Pub K
Cybersecurity Controls: What Do Regulators Expect Nowadays?

Alston & Bird – In recent years, U.S. state and federal regulators have increasingly emphasized, both through guidance and enforcement actions, cybersecurity controls that are more prescriptive and rigorous to reflect the evolving cyber-threat landscape and technological advancements. The days of regulators requiring companies to have basic security controls in place, such as antivirus software, a written information security program, annual security awareness training, and general updates to the board on the cybersecurity program, are long gone.