The Department of Defense (“DOD”) has announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were scheduled to take effect on November 10, 2026. This announcement is significant because, as we noted in our prior advisory, Phase II was expected to move CMMC toward more formal assessment requirements for […]
Five Eyes Issues Urgent Call to Action on AI-Driven Cyber Threats
On June 22, 2026, the intelligence alliance known as Five Eyes released a statement warning that frontier AI models will fundamentally transform offensive and defensive cyber capabilities, and that the timeline for this transformation is measured in months, not years. Five Eyes is an intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and […]
DOJ Settles False Claims Act Case with LOGZONE Over Cybersecurity Deficiencies
On June 18, 2026, the United States Department of Justice (DOJ) announced that it had reached a settlement with defense contractor LOGZONE, Inc. (LOGZONE) in which the company agreed to pay $507,144 to resolve its liability under the False Claims Act (FCA) for allegedly failing to comply with cybersecurity requirements. LOGZONE provides logistics, medical, training, […]
NYDFS Issues Frontier AI Advisory and Guidance for Heightened Cyber Threat Environment
On May 21, 2026, the New York Department of Financial Services (“NYDFS”) issued two Industry Letters to the organizations it regulates (“Regulated Entities”): “Heightened Cybersecurity Risks Associated with Frontier AI Models” (the “Advisory”) and “Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment” (the “Guidance”) (collectively, the “Letters”). The Letters discuss […]
NYDFS Revises Prescriptive FAQs on Multifactor Authentication
Two months after the New York Department of Financial Services (“NYDFS”) updated its Frequently Asked Questions (“FAQs”), which we wrote about here, NYDFS has released updated FAQs on multifactor authentication (“MFA”) that further clarify 23 NYCRR § 500.12. As we previously reported, the FAQs from December 2025 provided prescriptive guidance, including clarifications on technical requirements […]