Policy & Regulation


  • gavel and money
    Image attribution tooltip
    Avosb via Getty Images
    Image attribution tooltip

    Flagstar fined $3.5M for ‘misleading’ after 2021 cyberattack

    The bank “negligently made” materially misleading statements after a hack that resulted in the theft of 1.5 million customers’ personally identifiable information.

    By Gabrielle Saulsbery • Dec. 19, 2024
  • Person waits to enter Apple Store in San Francisco.
    Image attribution tooltip
    Justin Sullivan/Getty Images via Getty Images
    Image attribution tooltip

    CISA mobile security advice gets personal in wake of telecom intrusions

    The agency’s recommendations are not for the technically inept. Yet the extraordinary measures, including the use of encrypted apps, are applicable to all audiences.

    By Dec. 19, 2024
  • View of Rhode Island statehouse
    Image attribution tooltip
    sgoodwin4813 via Getty Images
    Image attribution tooltip

    Rhode Island officials warn residents as ransomware group threatens social services data leak

    The personal data of hundreds of thousands of vulnerable residents is at risk after a threat group attacked a state social services database.

    By Dec. 18, 2024
  • View of Microsoft store in NYC, July 2024
    Image attribution tooltip
    Adam Gray via Getty Images
    Image attribution tooltip

    CISA orders federal agencies to meet security baselines in Microsoft 365

    The mandate to secure cloud environments is responsive to recent cybersecurity incidents, but not one specific threat, agency officials said.

    By Updated Dec. 18, 2024
  • A facade of the U.S. Environmental Protection Agency signage on the wall of its building
    Image attribution tooltip
    Joe Cicak via Getty Images
    Image attribution tooltip

    Pennsylvania representative pitches bill to double cyber assistance for local water systems

    The proposed legislation comes amid a surge in ransomware and state-linked attacks against U.S. water utilities.

    By Dec. 17, 2024
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA’s pre-ransomware alerts nearly doubled in 2024

    The federal agency’s efforts to improve defenses surged in fiscal year 2024. Yet, attacks continue to climb.

    By Dec. 17, 2024
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA, ONCD propose updated National Cyber Incident Response Plan

    The updated framework is designed to bolster the government’s partnership with private-sector organizations in the wake of an attack.

    By Dec. 16, 2024
  • Sen. Ron Wyden, D-Ore.
    Image attribution tooltip
    Drew Angerer/Getty Images via Getty Images
    Image attribution tooltip

    Sen. Wyden wants FCC to tighten security rules on telecom companies

    The U.S. senator from Oregon wants the agency to strengthen rules requiring network operators to defend their systems and customers against intrusions.

    By Dec. 13, 2024
  • Photo illustration of a VF Corp. SEC filing.
    Image attribution tooltip

    Photo illustration: Industry Dive; US Securities and Exchange Commission

    Image attribution tooltip

    SEC cyber incident reporting rule generates 71 filings in 11 months

    Most companies that disclosed cyber incidents to the agency did not describe materiality or other useful information, a BreachRx report found.

    By Dec. 11, 2024
  • Federal Communications Commission Commissioner Brendan Carr
    Image attribution tooltip
    Kevin Dietsch / Getty Images via Getty Images
    Image attribution tooltip

    Trump’s pick to run FCC deeply concerned about Salt Typhoon

    The recently uncovered swarm of attacks on U.S. telecom companies, part of a China-sponsored campaign, made FCC Commissioner Brendan Carr want to smash his phone, he said.

    By Dec. 9, 2024
  • Federal Communications Commission Chair Jessica Rosenworcel
    Image attribution tooltip
    Chip Somodevilla/Getty Images via Getty Images
    Image attribution tooltip

    FCC proposes stronger telecom cyber rules as Salt Typhoon fallout continues

    The agency’s proposed rule changes come two months after a China-government sponsored espionage campaign first came to light.

    By Dec. 6, 2024
  • A skyline shot of a large city, bifurcated by a large river.
    Image attribution tooltip
    Alihan Usullu via Getty Images
    Image attribution tooltip

    UK cyber chief warns country is at an inflection point as digital threats rise

    In his first major speech, NCSC CEO Richard Horne said state linked and criminal threat groups are working to undermine the nation’s reliance on technology. 

    By Dec. 3, 2024
  • SEC regulation securities laws
    Image attribution tooltip
    Hapabapa via Getty Images
    Image attribution tooltip

    SEC reports drop in enforcement actions for 2024 FY

    The securities regulator also reported a record $8.2 billion in monetary remedies for its last fiscal year, driven by Terraform Labs crypto fraud settlement.

    By Justin Bachman • Nov. 26, 2024
  • exterior of the U.S. Department of Health and Human Services
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    HHS facing challenges as lead agency for healthcare cybersecurity: GAO

    The department hasn’t implemented some policies recommended by the watchdog, which could pose a risk to cybersecurity in the sector as attacks increase, according to the Government Accountability Office.

    By Emily Olsen • Nov. 20, 2024
  • Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    Federal probe finds vulnerabilities across more than 300 US water systems

    The Environmental Protection Agency lacks a documented plan to coordinate incident reporting with CISA, the agency’s Office of Inspector General found.

    By Nov. 19, 2024
  • CISA Director Jen Easterly speaks at Carnegie Mellon University urging the tech industry to embrace secure-by-design product development.
    Image attribution tooltip
    Permission granted by Carnegie Mellon University
    Image attribution tooltip

    Easterly to step down from CISA director role on Inauguration Day

    CISA confirmed that political appointees of the Biden administration will also depart the agency as the Trump administration takes over.

    By Nov. 18, 2024
  • Two men in chairs on a stage hold microphones in front of a purple background with crowns and a SIPA logo
    Image attribution tooltip
    Permission granted by Office of the National Cyber Director
    Image attribution tooltip

    National cyber director calls for streamlined security regulations

    Harry Coker Jr. assured critical infrastructure and private sector stakeholders that while standards are necessary, there is a need to harmonize burdensome compliance demands. 

    By Nov. 14, 2024
  • U.S. President Joe Biden speaks at the 79th U.N., General Assembly.
    Image attribution tooltip
    Michael Santiago via Getty Images
    Image attribution tooltip

    US hopes to leverage UN cybercrime treaty toward ransomware fight

    The Biden administration decided to back the controversial accord, despite widespread concerns about potential human rights abuses.

    By Nov. 12, 2024
  • Amtrak Coast Starlight Train
    Image attribution tooltip
    Laser1987 via Getty Images
    Image attribution tooltip

    TSA proposes cyber risk management programs for surface transportation, pipeline operators

    The proposed rule would also require the disclosure of cyber incidents to CISA and physical security concerns to TSA.

    By Nov. 7, 2024
  • Donald Trump in business attire stands in a stage with an U.S. flag in the background
    Image attribution tooltip
    Anna Moneymaker/Staff via Getty Images
    Image attribution tooltip

    4 tech issues to watch in Trump’s second term

    AI, cloud and cybersecurity policies are in the spotlight ahead of the forthcoming Trump administration.

    By Roberto Torres • Nov. 7, 2024
  • National Cyber Director Harry Coker Jr. delivers keynote on the national cybersecurity strategy implementation plan on May 22, 2024 at the McCrary Institute at Auburn University in Washington D.C.
    Image attribution tooltip
    Permission granted by McCrary Institute
    Image attribution tooltip

    USDA, White House launch study to boost cyber resilience of rural water utilities

    A yearlong program with the National Rural Water Association will provide technical assistance to water utilities led by Vermont and Oregon officials.

    By Nov. 4, 2024
  • John Pearce of Grant Thornton speaking during a CFO Dive panel
    Image attribution tooltip
    CIO Dive CFO Dive Panel/Cybersecurity Dive
    Image attribution tooltip

    SEC cyber rules could survive regardless of election outcome, experts say

    As the U.S. presidential election looms, cybersecurity remains a bipartisan focus, experts said during a joint CFO Dive and CIO Dive live event.

    By Grace Noto • Nov. 4, 2024
  • A photo illustration of Kamala Harris and Donald Trump shoulder to shoulder facing away from each other. The background is a purple wave with a grid gradient.
    Image attribution tooltip

    Photo illustration: Industry Dive; Joe Readle/Getty Images; Brandon Bell/Getty Images

    Image attribution tooltip

    As presidential election looms, disparate approaches to cyber policy come into focus

    Government officials and security leaders are hoping the nation’s need for cyber resilience will stand on bipartisan cooperation and transcend partisan politics regardless of the election results. 

    By Oct. 31, 2024
  • A man and a woman shake hands in front of a desk that has flags from the U.S. and Ukraine. The people are in front of a blue background with CISA logos.
    Image attribution tooltip
    Retrieved from Jen Easterly/CISA.
    Image attribution tooltip

    CISA rolls out international strategic plan to bolster cyber cooperation

    The agency is looking to strengthen intel sharing with key cyber partners, raise security standards and ensure a more resilient global supply chain. 

    By Oct. 30, 2024
  • People watch the presidential debate during a debate watch party at Penn Social on Sept. 10, 2024, in Washington
    Image attribution tooltip
    Alex Wong / Getty Images News via Getty Images
    Image attribution tooltip

    Cyber task force has a long to-do list for next president

    The change in leadership presents an opportunity to assess what’s working, where adjustments could be made and areas that are in most need of prioritization, the McCrary Institute said.

    By Oct. 29, 2024