United States: Cybersecurity

Subscribe
Accounting law and audit law thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics such as FinTech, marketing, media, new technology, security.
Article
Cyber Offensive: White House Establishes New Program For Private-Sector Cyber Operations Against Foreign Cybercrime Groups
President Trump's National Security Presidential Memorandum establishes a groundbreaking program authorizing vetted private US companies to conduct cyber surveillance and offensive operations against foreign cybercrime organizations under federal government direction. The initiative creates a National Coordination Center to oversee these operations while requiring rigorous vetting, legal compliance safeguards, and coordination across intelligence and law enforcement agencies.
United States Government
SJ
Steptoe LLP
Article
Ankura CTIX FLASH Update – August 21, 2026
Ankura provides expert insights across cybersecurity, data privacy, financial services, and corporate governance. From emerging cyber threats targeting critical infrastructure to new regulatory frameworks reshaping private equity valuations and UK corporate governance requirements, these analyses examine the evolving challenges facing organizations in 2026. How are businesses adapting to heightened security risks, regulatory scrutiny, and operational complexities?
United States Technology
AC
Ankura Consulting Group LLC
Article
The DOJ Bulk Data Security Program: Why Proof Matters More Than Prevention
Ankura presents a comprehensive collection of insights spanning cybersecurity threats, regulatory compliance, transaction analysis, and industry-specific challenges across multiple sectors. How are emerging technologies and evolving regulations reshaping risk management, valuation practices, and operational strategies for organizations navigating today's complex business landscape?
United States Strategy
AC
Ankura Consulting Group LLC
Article
Court Finds Physical Manifestations Of Purely Mental And Emotional Injuries Do Not Constitute ‘Bodily Injury’
A federal court in Pennsylvania ruled that physical manifestations of emotional distress from a data breach do not constitute bodily injury under a general liability policy. The decision also addressed whether the policy's personal and advertising injury coverage applied when a hacker gained unauthorized access to private photos of female athletes stored in software operated by the insured.
United States Insurance
WR
Wiley Rein
Article
Navigating The New Presidential Memorandum On Transnational Cyber Enabled-Crime
The Trump Administration has introduced a groundbreaking framework allowing vetted U.S. cybersecurity companies to conduct government-supervised offensive cyber operations against transnational criminal organizations. This unprecedented initiative raises critical questions about liability allocation, operational oversight, and the practical implications for private-sector firms considering participation in government-directed cyber surveillance and disruption activities.
United States Government
WR
Wiley Rein
Podcast
California Raises The Bar On Cybersecurity (Podcast)
On this episode of “Decrypted,” hosts William Ridgway and David Simon are joined by Cybersecurity and Data Privacy colleague Lisa Zivkovic for a deep dive into California’s new mandatory risk assessment and cybersecurity audit requirements, including why the 2028 filing deadlines are more urgent than they appear and the two distinct compliance regimes companies must navigate.
United States Technology
SA
Skadden Arps Slate Meagher & Flom
Article
Should HIPAA Compliance Be On Your 2027 Roadmap Even If You Are Not A Healthcare Entity?
The Department of Health and Human Services recently settled with Spencer Gifts following a 2021 ransomware attack that exposed employee health plan information, demonstrating that HIPAA compliance extends beyond traditional healthcare providers. Employer health plans are covered entities under HIPAA, requiring comprehensive risk assessments, security policies, and workforce training—obligations that many non-healthcare organizations may not realize apply to them.
United States Privacy
SM
Sheppard, Mullin, Richter & Hampton LLP
Article
AI: The Washington Report — August 2026 Edition
The Trump administration is reshaping AI policy through major cybersecurity, scientific research, and regulatory initiatives, while states like Illinois and Colorado pioneer new AI safety frameworks. Federal agencies are committing over $5 billion to embed AI across critical infrastructure, healthcare, and defense sectors, even as Congress struggles to pass comprehensive federal legislation. How will businesses navigate this fragmented landscape of federal action and state-by-state regulation?
United States Technology
M
Mintz
Article
FCC Adds Advanced Robotic Devices To The Covered List
The FCC has added foreign-produced advanced robotic devices to its Covered List following a National Security Determination, effectively blocking new models from receiving equipment authorization unless they obtain conditional approval. This regulatory action impacts autonomous mobile robots, humanoid robots, and quadrupeds weighing over 4.4 pounds with network connectivity, while existing authorized devices remain unaffected through at least 2029. Companies can seek exemption through a detailed conditional
United States Media & IT
SJ
Steptoe LLP
Article
DoW Hits Pause On Cyber Certifications: What Companies Need To Know Now
The Department of Defense has announced an immediate suspension of CMMC Phase II requirements, originally scheduled for November 2026, and launched a 60-day review of the entire cybersecurity certification program. Companies now face uncertainty about the future of the framework designed to strengthen data security protections for sensitive information under defense contracts, while Phase I self-assessment requirements remain in effect.
United States Government
SM
Sheppard, Mullin, Richter & Hampton LLP
See more