United States: Cybersecurity

Subscribe
Accounting law and audit law thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics such as FinTech, marketing, media, new technology, security.
Article
Last Call: “FAR CUI Rule” Draft Language Provides An Opportunity For Contractors To Weigh In By This Week
The FAR Council has released an updated draft of the government-wide FAR CUI Rule, proposing new solicitation provisions and contract clauses that would establish uniform requirements for contractors handling Controlled Unclassified Information. This comprehensive framework introduces specific cybersecurity obligations, incident reporting timelines, and compliance standards that would significantly impact federal contractors across all agencies.
United States Government
CM
Crowell & Moring LLP
Article
Episode 6: The Deepfake Defense Game Plan: Using IP Law To Fight AI Impersonation (Podcast)
Explore how cyber insurance is evolving to address emerging threats like AI-driven deepfakes, ransomware attacks, and geopolitical cyber conflicts. Industry experts discuss the challenges of adapting traditional insurance frameworks to cover synthetic media impersonation, war exclusions in digital warfare, and the critical role of leadership in ransomware response.
United States Insurance
WR
Wiley Rein
Article
Final Action On HIPAA Security Rule Modifications Now Projected For July 2027
The US Department of Health and Human Services' Office for Civil Rights has pushed back the timeline for finalizing significant changes to the HIPAA Security Rule, now targeting July 2027 instead of May 2026. The proposed modifications would impose extensive new cybersecurity requirements on healthcare entities, including mandatory encryption, multi-factor authentication, annual penetration testing, and elimination of the distinction between required and addressable implementation specifications.
United States Healthcare
SR
McDermott Will & Schulte
Article
Ankura Parcel Delivery Spotlight: The Case For Alternative Carriers
Disney's acquisition of Hulu exemplifies a recurring challenge in joint ventures: commercial conflicts between shareholders that ultimately force restructuring. This collection explores how organizations navigate strategic partnerships, operational conflicts, and value creation across industries from manufacturing to financial services, while examining the evolving landscape of corporate growth strategies and risk management.
United States Commercial
AC
Ankura Consulting Group LLC
Article
When The Classroom Goes Dark: Lessons From The Canvas Breach For Corporate Cyber Preparedness
A ransomware attack on Canvas, the widely-used learning management platform, compromised data from thousands of educational institutions by exploiting vulnerabilities in its Free-for-Teacher program. This incident reveals how cybercriminals are shifting tactics to target structural weaknesses in SaaS platforms, raising critical questions about third-party vendor security and institutional preparedness. Finnegan attorneys examine the breach's implications and provide actionable guidance for strengthening cyb
United States Technology
FH
Finnegan, Henderson, Farabow, Garrett & Dunner, LLP
Article
Structuring JV Deals To Manage Commercial Conflicts
Disney's acquisition of Hulu exemplifies a recurring challenge in joint ventures: commercial conflicts between shareholders that ultimately force restructuring. This collection explores how organizations navigate strategic partnerships, operational conflicts, and value creation across industries from manufacturing to financial services, while examining the evolving landscape of corporate growth strategies and risk management.
United States Commercial
AC
Ankura Consulting Group LLC
Article
DoD Suspends Phase II Of CMMC Program
The Department of Defense has suspended Phase II of its Cybersecurity Maturity Model Certification program, halting the planned November 2026 requirement for third-party cybersecurity assessments of defense contractors. While Phase I self-assessment requirements remain in effect, DoD has launched a 60-day review to address industry concerns about compliance costs and barriers to participation in the Defense Industrial Base.
United States Government
BL
Butzel Long
Article
Fraudulent Employees—the Newest Insider Threat? Defending Against State Actors
A healthtech company discovered a newly hired remote employee was operating under a false identity as part of a nation-state-linked operation designed to fraudulently obtain technology jobs. With support from Riveron, the company rapidly contained the threat, investigated the incident, and strengthened its hiring verification controls to defend against this emerging attack vector.
United States Technology
R
Riveron
Article
Ankura CTIX FLASH Update – July 13, 2026
Cybersecurity researchers have uncovered sophisticated threats targeting enterprise defenses and development workflows, while financial institutions grapple with AI deployment challenges and compliance systems face fundamental transformation. From ransomware leveraging kernel-level drivers to disable security tools, to the weaponization of AI coding assistants and open-source ecosystems, the modern attack landscape demands new defensive strategies and operational frameworks.
United States Technology
AC
Ankura Consulting Group LLC
Article
Department Of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review
The Department of War has suspended the Phase II rollout of its Cybersecurity Maturity Model Certification program, citing compliance costs and bureaucratic burdens, while establishing a Reform Task Force to conduct a comprehensive review. Defense contractors must navigate this regulatory shift while maintaining existing cybersecurity obligations under DFARS requirements and Phase I self-assessment protocols. The suspension raises critical questions about the future of third-party certification requirements
United States Government
CM
Crowell & Moring LLP
Article
Quantum Computing And The Future Of Cybersecurity: What Organizations Need To Know Now
Quantum computing poses a significant long-term threat to modern cryptographic systems, particularly public-key encryption used in secure communications and authentication. While cryptographically relevant quantum computers remain years away, organizations face complex legal, regulatory, and cybersecurity risks if they delay planning for post-quantum cryptography transitions.
United States Technology
SM
Sheppard, Mullin, Richter & Hampton LLP
See more