Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Round-Up: Proscriptive ICTS Supply Chain Regulation as a Means of Addressing Cyber Risk

By Angela Giancarlo, Justin Herring, Adam Hickey, Timothy J. Keeler, Stephen Lilley, Marcia Madsen, Tamer A. Soliman, Howard W. Waltzman & Lauren Williams on October 18, 2023
Email this postTweet this postLike this postShare this post on LinkedIn

Cybersecurity Awareness Month is a good time to highlight one trend in federal efforts to address cyber risk: proscriptive regulation of the information and communications technology and services (“ICTS”) supply chain.

Supply chain risk management is a broad field encompassing, among other things, federal efforts to improve software security, and proposals to revise the FAR to standardize cybersecurity and incident reporting requirements for US government contractors. This Legal Update concerns a different trend toward restricting use of equipment and services with ties to jurisdictions viewed as high-risk by the US government. That regulatory impulse has implications for buyers and sellers alike: it signals the salience of the issue from a cybersecurity standpoint, it leads to limitations on what companies in the United States can purchase, and it may encourage the development of so-called “trusted markets” in other jurisdictions. Here, we outline the origin of those authorities and provide the current status on how they have been deployed so far, according to public information.

Continue reading.

Photo of Stephen Lilley Stephen Lilley

Stephen Lilley is a partner in the Washington DC office of Mayer Brown. He focuses his practice on helping clients navigate cutting-edge and interrelated litigation, regulatory, and policy challenges. A member of the firm’s Litigation and Cybersecurity & Data Privacy practices, Stephen develops…

Stephen Lilley is a partner in the Washington DC office of Mayer Brown. He focuses his practice on helping clients navigate cutting-edge and interrelated litigation, regulatory, and policy challenges. A member of the firm’s Litigation and Cybersecurity & Data Privacy practices, Stephen develops strategies to manage legal risks and to shape regulatory policy across a broad range of substantive areas.

Stephen has significant experience working with clients to identify, evaluate, and manage cybersecurity and data privacy risks; responding to cyber incidents and vulnerability disclosures; and defending businesses in related litigation. Stephen is regularly called upon to advise senior executives and board members on their most challenging cybersecurity risks, to help companies develop governance programs to mitigate those risks, and to lead training exercises to implement and refine those programs. Stephen has particular experience advising on cybersecurity and national security issues relating to the Internet of Things, including vehicles and medical devices, and to manufacturing, critical infrastructure, and other industrial systems. Widely recognized for his cybersecurity law and policy experience, Stephen previously served as Chief Counsel to the Senate Judiciary Committee’s Subcommittee on Crime and Terrorism, where he focused on cybersecurity issues.

Read Stephen’s full bio.

Read more about Stephen LilleyEmail
Show more Show less
Photo of Marcia Madsen Marcia Madsen

Marcia focuses on Government Contracts and Litigation, advising clients on contract formation, teaming and strategic alliances, contract and subcontract negotiations, performance disputes, audits, terminations, cost accounting and allowability, technical data rights and trade secrets, and fraud/false claims investigations • litigates bid protests and…

Marcia focuses on Government Contracts and Litigation, advising clients on contract formation, teaming and strategic alliances, contract and subcontract negotiations, performance disputes, audits, terminations, cost accounting and allowability, technical data rights and trade secrets, and fraud/false claims investigations • litigates bid protests and claims and disputes before the GAO, the Boards of Contract Appeals, the Court of Federal Claims, and various other federal and state courts • has handled numerous ADR and mediation proceedings • areas of concentration include aerospace and defense contracts, systems integration, information systems and telecommunications contracts, health care and bio-technology, homeland security contracts, environmental remediation, and research and development contracts.

Read Marcia’s full bio.

Read more about Marcia MadsenEmail
Show more Show less
  • Posted in:
    Technology and AI
  • Blog:
    Inside Cybersecurity & Privacy Law
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo