nov. 2, 2023
  • Glasses, coding and reflection with business man reading software development analytics, database and system error report for information technology.
    Image attribution tooltip
    Kobus Louw via Getty Images
    Image attribution tooltip

    Global cybersecurity workforce grows, but still confronts shortfall of 4M people

    Despite growing to 5.5 million professionals worldwide, a study by ISC2 shows the industry still needs millions of qualified workers to defend against rising digital threats.

    By Oct. 31, 2023
  • SolarWinds
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by ismagilov via Getty Images
    Image attribution tooltip

    SEC charges SolarWinds, its CISO with fraud

    The company allegedly misled investors regarding its cybersecurity practices and failed to disclose known risks, according to a complaint.

    By Updated Oct. 31, 2023
  • Female IT Server Specialist Standing in Data Center. View from Rack Server Cabinet with Cloud Server User Interface Icons and Visualization in the Foreground.
    Image attribution tooltip
    gorodenkoff via Getty Images
    Image attribution tooltip

    CISA targets software identification in push to boost supply chain security

    The plan is part of a wider effort to boost software security using vulnerability management and SBOMs.

    By Oct. 27, 2023
  • Activision
    Image attribution tooltip
    jeenah Moon via Getty Images
    Image attribution tooltip

    Microsoft extends security log retention following State Department hacks

    Government and private sector customers will be able to search cloud data records for malicious threat activity by default.

    By Oct. 23, 2023
  • Two people sitting at a table with financial documents and a calculator
    Image attribution tooltip
    Daenin Arnee via Getty Images
    Image attribution tooltip

    FAIR Institute wants to quantify just how much a cyberattack costs

    The risk-management body is trying to create a standard to estimate material cyber attack costs and help stakeholders better understand risk.

    By Oct. 20, 2023
  • CISA Director Jen Easterly speaks at Carnegie Mellon University urging the tech industry to embrace secure-by-design product development.
    Image attribution tooltip
    Permission granted by Carnegie Mellon University
    Image attribution tooltip

    CISA launches new phase of Secure by Design to push global industry on software security

    The agency plans an RFI on secure engineering, while adding guidance on AI security and emphasizing default security that does not require customer configurations.

    By Oct. 18, 2023
  • stock image
    Image attribution tooltip
    Retrieved from Pixabay.
    Image attribution tooltip

    EPA rescinds rule to include cybersecurity in water system audits after legal challenge

    The Biden administration said it will continue efforts to reduce cyber risk in critical infrastructure sectors.

    By Oct. 16, 2023
  • Server room (Sefa Ozel/Getty)
    Image attribution tooltip
    Sefa Ozel/Getty via Getty Images
    Image attribution tooltip

    CISA’s top 10 misconfigurations reveal ‘systemic weaknesses’

    Common mistakes including poor credential management, weak MFA and lackluster patching continue to harm large enterprises.

    By Oct. 16, 2023
  • An engineer works with robotic arms in a factory using AI.
    Image attribution tooltip
    greenbutterfly via Getty Images
    Image attribution tooltip

    Federal agencies press OT/ICS providers on open-source security

    The U.S. is scrutinizing the security of critical infrastructure providers, which are becoming more dependent on connected infrastructure.

    By Oct. 12, 2023
  • Law flat icon on wooden block cube with calculator and pencil on dollar bank note money,
    Image attribution tooltip
    grapestock via Getty Images
    Image attribution tooltip

    Progress Software’s financial hit from MOVEit cuts deeper

    With insurance coverage dwindling, and class-action lawsuits and financial restitution claims piling up, more trouble could be on the way for the software company.

    By Oct. 11, 2023
  • Jen Easterly speaks during a fireside chat at the Billington Cybersecurity Summit.
    Image attribution tooltip
    Courtesy of Billington
    Image attribution tooltip

    CISA pivots focus to China-linked threats against critical infrastructure

    The agency now considers China the top nation-state threat, after a heavy emphasis on risks related to the Russia-Ukraine war.

    By Oct. 5, 2023
  • An angular view of the U.S. Capitol building against a clear blue sky.
    Image attribution tooltip
    Permission granted by Dan Zukowski
    Image attribution tooltip

    CISA furloughs will cut deep if government shuts down

    The agency will have to operate with a skeleton staff, which will reduce assessments and other programs for underserved critical infrastructure sectors and private industry partners.

    By Sept. 29, 2023
  • Brightly colored digital lock with central computer processor and futuristic circuit board.
    Image attribution tooltip
    da-kuk via Getty Images
    Image attribution tooltip

    Cisco routers abused by China-linked hackers against US, Japan companies

    A longstanding group, identified as BlackTech, uses custom malware to evade detection and hack into international subsidiaries of U.S. and Japanese firms.

    By Sept. 28, 2023
  • CISA Director Jen Easterly
    Image attribution tooltip

    Center for Strategic and International Studies

    Image attribution tooltip

    CISA rolls dice on public service campaign to raise cyber awareness

    The agency is hoping to get families and small businesses to adopt MFA, use stronger passwords and recognize phishing attacks.

    By Sept. 27, 2023
  • software, code, computer
    Image attribution tooltip

    Markus Spiske

    Image attribution tooltip

    CISA urges use of memory safe code in software development

    Unsafe programming languages, like C and C++, account for more than 70% of security vulnerabilities. 

    By Sept. 22, 2023
  • The CSC 2.0 report examines the progress made toward implementing the recommendations of the CSC, a congressionally mandated body that was designed to review the ability of the U.S. to deter maliciou
    Image attribution tooltip
    Permission granted by FDD
    Image attribution tooltip

    US is making headway on securing cyber infrastructure, commission says

    While Cyberspace Solarium Commission leaders praised U.S. cybersecurity improvements, they said more work is needed to secure critical infrastructure.

    By Sept. 20, 2023
  • FBI Director Chris Wray addresses the 2023 mWISE Conference from Mandiant.
    Image attribution tooltip
    Courtesy of Mandiant
    Image attribution tooltip

    FBI director urges private sector to work with the agency on cyber threats

    Christopher Wray told attendees at Mandiant’s mWISE 2023 private sector assistance contributed to the success of several recent operations.

    By Sept. 19, 2023
  • Cyber security  firewall interface protection concept. Businesswoman protecting herself from cyber attacks. Personal data security and banking
    Image attribution tooltip
    Getty Images via Getty Images
    Image attribution tooltip

    SEC cyber disclosure rules: What’s the role of the CIO?

    CIOs are on the front lines of managing the IT estate, making them a critical part of rapid incident response. 

    By Roberto Torres • Sept. 19, 2023
  • The United States Capitol Building seen at a distance.
    Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    6 stories on how SEC’s cyber rules are changing security response

    As enforcement of the rules takes effect later this year, themes around how and when businesses will disclose security incidents will emerge. 

    By Sept. 15, 2023
  • Anne Neuberger, deputy national security advisor for cyber and emerging technology, speaks at the White House.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    White House, federal cyber leaders pledge renewed support for open source security

    CISA released a roadmap for open source software security as industry officials convened to map out additional steps to protect federal agencies and the larger ecosystem.

    By Sept. 13, 2023
  • An exterior image of a the Bellagio hotel in Las Vegas
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    MGM Resorts discloses cyber incident in filing with SEC

    Moody’s Investors Service called the cyber incident credit negative, and MGM is still taking steps to protect data and fully secure business operations. 

    By Sept. 13, 2023
  • Anne Neuberger deputy national security advisor for cyber and emerging technologies, speaks at the Billington Cybersecurity Summit with Brad Medairy, EVP, Booz Allen.
    Image attribution tooltip
    Courtesy of Billington CyberSecurity Summit
    Image attribution tooltip

    White House mulls rating system to boost cybersecurity for critical infrastructure

    Anne Neuberger, deputy national security advisor for cyber, told the Billington Cybersecurity Summit that a new ransomware summit is set and updated a consumer labeling push for IoT.  

    By Sept. 11, 2023