Policy & Regulation


  • CISA Director Jen Easterly
    Image attribution tooltip

    Center for Strategic and International Studies

    Image attribution tooltip

    CISA director reiterates prior calls for C-suites, boards to take cyber risk ownership

    Jen Easterly said companies need to consider cybersecurity threats as core risks that need to be fully incorporated into corporate business strategy.

    By Jan. 10, 2025
  • Group of people working in a modern board room with augmented reality interface, all objects in the scene are 3D
    Image attribution tooltip
    piranka via Getty Images
    Image attribution tooltip

    4 cybersecurity trends to watch in 2025

    Critical industries are up against never before seen challenges to remain secure and operational, while regulatory pressures have completely upended the role of the CISO in corporate America.

    By , Jan. 9, 2025
  • Harry Coker Jr. speaking before the Foundation for the Defense of Democracies on Jan. 7, 2025.
    Image attribution tooltip
    Permission granted by Foundation for Defense of Democracies
    Image attribution tooltip

    National cyber director calls for deterrence against China-affiliated cyber threats

    Harry Coker Jr. said China and other adversaries cannot be allowed free reign to conduct malicious cyber activities.   

    By Jan. 9, 2025
  • Anne Neuberger deputy national security advisor for cyber and emerging technologies, speaks at the Billington Cybersecurity Summit with Brad Medairy, EVP, Booz Allen.
    Image attribution tooltip
    Courtesy of Billington CyberSecurity Summit
    Image attribution tooltip

    White House program to certify the security of IoT devices goes live

    The White House is also working on an executive order to limit federal purchasing of connected products that meet the minimum security standards under the program.

    By Jan. 8, 2025
  • FBI Director Chris Wray announces a major operation to disrupt a state-linked botnet, during a speech the Aspen Cyber Summit, Sept. 18, 2024.
    Image attribution tooltip
    Permission granted by Aspen Cyber Summit, Laurence Genon
    Image attribution tooltip

    US Treasury office sanctions firm connected to state-sponsored Flax Typhoon threat group

    A Beijing-based cybersecurity company, Integrity Technology Group Inc., is linked to years of exploitation activity targeting U.S. critical infrastructure.

    By Jan. 6, 2025
  • whistleblower program, Peirce, Uyeda, confidentiality
    Image attribution tooltip
    hapabapa via Getty Images
    Image attribution tooltip

    SEC cybersecurity enforcement outlook uncertain as Trump 2.0 looms

    With issues such as cryptocurrency and climate change facing the next SEC chair, it’s unclear whether rolling back cybersecurity rules will be high on the priority list.

    By Alexei Alexis • Jan. 3, 2025
  • 3D digital circular dynamic wave.
    Image attribution tooltip
    Vitalii Pasichnyk/Getty via Getty Images
    Image attribution tooltip

    White House says 9th telecom company hit in Salt Typhoon spree

    A senior official blamed the intrusions on lax security and said in one case the compromise of a single administrator account led to access of over 100,000 routers.

    By Dec. 27, 2024
  • gavel and money
    Image attribution tooltip
    Avosb via Getty Images
    Image attribution tooltip

    Flagstar fined $3.5M for ā€˜misleadingā€™ after 2021 cyberattack

    The bank “negligently made” materially misleading statements after a hack that resulted in the theft of 1.5 million customers’ personally identifiable information.

    By Gabrielle Saulsbery • Dec. 19, 2024
  • Person waits to enter Apple Store in San Francisco.
    Image attribution tooltip
    Justin Sullivan/Getty Images via Getty Images
    Image attribution tooltip

    CISA mobile security advice gets personal in wake of telecom intrusions

    The agency’s recommendations are not for the technically inept. Yet the extraordinary measures, including the use of encrypted apps, are applicable to all audiences.

    By Dec. 19, 2024
  • View of Rhode Island statehouse
    Image attribution tooltip
    sgoodwin4813 via Getty Images
    Image attribution tooltip

    Rhode Island officials warn residents as ransomware group threatens social services data leak

    The personal data of hundreds of thousands of vulnerable residents is at risk after a threat group attacked a state social services database.

    By Dec. 18, 2024
  • View of Microsoft store in NYC, July 2024
    Image attribution tooltip
    Adam Gray via Getty Images
    Image attribution tooltip

    CISA orders federal agencies to meet security baselines in Microsoft 365

    The mandate to secure cloud environments is responsive to recent cybersecurity incidents, but not one specific threat, agency officials said.

    By Updated Dec. 18, 2024
  • A facade of the U.S. Environmental Protection Agency signage on the wall of its building
    Image attribution tooltip
    Joe Cicak via Getty Images
    Image attribution tooltip

    Pennsylvania representative pitches bill to double cyber assistance for local water systems

    The proposed legislation comes amid a surge in ransomware and state-linked attacks against U.S. water utilities.

    By Dec. 17, 2024
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISAā€™s pre-ransomware alerts nearly doubled in 2024

    The federal agency’s efforts to improve defenses surged in fiscal year 2024. Yet, attacks continue to climb.

    By Dec. 17, 2024
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA, ONCD propose updated National Cyber Incident Response Plan

    The updated framework is designed to bolster the government’s partnership with private-sector organizations in the wake of an attack.

    By Dec. 16, 2024
  • Sen. Ron Wyden, D-Ore.
    Image attribution tooltip
    Drew Angerer/Getty Images via Getty Images
    Image attribution tooltip

    Sen. Wyden wants FCC to tighten security rules on telecom companies

    The U.S. senator from Oregon wants the agency to strengthen rules requiring network operators to defend their systems and customers against intrusions.

    By Dec. 13, 2024
  • Photo illustration of a VF Corp. SEC filing.
    Image attribution tooltip

    Photo illustration: Industry Dive; US Securities and Exchange Commission

    Image attribution tooltip

    SEC cyber incident reporting rule generates 71 filings in 11 months

    Most companies that disclosed cyber incidents to the agency did not describe materiality or other useful information, a BreachRx report found.

    By Dec. 11, 2024
  • Federal Communications Commission Commissioner Brendan Carr
    Image attribution tooltip
    Kevin Dietsch / Getty Images via Getty Images
    Image attribution tooltip

    Trumpā€™s pick to run FCC deeply concerned about Salt Typhoon

    The recently uncovered swarm of attacks on U.S. telecom companies, part of a China-sponsored campaign, made FCC Commissioner Brendan Carr want to smash his phone, he said.

    By Dec. 9, 2024
  • Federal Communications Commission Chair Jessica Rosenworcel
    Image attribution tooltip
    Chip Somodevilla/Getty Images via Getty Images
    Image attribution tooltip

    FCC proposes stronger telecom cyber rules as Salt Typhoon fallout continues

    The agency’s proposed rule changes come two months after a China-government sponsored espionage campaign first came to light.

    By Dec. 6, 2024
  • A skyline shot of a large city, bifurcated by a large river.
    Image attribution tooltip
    Alihan Usullu via Getty Images
    Image attribution tooltip

    UK cyber chief warns country is at an inflection point as digital threats rise

    In his first major speech, NCSC CEO Richard Horne said state linked and criminal threat groups are working to undermine the nation’s reliance on technology. 

    By Dec. 3, 2024
  • SEC regulation securities laws
    Image attribution tooltip
    Hapabapa via Getty Images
    Image attribution tooltip

    SEC reports drop in enforcement actions for 2024 FY

    The securities regulator also reported a record $8.2 billion in monetary remedies for its last fiscal year, driven by Terraform Labs crypto fraud settlement.

    By Justin Bachman • Nov. 26, 2024
  • exterior of the U.S. Department of Health and Human Services
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    HHS facing challenges as lead agency for healthcare cybersecurity: GAO

    The department hasn’t implemented some policies recommended by the watchdog, which could pose a risk to cybersecurity in the sector as attacks increase, according to the Government Accountability Office.

    By Emily Olsen • Nov. 20, 2024
  • Image attribution tooltip
    Win McNamee via Getty Images
    Image attribution tooltip

    Federal probe finds vulnerabilities across more than 300 US water systems

    The Environmental Protection Agency lacks a documented plan to coordinate incident reporting with CISA, the agency’s Office of Inspector General found.

    By Nov. 19, 2024
  • CISA Director Jen Easterly speaks at Carnegie Mellon University urging the tech industry to embrace secure-by-design product development.
    Image attribution tooltip
    Permission granted by Carnegie Mellon University
    Image attribution tooltip

    Easterly to step down from CISA director role on Inauguration Day

    CISA confirmed that political appointees of the Biden administration will also depart the agency as the Trump administration takes over.

    By Nov. 18, 2024
  • Two men in chairs on a stage hold microphones in front of a purple background with crowns and a SIPA logo
    Image attribution tooltip
    Permission granted by Office of the National Cyber Director
    Image attribution tooltip

    National cyber director calls for streamlined security regulations

    Harry Coker Jr. assured critical infrastructure and private sector stakeholders that while standards are necessary, there is a need to harmonize burdensome compliance demands. 

    By Nov. 14, 2024
  • U.S. President Joe Biden speaks at the 79th U.N., General Assembly.
    Image attribution tooltip
    Michael Santiago via Getty Images
    Image attribution tooltip

    US hopes to leverage UN cybercrime treaty toward ransomware fight

    The Biden administration decided to back the controversial accord, despite widespread concerns about potential human rights abuses.

    By Nov. 12, 2024