Policy & Regulation


  • A large sign reading "Black Hat" sits in the carpeted foyer of a convention center
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip

    US still prioritizing zero-trust migration to limit hacks’ damage

    The zero-trust initiative, which gained steam during the Biden administration, is still underway.

    By Aug. 6, 2025
  • Bob Ackerman, founder and managing director of AllegisCyber and DataTribe moderates a Black Hat panel Aug. 5, 2025. Marci McCarthy, director of public affairs at CISA; Rob Joyce, Data Tribe venture partner and former cybersecurity director at the NSA and Patrick Opet, CISO at JPMorgan Chase.
    Image attribution tooltip
    Permission granted by Kesserling Communications
    Image attribution tooltip

    CISA’s relationship with industry needs work to reestablish trust, experts say

    Critics say budget cuts, job losses have hurt the agency’s ability to coordinate with private industry.

    By Aug. 6, 2025
  • Sean Cairncross stands on a stage in front of two microphones
    Image attribution tooltip
    Riccardo Savi via Getty Images
    Image attribution tooltip

    Senate confirms Trump’s national cyber director nominee

    Sean Cairncross, a political veteran without significant cybersecurity experience, could turn the relatively new White House office into a major player in the administration.

    By Aug. 3, 2025
  • A sign that says Illumina is on a curb in front of red brick buildings.
    Image attribution tooltip
    Courtesy of Illumina
    Image attribution tooltip

    DOJ reaches $9.8 million settlement with Illumina over cyber whistleblower claims

    The U.S. alleged the company knowingly sold genetic-sequencing systems with software vulnerabilities to federal agencies.

    By Updated Aug. 1, 2025
  • Harrods is one of three UK-based retail companies responding to a spree of attacks beginning in April 2025.
    Image attribution tooltip
    Hollie Adams via Getty Images
    Image attribution tooltip

    FBI, CISA warn about Scattered Spider’s evolving tactics

    International authorities are pursuing the group following the arrests of four suspects in a series of attacks targeting British retailers.

    By July 29, 2025
  • Senators push CISA director nominee on election security, agency focus

    Sean Plankey said he would double down on CISA’s core mission and “allow the operators to operate.”

    By July 24, 2025
  • The White House in Washington, D.C.
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    Trump AI plan calls for cybersecurity assessments, threat info-sharing

    It remains unclear how federal agencies depleted by layoffs will be able to implement the strategy’s ambitious vision, which includes an ISAC dedicated to AI.

    By July 23, 2025
  • A security scanner extracts the code of a computer virus from a string of binary code (1s and 0s).
    Image attribution tooltip
    Hailshadow via Getty Images
    Image attribution tooltip

    Lapsed CISA contract impedes national lab’s threat-hunting operations

    The CyberSentry program remains operational, according to CISA, with analysts outside the lab continuing to review sensor data.

    By July 23, 2025
  • Aerial view of the Jack H. Wilson Water Treatment Plant in Little Rock, Arkansas.
    Image attribution tooltip
    Permission granted by Central Arkansas Water
    Image attribution tooltip
    Deep Dive

    Dwindling federal cyber support for critical infrastructure raises alarms

    A plan to transfer cybersecurity and resilience responsibilities to states could have major unintended consequences.

    By July 22, 2025
  • Microsoft, antitrust, Alaily, FTC. Google
    Image attribution tooltip
    David Ramos via Getty Images
    Image attribution tooltip

    Top US senator calls out supply-chain risk with DoD contractors

    The Senate Intelligence Committee chairman questioned the security of Microsoft’s “digital escort” arrangement with its Chinese employees.

    By Updated July 18, 2025
  • A sign reading "Department of State" sits outside the U.S. State Department headquarters in Washington, D.C.
    Image attribution tooltip
    Pacheco, Isaac. Retrieved from U.S. Department of State / Flickr.
    Image attribution tooltip

    State Department cyber diplomacy firings and changes threaten US defenses

    Departures and restructuring will make it harder for the agency to pursue global policies that strengthen U.S. critical infrastructure, experts said.

    By July 17, 2025
  • Harrods is one of three UK-based retail companies responding to a spree of attacks beginning in April 2025.
    Image attribution tooltip
    Hollie Adams via Getty Images
    Image attribution tooltip

    UK authorities arrest 4 people in probe of retail cyberattack spree

    The arrests mark the first major break in a case linked to the Scattered Spider cybercrime group, although additional work continues with multiple agencies.

    By Updated July 10, 2025
  • A general view of the Marks and Spencer flagship department store.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    M&S chairman calls for mandatory disclosure of material cyberattacks

    The chairman testified before British lawmakers following a major social-engineering attack on the department-store chain.

    By July 9, 2025
  • Symbolic of Sino-American relations, the flag of the United States of America and the flag of the Republic of China fly together on flag poles next to each other on a sunny, windy day.
    Image attribution tooltip
    Stock via Getty Images
    Image attribution tooltip

    Suspected contractor for China’s Hafnium group arrested in Italy

    U.S. authorities charged the man and a co-conspirator with hacking COVID-19 researchers and kicking off a cyberattack spree targeting Microsoft Exchange servers. 

    By July 8, 2025
  • Longworth Congressional Building
    Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    Security coalition urges Congress to renew 2015 CISA law

    A group of top cybersecurity and technology firms said the law provided critical protections for sharing essential vulnerability information.

    By July 8, 2025
  • SolarWinds
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by ismagilov via Getty Images
    Image attribution tooltip

    SEC seeks SolarWinds settlement in reversal for agency under new leadership

    The decision by the commission, now under Republican control, could reshape the landscape of corporate accountability for cyber incidents.

    By July 7, 2025
  • Sen Ron Wyden sits behind a wooden podium with a microphone.
    Image attribution tooltip
    Sarah Silbiger / Stringer via Getty Images
    Image attribution tooltip

    FBI cyber guidance to lawmakers falls short, US senator says

    Sen. Ron Wyden wants FBI briefings to cover four often-overlooked cybersecurity practices.

    By July 2, 2025
  • An American flag and a flag bearing the seal of the Cybersecurity and Infrastructure Security Agency (which features an eagle holding a shield with elements of a skyline on it) flank a large upright square panel bearing the same CISA seal. On the wall to the right of the panel and the flags, a row of digital clocks shows the time in the four major U.S. time zones.
    Image attribution tooltip
    Eric Geller/Cybersecurity Dive
    Image attribution tooltip
    Deep Dive

    ‘Suspended animation’: US government upheaval has frayed partnerships with critical infrastructure

    Recent federal cuts, reorganizations and other disruptions have alarmed industry leaders, who say the government is a less reliable partner even as cyber threats increase.

    By June 25, 2025
  • regenerative agriculture
    Image attribution tooltip
    Scott Olson via Getty Images
    Image attribution tooltip

    Federal officials, critical infrastructure leaders remain on guard for Iran-linked hacks

    Amid an uneasy truce, security teams in the U.S. said they have not seen any credible or specific threats.

    By June 24, 2025
  • piece of paper saying insurance policy
    Image attribution tooltip
    Mohamad Faizal Bin Ramli via Getty Images
    Image attribution tooltip

    Cyber insurance premiums drop for first time, report finds

    Despite a decline in both premiums and prices, the market continues to be profitable.

    By June 24, 2025
  • Chairman of the Joint Chiefs of Staff Air Force Gen. Dan Caine discusses the mission details of a strike on Iran during a news conference at the Pentagon on June 22, 2025 in Arlington, Virginia. U.S. President Donald Trump gave an address to the nation last night after three Iranian nuclear facilities were struck by the U.S. military.
    Image attribution tooltip
    Andrew Harnik via Getty Images
    Image attribution tooltip

    DHS warns of heightened cyber threat as US enters Iran conflict

    Federal officials are warning that pro-Iran hacktivists or state-linked actors may target poorly secured U.S. networks.

    By June 23, 2025
  • New cars J.D. Power
    Image attribution tooltip
    Shaunl via Getty Images
    Image attribution tooltip

    FTC reminds car dealers to protect customer data

    The commission described how recently updated federal regulations affect dealerships — and their vendors.

    By Updated June 17, 2025
  • SEC seal outside Washington D.C. building
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    SEC scraps proposed cybersecurity rules for investment advisers, market participants

    The commission offered no rationale for removing rules that would have imposed security requirements on financial services providers.

    By Updated June 16, 2025
  • software developers using computer to write code sitting at desk with multiple screens work remotely in home at night.
    Image attribution tooltip
    MTStock Studio via Getty Images
    Image attribution tooltip

    Software vulnerabilities pile up at government agencies, research finds

    A Veracode report reveals that government networks have accumulated years of unresolved security flaws, putting them at serious risk of exploitation.

    By June 12, 2025
  • President Donald Trump waves to a crowd at the White House on April 2, 2025.
    Image attribution tooltip
    Andrew Harnik via Getty Images
    Image attribution tooltip

    Trump scraps Biden software security, AI, post-quantum encryption efforts in new executive order

    The White House accused the Biden administration of trying to “sneak problematic and distracting issues into cybersecurity policy.” 

    By June 6, 2025