On September 10, 2026, the New York State Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) to regulated entities (“Covered Entities”) addressing what is probably the most frequently asked Part 500 question: “How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.” The risk assessment is, by all accounts, […]
Board Governance & Cyber Risk Management
Secure Connectivity for Operational Technology—UK NCSC Publishes New Guidance
The UK National Cyber Security Centre (NCSC) published guidance to help organisations design, secure, and manage Operational Technology (OT) environments. It sets out eight core principles to improve resilience, reduce exposure, and support secure architectural decision‑making. The NCSC positions these as goals rather than minimum requirements, and operators of essential services (including those within scope […]
CalPrivacy Goes to the Board with Digital Advertising-Focused Enforcement
On February 27, 2026, the California Privacy Protection Agency (“CalPrivacy”) issued an order (the “Order”) requiring a sports-focused media and technology company (the “Company”) to pay a $1.10 million administrative fine for violations of the California Consumer Privacy Act (“CCPA”). The action continues California regulators’ scrutiny of how companies deploy cookies, software development kits and […]
CISA Revives CIRCIA Rulemaking
Almost two years after seeking stakeholder input about a final rule under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), the Cybersecurity and Infrastructure Security Agency (CISA) announced that it will hold virtual town hall meetings for certain industry sectors in March and April 2026 to solicit additional input on the Notice […]
European Commission Publishes Guidance For Companies Implementing the EU Cyber Resilience Act
On December 3, 2025, the European Commission published its first set of technical FAQs on the EU Cyber Resilience Act (‘CRA’). The CRA is an EU-wide law which lays down cybersecurity requirements for ‘products with digital elements’ (‘PDEs’), including IoT devices, hardware components, and certain software. It becomes fully applicable on December 11, 2027, with […]