Cybersecurity

On Jan. 17, 2025, EU Regulation 2022/2554 on digital operational resilience for the financial sector (DORA) became applicable in the EU.

DORA focusses on risk management and resilience testing, with a strong focus on vendor risk management, incident management and reporting, and resilience testing of key systems.

DORA applies to financial institutions that are authorized

Six months after the SEC’s Cybersecurity Incident Disclosure Rule (SEC Rule) came into force, an April 2024 GT Alert summarized disclosure trends. The GT Alert identified that the companies who filed a mandatory form 8-K disclosing a cybersecurity incident had erred on the side of caution, hedged on whether the materiality threshold had been met

On Jan. 15, 2025, the Department of Defense (DoD), General Services Administration, and NASA, all members of the FAR Council, published a proposed FAR CUI Rule under Title 48 of the CFR. This proposed rule amends the Federal Acquisition Regulation (FAR) to implement the third and final piece of the National Archives and Records Administration’s

David Zetoony, co-chair of GT’s U.S. Data, Privacy and Cybersecurity Practice, and Shareholders Reena Bajowala and Liz Harding will present the MyLawCLE and Federal Bar Association webinar, “Artificial Intelligence and Data Privacy: Current Laws and Regulations in the United States and the European Union,” Jan. 15, 2025.

This program will include an in-depth

Cyber criminals constantly develop new ways to steal money from businesses. One common scam targeting law firms and corporate legal departments involves “imposters” pretending to be clients or other parties who are owed payment, then tricking the attorney into paying the imposters. This deception has led to a rise in lawsuits where parties are battling

GT Shareholders Darren Abernethy and Gretchen A. Ramos, Global Co-Chair of the firm’s Data Privacy and Cybersecurity Practice, presented the ACC of San Francisco Dec. 10 webinar, “Reading the Tea Leaves – Privacy Compliance in 2025.” Staying advised of the developments in the privacy compliance world can be challenging; this one-hour webinar provided

GT Shareholder Ian C. Ballon will speak during the “Data Privacy in the Age of Digital Transformation” webinar Dec. 3, 2024. This virtual event will offer an in-depth exploration of key global data privacy regulations, including GDPR, CCPA, and other frameworks. This masterclass, hosted by Events 4 Sure in partnership with GeneralCounsel360, is designed for

On Oct. 22, 2024, the SEC announced settled administrative actions against four current or formerly public technology companies, finding that the companies all made materially misleading disclosures to investors in their periodic filings concerning the impact of the 2020 SolarWinds breach on their businesses. 

Continue reading the full GT Alert.