Policy & Regulation: Page 5


  • Cyber security  firewall interface protection concept. Businesswoman protecting herself from cyber attacks. Personal data security and banking
    Image attribution tooltip
    Getty Images via Getty Images
    Image attribution tooltip

    SEC cyber disclosure rules: What’s the role of the CIO?

    CIOs are on the front lines of managing the IT estate, making them a critical part of rapid incident response. 

    By Roberto Torres • Sept. 19, 2023
  • The United States Capitol Building seen at a distance.
    Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    6 stories on how SEC’s cyber rules are changing security response

    As enforcement of the rules takes effect later this year, themes around how and when businesses will disclose security incidents will emerge. 

    By Sept. 15, 2023
  • Anne Neuberger, deputy national security advisor for cyber and emerging technology, speaks at the White House.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    White House, federal cyber leaders pledge renewed support for open source security

    CISA released a roadmap for open source software security as industry officials convened to map out additional steps to protect federal agencies and the larger ecosystem.

    By Sept. 13, 2023
  • An exterior image of a the Bellagio hotel in Las Vegas
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    MGM Resorts discloses cyber incident in filing with SEC

    Moody’s Investors Service called the cyber incident credit negative, and MGM is still taking steps to protect data and fully secure business operations. 

    By Sept. 13, 2023
  • Anne Neuberger deputy national security advisor for cyber and emerging technologies, speaks at the Billington Cybersecurity Summit with Brad Medairy, EVP, Booz Allen.
    Image attribution tooltip
    Courtesy of Billington CyberSecurity Summit
    Image attribution tooltip

    White House mulls rating system to boost cybersecurity for critical infrastructure

    Anne Neuberger, deputy national security advisor for cyber, told the Billington Cybersecurity Summit that a new ransomware summit is set and updated a consumer labeling push for IoT.  

    By Sept. 11, 2023
  • Jen Easterly speaks during a fireside chat at the Billington Cybersecurity Summit.
    Image attribution tooltip
    Courtesy of Billington
    Image attribution tooltip

    CISA director: Critical infrastructure cyber incident reporting rules almost ready

    The Cybersecurity and Infrastructure Security Agency is in the final stages of work on the reporting requirements included in a March 2022 law.

    By Sept. 8, 2023
  • Acting National Cyber Director Kemba Walden speaks during the Billington Cybersecurity Summit on Sept. 5, 2023 in Washington, D.C.
    Image attribution tooltip
    Permission granted by ZeroFox
    Image attribution tooltip

    Cybersecurity investments boost profitability, resilience: White House

    Expenditures on resilience will help companies reduce downtime, Acting National Cyber Director Kemba Walden said at the Billington Cybersecurity Summit.

    By Sept. 6, 2023
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA creates voluntary ed tech pledge to boost K-12 cybersecurity

    Companies signing the agreement are urged to commit to encouraging the use of multifactor authentication and public vulnerability disclosure.

    By Anna Merod • Sept. 6, 2023
  • Close up of Gary Gensler speaking during a senate hearing
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    SEC cyber disclosure rules put CISO liability under the spotlight

    Security executives find themselves in the eye of the needle as governance and incident response come into focus.

    By Sept. 5, 2023
  • The New York Stock Exchange building.
    Image attribution tooltip
    Spencer Platt via Getty Images
    Image attribution tooltip

    SEC cyber disclosure rules are taking effect: Here’s what to expect

    With enforcement on the horizon, much of the SEC's rules for material disclosures are subject to interpretation.

    By Aug. 31, 2023
  • An image of Federal Bureau of Investigation Director Christopher Wray at a press conference.
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    US leads takedown of Qakbot malware, which automated initial infections

    The botnet and malware had infected more than 700,000 computers worldwide and was linked to the abuse of OneNote files.

    By Aug. 30, 2023
  • Close-up Focus on Person's Hands Typing on the Desktop Computer Keyboard
    Image attribution tooltip
    gorodenkoff via Getty Images
    Image attribution tooltip

    Software industry urged to assume risk on open source security

    The Open Source Security Foundation called on commercial and non-commercial organizations that use open source software components to adopt better security practices.

    By Aug. 25, 2023
  • A textbox with five stars blocking out a word and a lock to simulate password protection.
    Image attribution tooltip
    kaedeezign via Getty Images
    Image attribution tooltip
    Opinion

    Government investigation puts spotlight on password insecurity

    A team working for the Department of Interior’s inspector general successfully cracked 1 in 5 active user passwords, a ratio that highlights traps in cybersecurity standards, Mike Kosask from LastPass writes.

    By Michael Kosak • Aug. 24, 2023
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    Cyber authorities have a plan to defend remote monitoring tools

    Threat actors can turn one point of attack into many by targeting remote management services that lack security controls.

    By Aug. 18, 2023
  • A sunlit New York Stock Exchanges is seen with 6 columns and 3 American flags with people walking by in shadow.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    SEC cyber rules ignite tension between reputation and security risk

    The rules, which take effect Sept. 5, encountered mixed reactions. Some champion board-level cyber accountability. Others say the rules are too big of a lift.

    By Aug. 15, 2023
  • Close up of Gary Gensler speaking during a senate hearing
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    Chamber of Commerce urges SEC to delay cyber rule implementation

    The SEC has “chosen speed over accuracy” while ignoring important business community concerns in pushing out the new regulations, the U.S. Chamber of Commerce says.

    By Alexei Alexis • Aug. 15, 2023
  • Dark servers data center room with computers and storage systems.
    Image attribution tooltip
    sdecoret via Getty Images
    Image attribution tooltip

    Microsoft, cloud security under the microscope with federal cyber review

    The federal Cyber Safety Review Board will examine issues related to the state-linked hack of Microsoft Exchange and larger concerns tied to identity management and authentication.

    By Aug. 14, 2023
  • The LG widescreen display in the Mercedes-Benz EQS electric sedan.
    Image attribution tooltip
    Courtesy of LG Electronics
    Image attribution tooltip

    Automotive data privacy under scrutiny in California

    The California Privacy Protection Agency’s enforcement division is examining how automakers handle data collected from internet-connected vehicles.

    By Michael Brady • Aug. 14, 2023
  • Acting National Cyber Director Kemba Walden speaking at Black Hat 2023.
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Why Walden thinks this national cybersecurity strategy will work

    The acting national cyber director, armed with more talent at the federal level and an implementation plan, is striving for lasting impact.

    By Aug. 11, 2023
  • CISA Director Jen Easterly speaks at Carnegie Mellon University urging the tech industry to embrace secure-by-design product development.
    Image attribution tooltip
    Permission granted by Carnegie Mellon University
    Image attribution tooltip

    White House wants input on open source security, memory-safe languages

    Federal agencies put out a request for information Thursday, building on Biden administration priorities to help secure open source post-Log4j.

    By Aug. 11, 2023
  • three adults stand on a stage in front of a yellow curtain. One adult is standing at a podium and speaking.
    Image attribution tooltip
    Kara Arundel/Cybersecurity Dive, data from White House
    Image attribution tooltip

    3 best practices from the White House K-12 cybersecurity summit

    School leaders must take prevention seriously and know who to call when an attack happens, government officials and educators said.

    By Kara Arundel • Aug. 11, 2023
  • Woman in a black suit stands behind a podium with a sign that reads "enhancing cybersecurity protecting New Yorkers."
    Image attribution tooltip
    Courtesy of Darren McGee/ Office of Governor Kathy Hochul
    Image attribution tooltip

    New York rolls out statewide cybersecurity strategy

    The strategy follows previous steps to enhance local cybersecurity and protect critical infrastructure across the state.

    By Aug. 10, 2023
  • U.S. President Joe Biden waves toward visitors watching the departure as he walks to Marine One on the South Lawn of the White House July 28, 2023 in Washington, DC.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    White House launches AI cyber competition to fix software vulnerabilities

    In partnership with OpenAI, Anthropic, Google and Microsoft, participants will have access to top AI companies’ technology for designing new cybersecurity solutions.

    By Lindsey Wilkinson • Aug. 9, 2023
  • The United States Capitol Building seen at a distance.
    Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    NIST releases draft overhaul of its core cybersecurity framework

    It marks the first major update to federal risk guidance since 2014 and incorporates new issues, including supply chain security and threats to small business.

    By Aug. 9, 2023
  • AWS logo on display at AWS Summit New York, July 26, 2023.
    Image attribution tooltip
    Courtesy of AWS
    Image attribution tooltip

    AWS pledges $20M to K-12 cyber training, incident response

    The cloud services provider is participating in a broad White House plan to build additional protection to defend schools against ransomware and other threats.

    By Aug. 7, 2023