​

  1. Home
  2. Insights
  3. Blogs
  1. Home
  2. Insights
  3. Blogs

Series

Blogs

US – Cyber security in flux

Article|
27 October 2023

Share this:

LinkedInMail
Up next

China: New guidance on classifying data and identifying important data in the financial industry

Article | 3 February 2026

​

RELATED TOPICS:

Share this:

LinkedInMail

​

​

  • Find a Lawyer

    Find a lawyer

    Find a lawyer
    • Aerospace, Defence and Security
    • Automotive
    • Banks
    • Chemicals
    • Consumer
    • Energy and Utilities
    • Healthcare and Life Sciences
    • Industrials
    • Infrastructure
    • Insurance
    • Mining
    • Mobility
    • Private Capital
    • Private Equity and Financial Sponsors
    • Real Estate
    • Retail Asset Managers
    • Sports
    • Technology
    • Telecoms
  • Insights

    Insights

    Insights
    Featured Topics
    • Energy
    • Financial Regulation
    • Tech
    Featured Article
    AI in Financial Services 4.0
    Publication
    20 October 2025
  • Our Firm

    Our Firm
    • About us
    • Our culture and values
    • Our people
    • Responsible business
    • News and Deals
    • Alumni
  • Your Career

    Your Career

    Your Career
  • Find a Lawyer

    Find a lawyer

    Find a lawyer
  • Sectors

    • Aerospace, Defence and Security
    • Automotive
    • Banks
    • Chemicals
    • Consumer
    • Energy and Utilities
    • Healthcare and Life Sciences
    • Industrials
    • Infrastructure
    • Insurance
    • Mining
    • Mobility
    • Private Capital
    • Private Equity and Financial Sponsors
    • Real Estate
    • Retail Asset Managers
    • Sports
    • Technology
    • Telecoms

    Services

    • Antitrust & Foreign Investment
    • Artificial Intelligence
    • Banking
    • Business Crime
    • Capital Markets
    • Capital Solutions
    • Construction
    • Corporate/M&A
    • Crisis Management
    • Data and Cyber
    • Digital Regulation and Technology Projects
    • Employment and Incentives
    • Energy & Infrastructure
    • Environment, Social and Governance
    • Financial Regulation Group
    • Fintech
    • Intellectual Property
    • International Arbitration
    • Investigations
    • Investment Funds
    • Islamic Finance
    • Legal Operations
    • Litigation
    • Pensions
    • Private Credit
    • Private Equity
    • Public & Administrative Law
    • Public Advocacy
    • Real Estate
    • Restructuring and Insolvency
    • Risk Advisory
    • Supply Chain and Procurement
    • Tax
    • Telecoms
    • Products

    Locations

  • Insights

    Insights

    Insights
    Featured Topics
    • Energy
    • Financial Regulation
    • Tech
    Featured Article
    AI in Financial Services 4.0
    Publication
    20 October 2025
  • Our Firm

    Our Firm
    • About us
    • Our culture and values
    • Our people
    • Responsible business
    • News and Deals
    • Alumni
  • Your Career

    Your Career

    Your Career

As October is Cybersecurity Awareness Month, it’s an appropriate time to provide an overview of the evolving cybersecurity obligations, guidance, and risks following recent regulatory developments and cyberattacks that regulators are seeking to address.

Our update here offers four critical takeaways for every business in managing their cybersecurity program.

Takeaway #1: Cybersecurity programs must be “real”, not “check-the-box.”

SEC Director Grewal remarked that “firms need to have real policies that work in the real world, and then they need to actually implement them; having generic ‘check-the-box’ cybersecurity policies simply doesn’t cut it.” For example, “real” cybersecurity education and training should be tailored not only to the applicable business and the risks that it faces, but also on a department-by-department basis to address each department’s particular responsibilities and risks.

Takeaway #2: Companies must regularly review and update their cybersecurity programs to keep up with constantly evolving threats.

The typical standard with respect to such “regular” review and update is “at least annual.” However, annually may not be enough. Companies will need to exercise judgement about when a significant or material change has impacted their business and altered their risk profile. They will need to respond in kind by conducting updated cybersecurity risk assessments and updating relevant policies and procedures.

Takeaway #3: Appropriate information must be reported, both internally and externally.

Examples of internal reporting obligations and principles in connection with the recent regulatory developments include the CPPA’s draft cybersecurity audit regulations, which would require that the audit’s findings be reported to the business’s board of directors. Added to this are the numerous external reporting obligations, including a number of new obligations set out in our update.

Takeaway #4: Individuals whose personal data is compromised are NOT the only victims

Director Grewal indicated that “When there are cyberattacks on publicly traded companies and other market participants, we consider the investing public to also be potential victims of those incidents.”

Similarly, class action lawsuits arising out of cybersecurity incidents have been filed not just on behalf of affected “consumers” whose personal data was compromised (e.g., in connection with the Estée Lauder, MGM Resorts, and Caesars Entertainment cyberattacks), but also on behalf of investors in the company targeted by the cyberattack (e.g., in connection with the SolarWinds cyberattack).

 

Read more in our update here

US – Cyber security in flux

27 October 2023

Inspiring confidence and trust as the #1 global legal team in the world

Quick Links

  • About Us
  • Sectors
  • Insights
  • Services
  • Contact Us

Social

  • LinkedIn
  • X (Twitter)
  • WeChat
  • YouTube

Legal

  • Accessibility
  • Attorney Advertising
  • Legal Notices
  • Modern Slavery
  • Remote working
  • Fraud and Scams

© Copyright Linklaters LLP

Privacy Policy