On July 10, the SEC’s Office of Compliance Inspections and Examinations (OCIE) issued a Risk Alert noting the increasing sophistication of ransomware attacks on SEC registrants and service providers to SEC registrants. The Risk Alert is notable for its encouragement of financial services market participants more broadly and not just SEC registrants to monitor CISA […]
Search Results for: ransomware
Outbreak of “WannaCry” and “Wanna Decryptor” Ransomware Affects Companies Across the Globe
On Friday, May 12, companies in countries across the globe witnessed an unprecedented malware outbreak as ransomware labeled “WannaCry” and “Wanna Decryptor” infected a large range of critical systems. The malware exploits a vulnerability in older versions of Microsoft’s Windows, locks the systems it infects, and threatens to delete files unless a bitcoin ransom is […]
NYDFS Issues Guidance on the Million Dollar Question—How to Conduct Cybersecurity Risk Assessments Under Part 500
On September 10, 2026, the New York State Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) to regulated entities (“Covered Entities”) addressing what is probably the most frequently asked Part 500 question: “How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.” The risk assessment is, by all accounts, […]
IBM’s 2026 Cost of a Data Breach Report Signals a New Era of AI-Driven Cyber Risk
IBM recently released its Cost of a Data Breach Report 2026, which highlights the changing cyber threat landscape in which artificial intelligence (AI) is accelerating how threat actors identify vulnerabilities, launch attacks, and exploit compromised systems. These trends are reflected in rising average breach costs, with the global average cost rising 12% to a record […]
UK Cyber Security Breaches Survey 2025/2026: Key Takeaways
The UK Government has published its 2025/2026 Cyber Security Breaches Survey, which is drawn from information received from thousands of UK businesses. The 2025/2026 survey paints a picture of a cyber threat landscape that is stable in its scale but shifting in its character. The publicity surrounding high-profile incidents has not yet resulted in a […]