For many, December is a time to reflect on the past year and to look forward to what the New Year may bring. I believe organizations also should mark milestones, take stock of what has been done and what needs

For many, December is a time to reflect on the past year and to look forward to what the New Year may bring. I believe organizations also should mark milestones, take stock of what has been done and what needs
On March 14, 2018, the Securities and Exchange Commission charged a former chief information officer of Equifax with insider trading. The complaint alleged that he profited from selling stock ahead of the September 2017 public announcement of a major cybersecurity …
With so much boardroom attention on cybersecurity, directors continue to focus on the Securities and Exchange Commission (SEC) guidance issued earlier this year and its implications. The guidance adds specific expectations for disclosure controls and incident response procedures, and reiterates …
With the vast majority of annual meetings set to be held in the coming weeks, the contours of the 2018 proxy season are coming into focus. While previous years are remembered for defining initiatives — “say on pay” in 2011, …
The past year has seen continued evolution in the political, legal and economic arenas as technological change accelerates. Innovation, new business models, dealmaking and rapidly evolving technologies are transforming competitive and industry landscapes and impacting companies’ strategic plans and prospects …
On February 21, 2018, the SEC issued new Guidance regarding cybersecurity disclosure and governance requirements applicable to SEC reporting companies. In our earlier Client Update on this topic, we discussed the disclosure considerations addressed in the Guidance. In this Client …
On February 20, the Securities and Exchange Commission approved the issuance of an interpretive release, available here, to provide guidance to public companies when preparing disclosures about cybersecurity risks and incidents. The release also communicates the Commission’s views on the
In our memo last year, we acknowledged that it was close to impossible to predict the likely impact that the newly elected Trump administration would have on white-collar and regulatory enforcement. (White Collar and Regulatory Enforcement: What to Expect …
Earlier this year, the Securities and Exchange Commission (SEC) issued guidance regarding “robo-advisers,” automated investment advice tools accessed via web-based or mobile platforms with minimal human interaction.1 The guidance is an important reminder to the industry that robo-advisers are …
Good afternoon and thank you for inviting me to speak today. Before I begin, let me give the required disclaimer that the views I express here today are my own and do not necessarily represent the views of the Commission
The May 2017 WannaCry ransomware attack affected more than 200,000 computers spread across 150 nations. The results of the attack made clear that computers whose software is not up to date can hurt not only the computers’ owners, but ultimately …
On May 23, Target Corp. reached a record $18.5 million settlement with 47 states and the District of Columbia to end investigations into Target’s data breach in 2013. The settlement highlights the growing list of specific measures that companies are …
Many financial institutions1 have implemented the three Lines of Defense (LoD) model to help define their risk management frameworks and bolster supervisors’ (e.g., desk heads and senior traders) abilities to monitor risk.2 However, as frameworks for managing financial …
In 2016, companies, governments, and consumers were again challenged to navigate an evolving landscape of cybersecurity and privacy issues. This year saw flash points impacting the trajectory for data breach litigation, the future for privacy class actions, and the scope …
New York’s Department of Financial Services (DFS or the Department) has responded to a large volume of comments about its proposed, sweeping cybersecurity regulation for banks, insurers and other financial service providers by softening a number of provisions that many …
The growth in cybersecurity threats combined with the increasing demands placed on outside directors create challenges that often go beyond the risks that public companies face from employee and client communications. If public companies cannot communicate quickly with directors or …
On September 13, 2016, the New York State Department of Financial Services (DFS) proposed a broad set of cybersecurity regulations for banks, insurers, and other financial institutions.[1] The proposal is largely consistent with existing guidance (e.g., under the NIST …
On September 13, 2016, the New York Department of Financial Services (“DFS” or the “Department”) issued proposed regulations (the “Proposed Regulations”) designed to guard against the onslaught of cyber-attacks faced by banks, insurance companies and other financial services providers.[1]…
The World Economic Forum threw a knockout punch last month when it released its report, “The Future of Infrastructure: An Ambitious Look at How Blockchain Can Reshape Financial Services.”[1] When Giancarlo Bruno, the World Economic Forum’s Head …
On April, 27 2016, the European Council and Parliament finally adopted a new data protection law: the General Data Protection Regulation (GDPR). The following is a summary of key issues and a checklist of initial tasks to help you prepare …