
Articles

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.
Proposed “Cyber Incident Reporting for Critical Infrastructure Act of 2021”
The CMMC is Here to Stay, But Has Room for Improvement
Don’t Fixate on CMMC Maturity Level: Start With Foundational Best Practices
Double Time – NIST Seeks Comments on Major Revision to Practices for Developing Cyber-Resilient Systems (SP 800-160) and Assessing Security and Privacy Controls in Information Systems and Organizations (SP 800-53A)
The Journey Has Just Begun: China Passes its Personal Information Protection Law
Senators Introduce Bipartisan Legislation To Require Federal Contractors and Operators of Critical Infrastructure to Disclose Cyber Intrusions
Don’t Overlook IT Governance
Recent SEC Enforcement Activity Highlights Issuers’ Cybersecurity Disclosure Obligations and Pitfalls
T-Mobile Clarifies Facts of Security Incident in Press Release
The SEC’s Latest Salvo on Cybersecurity Disclosures: A $1 Million Penalty and Cease & Desist Order
China’s New Data Privacy Law is Sweeping and Serious: Avoid the High Cost of Noncompliance
EDPB Reports on EU Data Protection Authorities’ Resources and Enforcement Actions
Analyzing China’s PIPL and How It Compares to the EU’s GDPR
Personal Information Protection Law: China’s GDPR Is Coming
SEC Lessons Learned: Public Companies Must Accurately Disclose Material Cyber Breaches to Investors
China’s Personal Information Protection Law
A Timely Appraisal of China’s Critical Information Infrastructure Protection Regime
OSFI Issues Stricter Reporting Requirements for Technology and Cybersecurity Incidents
SEC Is Still Cyber Serious About Disclosures
Keep reading


