• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to secondary sidebar

Alston & Bird Privacy, Cyber & Data Strategy Blog

  • Home
  • Services
  • Events
  • Contacts

Cybersecurity

CPPA Issues Revised Draft CCPA Regulations; Votes to Initiate Public Comment Period

May 9, 2025 By Dorian Simmons

On May 1, 2025, the California Privacy Protection Agency (“CPPA”) Board convened to discuss revisions to the California Consumer Privacy Act (“CCPA”) draft regulations on cybersecurity audits, risk assessments, automatic decisionmaking technology (“ADMT”), insurance, and updates to the existing CCPA regulations. The revisions were informed by comments received by the CPPA during the formal public […]

Filed Under: Adtech & Digital Tracking, AI Cybersecurity & Privacy, Artificial Intelligence (AI), Board Governance & Cyber Risk Management, California Privacy & the CCPA, Consumer Protection/FTC, Privacy & Cyber Regulatory Enforcement Tagged With: Artificial Intelligence, Behavioral Tracking, California Consumer Privacy Act (CCPA), California Privacy Protection Agency (CPPA), California Privacy Rights Act (CPRA), Cybersecurity, Federal Trade Commission (FTC), Tracking, US State Law

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

May 6, 2025 By Hanna Hewitt and Kelly Hagedorn

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found that DPP failed to implement appropriate technical and organisational measures, as required by Article 5(1)(f) and Article 32 UK GDPR. This is the […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, European Privacy & Cybersecurity Tagged With: Cybersecurity, Data breach, Regulatory Enforcement, UK GDPR

Additional Cybersecurity Requirements of NYDFS Part 500 Take Effect Today

May 1, 2025 By Kim Peretti and Lance Taubin

Today, on May 1, 2025, additional enhanced cybersecurity controls required by the Second Amendment to the New York Department of Financial Services (NYDFS) Cybersecurity Regulation (23 NYCRR Part 500) (the “Second Amendment”) take effect.  Although the Second Amendment was originally adopted in November of 2023, NYDFS established a multi-year rollout of the Second Amendment’s requirements, […]

Filed Under: Board Governance & Cyber Risk Management, Privacy & Cyber Regulatory Enforcement Tagged With: Cybersecurity, Data Protection, NYDFS, Regulations

UK Government Publishes Cyber Governance Code of Practice for Boards and Directors

April 10, 2025 By Hanna Hewitt and Kelly Hagedorn

On April 8, 2025, the UK government published the Cyber Code of Practice (the “Code”) to support board directors in governing cybersecurity risks. The Code is available online. The UK’s data protection regulator is actively investigating and, in some instances, fining companies for personal data breaches caused by cybersecurity issues. It is therefore more important […]

Filed Under: Board Governance & Cyber Risk Management Tagged With: Cyber resilience, Cyber risk, Cybersecurity, UK Cybersecurity

UK Government Proposes Targeted Ban on Ransom Payments and Increased Ransomware Incident Reporting

February 5, 2025 By Kelly Hagedorn and Kristen Bartolotta

On January 14, 2025, the United Kingdom government published a consultation on ransomware proposing new measures to increase incident reporting and reduce ransom payments (the “Consultation”). The Consultation outlines three objectives in this regard and is open for responses until April 8, 2025. Proposal 1: Targeted Ban on Ransomware Payments The UK government is proposing […]

Filed Under: Board Governance & Cyber Risk Management, Crisis & Data Breach Response, Privacy & Cyber Regulatory Enforcement, Ransomware Fusion Center Tagged With: Cybersecurity, Incident Reporting, Ransomware, United Kingdom (UK)

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • Interim pages omitted …
  • Page 21
  • Go to Next Page »

Primary Sidebar

This blog is a service of Alston & Bird’s Privacy, Cyber & Data Strategy team and focuses on key data privacy and data security issues.


Receive email notifications when new posts are added.

Receive email notifications when new posts are added.


RANSOMWARE FUSION CENTER
Click here to request access

THE DIGITAL DOWNLOAD
Click here to see the editions

PRIVACY & CYBER EVENTS
Click here to see upcoming and past events

PRIVACY & CYBER MAILINGS
Click here to sign up


Secondary Sidebar

Categories

Recent Posts

  • Produce the Prompts: A Court Says Expert AI Inputs Are Fair Game in Discovery
  • Louisiana Delays App Store Accountability Effective Date to July 2027
  • NYDFS Issues Frontier AI Advisory and Guidance for Heightened Cyber Threat Environment
  • California Puts Social Media’s Youth Feeds on Notice
  • European Commission Publishes Draft Guidelines on Classification of High-Risk AI Systems Under the EU AI Act
Copyright © 2026 · Alston & Bird · All Rights Reserved. Privacy.