Eversheds Sutherland Cybersecurity and Privacy Insights Blog
content top

FCC Adopts Order Approving New Rules for ISPs

The Federal Communications Commission (“FCC”) has adopted new data privacy and security rules for internet service providers (“ISPs”). Under the new rules, ISPs must adopt “reasonable” data security and other measures, and obtain their customers’ explicit consent before using or sharing with third parties sensitive data. Sensitive data includes financial and health-related...

ISAO Standards Group Releases Guidelines for Information Sharing

Information and Sharing and Analysis Organizations, or ISAOs, can now look to four new publications for guidance in establishing ISAOs and in sharing cybersecurity information and interacting with the intelligence community, law enforcement agencies, U.S. regulatory agencies, and the Department of Homeland Security (DHS). The guidance documents include: ISAO 100-1, Introduction to...

CFTC Finalizes Rules on Cybersecurity Testing for Futures Industry

Under new rules adopted by the Commodity Futures Trading Commission (CFTC), various entities in the futures industry must undertake cybersecurity testing. At its open meeting on Sept. 8, 2016, the CFTC amended its system safeguards rules for exchanges, clearinghouses, and data repositories to require cybersecurity testing and system safeguards risk analysis. Under the amended rules,...

White House Cyber Commission Issues Requests for Information

The White House’s Commission on Enhancing National Cybersecurity has announced in a Federal Register Notice that it is seeking information on a variety of cybersecurity topics. The Notice indicates that the Commission is seeking information on topics including critical infrastructure cybersecurity, cyber insurance, research and development, the cyber workforce, federal governance,...

Federal Judge Dismisses Class Action Arising from Data Breach

A D.C. federal judge has dismissed a putative class action against CareFirst BlueCross BlueShield that arose from a 2014 data breach. The judge determined that the alleged injuries suffered by the seven named plaintiffs failed to establish standing to sue, finding that “merely having one’s personal information stolen in a data breach is insufficient to establish standing to sue the...

Cyber Storm V Highlights Need for Greater Info-sharing and Formalized Incident Response

Results from the Department of Homeland Security’s  (“DHS”) “Cyber Storm V” national exercise revealed that challenges remain around information and cyber threat indictor sharing, and that a plan for widespread cyber response would help improve response from government and industry to cyberattacks. Though the exercise showed that challenges remain, it also revealed an increased...

« Older Entries Next Entries »