• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Kim Peretti

Avatar photo

About Kim Peretti

A former DOJ cybercrime prosecutor and former director of PwC's cyber forensics group, Kim delivers top of the line cyber risk management and information security counsel to her clients. As co-leader of our Privacy, Cyber & Data Strategy Team, Kim is recognized by select publications and is frequently quoted by the media.

[Read Bio]

DOJ Cybersecurity Enforcement Pace Shows No Signs of Slowing Down Going Into 2026

January 20, 2026 By Kim Peretti, Andrew Liebler, Lance Taubin and Andrew Rice

As 2025 drew to a close, the United States Department of Justice (DOJ) announced significant developments in cases relating to the allegedly deficient cybersecurity practices of two Department of Defense (DoD) contractors. These two cases suggest that the federal government will continue to make DFARS 7012 compliance for companies that process Controlled Unclassified Information (CUI) […]

Filed Under: National Security & Digital Crimes, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Defense Federal Acquisition Regulation Supplement (DFARS), Department of Defense, FCA

NYDFS Releases New Prescriptive FAQs on MFA

December 22, 2025 By Kim Peretti, Kate Hanniford, Lance Taubin and Carson Kuck

The New York Department of Financial Services (NYDFS) has released a new set of Frequently Asked Questions (FAQs 18–23) under 23 NYCRR Part 500, reinforcing its position that multifactor authentication (MFA) remains a critical component of a covered entity’s cybersecurity program. These FAQs provide highly prescriptive guidance, including clarifications on technical requirements for the “possession” […]

Filed Under: Privacy & Cyber Regulatory Enforcement

Key Breach Notification Updates in California and Oklahoma for 2026

October 24, 2025 By Kim Peretti and Alysa Austin

Effective January 1, 2026, new legislation in California and Oklahoma will introduce important updates to each state’s breach notification requirements. These changes may significantly impact breach response obligations for businesses operating in or handling data related to residents of these states. Below is a summary of the key provisions under each law. California – Senate […]

Filed Under: Board Governance & Cyber Risk Management, California Privacy & the CCPA, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement Tagged With: California, Data Breach Notification, Oklahoma, US State Law

Government Shutdown Creates Lapse in Cyber Threat Information Sharing

October 23, 2025 By Kim Peretti and Scott Hilsen

The day before the recent federal government shutdown, a ten-year old cybersecurity law expired before it could be reauthorized. The Cybersecurity Information Sharing Act of 2015 (“CISA”) provided a mechanism for private companies to share information with the federal government about cyber threats in return for certain legal protections. CISA applied only when the information […]

Filed Under: Uncategorized

United States, International Coalition Issue Joint Warning of Increasing PRC Backed Threat Activity

September 10, 2025 By Kim Peretti, Lance Taubin and Andrew Rice

On August 27, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the United States Department of Defense Cyber Crime Center (DC3) issued a joint advisory (Advisory) highlighting increased cyber threat activity linked to People’s Republic of China (PRC) affiliated threat […]

Filed Under: Board Governance & Cyber Risk Management, National Security & Digital Crimes Tagged With: China, CISA, Cybercrime, Cybersecurity, Department of Defense, Federal Bureau of Investigation (FBI), International

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 24
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • DOJ Cybersecurity Enforcement Pace Shows No Signs of Slowing Down Going Into 2026
  • Spanish DPA Highlights Privacy Risks in GenAI Content Creation
  • Texas Court Blocks Smart TV Data Collection
  • NYDFS Releases New Prescriptive FAQs on MFA
  • How to Comply with the EU AI Act: Guidance from the Spanish AI Regulator
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.
This website uses cookies to improve functionality and performance. By continuing to browse this site, you are consenting to the use of cookies on this website.