article thumbnail

The EU’s Cyber Resilience Act Has Now Been Agreed

Inside Privacy

In terms of timing, the CRA will come into force over a phased transition period starting in late 2025. Conducting due diligence on imported PDEs. We’ll provide a more detailed summary of the agreed text once it is finalized and published but in this post we set out a brief summary of key provisions.

article thumbnail

Helpful Guidance on Managing AI-Related Cybersecurity Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their cybersecurity compliance budgets and the securing of additional resources for 2025 and beyond. Some companies may want to address this now as 2025 budgets are being finalized.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

EU cyber regulation wave quietly rolls on – Commission set to finalize new cyber standards

Inside Privacy

Meanwhile, the Cyber Resilience Act, which has now been agreed in substance but awaits legislative formalities, will continues to work its way through the legislative process after which that Act would come into force over a phased transition period starting in late 2025. of global turnover.

article thumbnail

Part 2 – Helpful Guidance on Managing (Non-Cybersecurity) AI Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their compliance budgets and the securing of additional resources for 2025 and beyond.

article thumbnail

Managing Cybersecurity Risks Arising from AI – New Guidance from the NYDFS

Debevoise Data Blog

Third-Party Service Provider and Vendor Management The NYDFS “strongly” recommends that due diligence of third-party service providers should include diligence on the AI-related risks they pose to themselves and to the covered entities.

article thumbnail

UK Financial Regulators Publish Response to AI Consultation – Seven Takeaways

Debevoise Data Blog

One possibility is for the UK Financial Regulators to introduce standardized AI due diligence requirements that firms must satisfy before they can adopt third-party tools. There is strong appetite for any future regulations to align with existing domestic and international laws and regulations.

article thumbnail

The EU Digital Operational Resilience Act (DORA): What you need to know and how to prepare

Debevoise Data Blog

Covered entities must come into compliance with the provisions within 24 months after its entry into force, which depending on the date of publication will likely be December 2024 or January 2025. What are the key requirements for financial entities? DORA requires covered financial entities to comply with new rules in four key areas: 1.