On May 3, 2022, the SEC announced that it was renaming the Division of Enforcement’s Cyber Unit as the Crypto Assets and Cyber Unit, and significantly increasing its size with the addition of 20 new positions.[1] In the
Cleary Cybersecurity and Privacy Watch
Global Legal Developments related to Cybersecurity Incidents, Cyber Corporate Governance and Regulation Issues, and Privacy and Data Protection Laws
Cleary Cybersecurity and Privacy Watch, published by Cleary Gottlieb Steen & Hamilton LLP, focuses on legal developments and regulatory issues related to cybersecurity, data privacy, and emerging technologies. The blog covers topics such as GDPR compliance, data breach liability, AI-related cyber threats, government enforcement actions, and evolving privacy laws. It also addresses the intersection of cybersecurity with corporate governance, international trade, and regulatory compliance. The blog provides analysis of court rulings, legislative initiatives, and enforcement trends affecting companies and legal practitioners navigating cybersecurity and privacy challenges.
Latest from Cleary Cybersecurity and Privacy Watch - Page 7
The SEC’s Climate Proposal – Top Points for Comment
The SEC published in March 2022 a dauntingly complex proposal to require public companies to provide climate-related disclosures.[1] The period for public comment on the proposal is very short, and it seems clear that a majority of the…
SEC Proposes New Disclosure Rules for Cybersecurity Incidents and Governance
Last month, the U.S. Securities and Exchange Commission issued a proposal to enhance and standardize disclosure requirements related to cybersecurity incident reporting and cybersecurity risk management, strategy, and governance. Among other changes, the SEC’s proposal would require disclosure about material…
Schrems III? The European Commission and U.S. Government Announce New Trans-Atlantic Data Privacy Framework
After nearly two years of detailed negotiations, on March 25, 2022, U.S. President Joe Biden and European Commission President Ursula von der Leyen announced an “agreement in principle” on a new Trans-Atlantic Data Privacy Framework (the “Framework”) to re-establish an…
Businesses Buzzing With News of Utah’s New Comprehensive Privacy Law
Cyber Incident Reporting for Critical Infrastructure Act Signed Into Law
On March 15, 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022, which imposes federal reporting requirements for cyber incidents and ransomware attack payments. The legislation will require covered critical infrastructure entities…
U.S. Senate Fast Tracks Major Cybersecurity Legislation in Response to Russia Threat
On March 1, 2022, the U.S. Senate passed by unanimous consent a package of three cybersecurity bills, known collectively as the Strengthening American Cybersecurity Act, which would enhance reporting requirements for certain major cyber incidents and ransomware attacks. Senators Gary…
SEC Takes Aim at Crypto Lending in BlockFi Settlement; Calls on Market to “Come into Compliance”: Is Regulatory Clarity Coming Soon?
The SEC and a consortium of 32 states recently announced a $100 million settlement with BlockFi Lending LLC over its crypto lending product, BlockFi Interest Accounts. The SEC alleged BlockFi had violated the securities laws by failing to register its…
Developments at Justice: The Deputy Attorney General Talks Cybersecurity and the National Cryptocurrency Enforcement Team Gets its First Director
February 17, 2022 was a busy day for the Department of Justice and its growing cyber portfolio. First, Deputy Attorney General Lisa O. Monaco delivered remarks at the Annual Munich Cyber Security Conference, stressing the Department’s efforts to confront cyber…
SEC Chair Previews Ramp Up in Regulation and Enforcement in the Cybersecurity Context
On January 24, 2022, Securities and Exchange Commission Chair Gary Gensler gave a speech at the Northwestern Pritzker School of Law’s Annual Securities Regulation Institute signaling the SEC’s intention to step up its cyber-related regulatory and enforcement efforts. Gensler described…