article thumbnail

The EU’s Cyber Resilience Act Has Now Been Agreed

Inside Privacy

In terms of timing, the CRA will come into force over a phased transition period starting in late 2025. Conducting due diligence on imported PDEs. We’ll provide a more detailed summary of the agreed text once it is finalized and published but in this post we set out a brief summary of key provisions.

article thumbnail

EU cyber regulation wave quietly rolls on – Commission set to finalize new cyber standards

Inside Privacy

Meanwhile, the Cyber Resilience Act, which has now been agreed in substance but awaits legislative formalities, will continues to work its way through the legislative process after which that Act would come into force over a phased transition period starting in late 2025. of global turnover.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Top 10 (Well, 11) Cybersecurity Blog Posts for 2024

Debevoise Data Blog

In this post, we discuss how companies can comply with NYDFSs current approach by establishing internal governance committees, conducting a gap assessment against existing controls and standardizing due diligence processes, among other practical tips.

article thumbnail

Helpful Guidance on Managing AI-Related Cybersecurity Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their cybersecurity compliance budgets and the securing of additional resources for 2025 and beyond. Some companies may want to address this now as 2025 budgets are being finalized.

article thumbnail

Managing Cybersecurity Risks Arising from AI – New Guidance from the NYDFS

Debevoise Data Blog

Third-Party Service Provider and Vendor Management The NYDFS “strongly” recommends that due diligence of third-party service providers should include diligence on the AI-related risks they pose to themselves and to the covered entities.

article thumbnail

Part 2 – Helpful Guidance on Managing (Non-Cybersecurity) AI Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their compliance budgets and the securing of additional resources for 2025 and beyond.

article thumbnail

UK Financial Regulators Publish Response to AI Consultation – Seven Takeaways

Debevoise Data Blog

One possibility is for the UK Financial Regulators to introduce standardized AI due diligence requirements that firms must satisfy before they can adopt third-party tools. There is strong appetite for any future regulations to align with existing domestic and international laws and regulations.