article thumbnail

EU cyber regulation wave quietly rolls on – Commission set to finalize new cyber standards

Inside Privacy

Meanwhile, the Cyber Resilience Act, which has now been agreed in substance but awaits legislative formalities, will continues to work its way through the legislative process after which that Act would come into force over a phased transition period starting in late 2025. of global turnover.

article thumbnail

FTC’s Consent Order Against Marriott: Expectations for Reasonable Security

Debevoise Data Blog

Whereas the Consent Order has a 180-day implementation deadline, the AG Settlement requires full implementation within one year: by October 9, 2025. Conduct Careful Cybersecurity Due Diligence Pre-Acquisition and Develop Post-Acquisition Remediation Plan. The AG Settlement also featured a 20-year term.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Managing Cybersecurity Risks Arising from AI – New Guidance from the NYDFS

Debevoise Data Blog

Third-Party Service Provider and Vendor Management The NYDFS “strongly” recommends that due diligence of third-party service providers should include diligence on the AI-related risks they pose to themselves and to the covered entities.

article thumbnail

Part 2 – Helpful Guidance on Managing (Non-Cybersecurity) AI Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their compliance budgets and the securing of additional resources for 2025 and beyond.

article thumbnail

The New Way of Conducting Patent Research: Proven Strategies For Efficient Due Diligence

Speaker: Andrew Klein

Patent due diligence processes take too long. Join us to hear best practices in researching and producing thorough patent due diligence reports. Register now and start mastering patent due diligence like a pro! 📆 March 25, 2025 at 11:00 am PT, 2:00 pm ET, 7:00 pm GT There are better methods!

article thumbnail

The EU Digital Operational Resilience Act (DORA): What you need to know and how to prepare

Debevoise Data Blog

Covered entities must come into compliance with the provisions within 24 months after its entry into force, which depending on the date of publication will likely be December 2024 or January 2025. What are the key requirements for financial entities? DORA requires covered financial entities to comply with new rules in four key areas: 1.

article thumbnail

Helpful Guidance on Managing AI-Related Cybersecurity Risks from Hong Kong’s SFC

Debevoise Data Blog

For some firms, compliance with the Circular will require a significant increase in their cybersecurity compliance budgets and the securing of additional resources for 2025 and beyond. Some companies may want to address this now as 2025 budgets are being finalized.