• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Kelly Hagedorn

Avatar photo

About Kelly Hagedorn

Kelly leverages her significant enforcement background to help clients mitigate risk under UK and EU data protection laws and support global clients on regulatory issues involving data privacy regulation and litigation.

[Read Bio]

Secure Connectivity for Operational Technology—UK NCSC Publishes New Guidance

April 21, 2026 By Hanna Hewitt, Kelly Hagedorn and Paul Greaves

The UK National Cyber Security Centre (NCSC) published guidance to help organisations design, secure, and manage Operational Technology (OT) environments. It sets out eight core principles to improve resilience, reduce exposure, and support secure architectural decision‑making. The NCSC positions these as goals rather than minimum requirements, and operators of essential services (including those within scope […]

Filed Under: AI Cybersecurity & Privacy, Board Governance & Cyber Risk Management, European Privacy & Cybersecurity Tagged With: Cybersecurity, National Cyber Security Centre, UK Cybersecurity

Britain’s Financial Regulators Raise the Bar on Cyber Reporting and Resilience

April 20, 2026 By Kelly Hagedorn and Kristen Bartolotta

Cyber risk has shifted from a technical issue to a systemic one and Britain’s financial regulators are making that reality unmistakably clear. On March 18, 2026, the Financial Conduct Authority (FCA), Prudential Regulation Authority (PRA), and Bank of England announced a new, unified cyber and operational resilience framework that strengthens the requirements on how firms […]

Filed Under: Crisis & Data Breach Response, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Data Breach Notification, Data Protection, EU Data Protection, UK data protection

European Commission Publishes Guidance For Companies Implementing the EU Cyber Resilience Act

January 29, 2026 By Paul Greaves, Kelly Hagedorn and Wim Nauwelaerts

On December 3, 2025, the European Commission published its first set of technical FAQs on the EU Cyber Resilience Act (‘CRA’). The CRA is an EU-wide law which lays down cybersecurity requirements for ‘products with digital elements’ (‘PDEs’), including IoT devices, hardware components, and certain software.  It becomes fully applicable on December 11, 2027, with […]

Filed Under: Board Governance & Cyber Risk Management, European Privacy & Cybersecurity, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, EU Privacy, EU Regulation

New EU Regulation Clarifies Cybersecurity Rules for IoT Devices and Other ‘Products with Digital Elements’

December 10, 2025 By Paul Greaves, Wim Nauwelaerts and Kelly Hagedorn

On November 28 2025, the European Commission adopted a regulation implementing the Cyber Resilience Act (‘CRA’) – an EU-wide law which lays down cybersecurity requirements for companies that design and sell ‘products with digital elements’. PDEs can take many forms including IoT devices, hardware components, and certain software. The CRA imposes cybersecurity obligations in connection […]

Filed Under: Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, EU Regulation, European Union (EU)

UK Cybersecurity Legislation Soon to be Introduced

November 21, 2025 By Hanna Hewitt and Kelly Hagedorn

The UK Government has introduced the Cyber Security and Resilience (Network and Information Systems) Bill (the “Bill”) to Parliament, marking the most significant update to the UK’s cyber legislation since 2018. You can access a copy of the Bill here. The Bill aims to strengthen national security and protect critical infrastructure networks in key sectors […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, European Privacy & Cybersecurity Tagged With: Cybersecurity, National Security, UK, UK Cybersecurity

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 5
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • The World Data Organization: A New Player in Global Data Governance – What Businesses Need to Know
  • Secure Connectivity for Operational Technology—UK NCSC Publishes New Guidance
  • Britain’s Financial Regulators Raise the Bar on Cyber Reporting and Resilience
  • New York AI Disclosure Bill Passes State Legislature
  • Cybercrime Trends to Watch: Takeaways from the FBI’s 2025 IC3 Annual Report
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.