On May 12, 2021, President Biden signed a landmark Executive Order to improve and modernize the federal government’s cybersecurity infrastructure. The Executive Order comes in the wake of numerous cyber incidents targeting the United States, including the so-called SolarWinds, Microsoft Exchange, and Colonial Pipeline incidents. The Executive Order will directly affect government contractors, including companies

Michael Vatis
Michael Vatis has spent most of his career addressing cutting edge issues at the intersection of law, policy, and technology. Michael's practice focuses on Internet, e-commerce, and technology matters, providing legal advice and strategic counsel on matters involving privacy, security, encryption, intelligence, law enforcement, Internet gambling, and international regulation of Internet content.
New York Adopts Cybersecurity Framework for Insurers
On February 4, 2021, the New York State Department of Financial Services (NYDFS) released a Cyber Insurance Risk Framework (the Framework) to assist property and casualty insurers in managing their cyber insurance risk. The Framework comes on the heels of an increased demand for cyber insurance coverage from businesses to protect against the growing and ever-changing threat posed by cyberattacks.
To help issuers effectively manage the increased risk associated with issuing cyber insurance policies, the Framework recommends that insurers adopt seven “best practices,” which are discussed in this post.…
Continue Reading New York Adopts Cybersecurity Framework for Insurers
Virginia Poised to Become Second State with Comprehensive Privacy Law
On January 29, 2021 and February 3, 2021, respectively, the Virginia House of Delegates and Virginia Senate passed the Virginia Consumer Data Protection Act (VCDPA). The legislation, if signed into law by the governor, would be the first comprehensive privacy law enacted by a state since California enacted the California Consumer Privacy Act (CCPA) and, more recently, the California Privacy Rights Act (CPRA). Though the VCDPA is not slated to take effect until January 1, 2023, it will be important for companies to understand the complicated provisions of the VCDPA much earlier, so they can begin instituting any necessary changes in their internal and public-facing policies and their information practices. The VCDPA’s passage may also spur other states to enact their own privacy laws, which until now have been mired in legislative purgatory.
Some of the more significant aspects of the VCDPA are summarized in this post.…
Continue Reading Virginia Poised to Become Second State with Comprehensive Privacy Law
The Urgent Need to Assess and Respond to Russian Supply Chain Attacks
According to media reports, Russian government hackers have penetrated the systems of thousands of companies across a variety of industries, as well numerous US government agencies. Moreover, what has been publicly reported may be only the tip of the iceberg in terms of both the scope of the attacks’ victims and the attackers’ methodologies. The most recent reporting also suggests that victim companies are not just those that would be of obvious interest to Russian intelligence services. Accordingly, all companies should assess whether they have been affected by this attack, what steps they need to take to remediate those effects, and what legal and contractual obligations they may have to notify government agencies, business partners, customers, and individuals.
Continue Reading The Urgent Need to Assess and Respond to Russian Supply Chain Attacks
California Voters Approve Expansive New Data Privacy Law, Shaking Up the CCPA
For over two years businesses have spent considerable energy preparing for and complying with the California Consumer Privacy Act (CCPA). Businesses now have more work to do after California voters overwhelmingly approved Proposition 24, the California Privacy Rights Act (CPRA), which completely reshapes and overhauls the CCPA. Fortunately, most of the CPRA’s changes, including those…
California Attorney General Proposes More Modifications to CCPA Regulations
Just when you thought you finally had a handle on CCPA compliance, the California Attorney General has proposed additional modifications to the regulations that recently became final on August 14. Fortunately, the changes are minor. More significant changes to the CCPA may be just around the corner, though, if California voters approve the California Privacy…
California Extends Exemptions from CCPA for B2B and Employee Information
On September 30, California Gov. Gavin Newsom signed into law AB-1281, which extends until January 1, 2022 the exemptions from the California Consumer Privacy Act (CCPA) for personal information collected as part of a B2B transaction or collected from employees and job applicants. The exemptions apply to most, but not all, of…
CCPA Regulations Take Effect, Six Weeks After CCPA Enforcement Begins
On Friday, August 14, 2020, California Attorney General Xavier Becerra announced that the regulations implementing the California Consumer Privacy Act (CCPA) have been approved by the California Office of Administrative Law (OAL) and are effective immediately. The attorney general had already begun enforcing the CCPA itself on July 1. But now that the regulations have…
Webinar: CCPA Enforcement Is About to Begin: Are You Ready?
On July 1, 2020, the California attorney general is expected to begin enforcing the California Consumer Privacy Act (CCPA), California’s groundbreaking new privacy law which has been in effect since January 1, 2020. In addition, the attorney general is also finalizing regulations that interpret and build upon the CCPA. To minimize the risk of potentially…
Data Security Components of New York’s SHIELD Act Take Effect
While most businesses have been preoccupied with navigating the effects of the COVID-19 pandemic, a significant change to businesses’ data security obligations has taken effect in New York. On March 21, 2020, the second part of the Stop Hacks and Improve Electronic Data Security Act (the SHIELD Act) went into effect in New York State.
…