The Courts Are Picking Up the Cyber Pace: A New Era of Accountability for Boards of Directors

The Courts Are Picking Up the Cyber Pace: A New Era of Accountability for Boards of Directors

There is a higher court than courts of justice and that is the court of conscience. It supersedes all other courts. —Mahatma Gandhi Introduction In recent years, the legal landscape around cybersecurity and data breaches has shifted significantly, placing increasing...
Thinking Clearly About Risk Assessments

Thinking Clearly About Risk Assessments

If I had an hour to solve a problem and my life depended on the solution, I would spend the first 55 minutes determining the proper question to ask.– Albert EinsteinIntroductionThere are few Einsteins out there for solving the problem of establishing, implementing,...
Heads Up! Massive Increase in Proposed FY2025 OCR Budget:  Focus on HIPAA Enforcement and Risk Management

Heads Up! Massive Increase in Proposed FY2025 OCR Budget: Focus on HIPAA Enforcement and Risk Management

Heads Up! Massive Increase in Proposed FY2025 OCR Budget: Focus on HIPAA Enforcement and Risk ManagementIntroductionThe proposed Fiscal Year 2025 (FY2025) budget for the Office for Civil Rights (OCR) under the U.S. Department of Health and Human Services (HHS)...
Should Not-for-Profit and Private Companies Care about Proposed SEC Cyber Disclosure Requirements?

Should Not-for-Profit and Private Companies Care about Proposed SEC Cyber Disclosure Requirements?

Blog #6 – Epilogue to SEC Cyber Series Should Not-for-Profit and Private Companies Care about Proposed SEC Cyber Disclosure Requirements? Introduction In my Blog Series, SEC “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure” Proposed Rule...
Disclosure Regarding the Board of Directors’ Cybersecurity Expertise

Disclosure Regarding the Board of Directors’ Cybersecurity Expertise

Blog #5 of 5 in SEC Cyber SeriesDisclosure Regarding the Board of Directors’ Cybersecurity Expertise [1]Introduction In the first post in this series Overview of the SEC “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure” Proposed Rule...