Credential Stuffing Attacks and What they Mean for Businesses

Over the past few months, Cooley’s incident response team has seen an increase in “Credential Stuffing” attacks. Credential Stuffing is an account takeover attack in which actors obtain user names and passwords available on the dark web from prior data breaches, and then attempt to login to various online accounts […]

Cybersecurity Governance for Maturing Companies

With cyber resilience top of mind for investors, shareholders, regulators and the plaintiffs’ bar, growing organizations can no longer afford to put their cybersecurity efforts on the back burner. Building a cybersecurity program has become an essential element in the growth strategy. But where do you begin? Cooley’s cyber/data/privacy lawyers […]

FTC’s Proposed Amendments to the GLBA Safeguards Rule Seek to Incorporate Requirements from NY DFS Cybersecurity Regulations

On March 5, the FTC announced proposed amendments to the Standards for Safeguarding Customer Information under the Gramm-Leach-Bliley Act (“Safeguards Rule” or “Rule”).  The FTC version of the Safeguards Rule applies to financial institutions that are not governed by federal banking regulators (e.g., FDIC, Federal Reserve, OCC, and NCUA) or […]

California Privacy Legislation Update

With the promulgation of the California Consumer Privacy Act of 2018 (“CCPA”), California has continued its role in pushing bleeding edge privacy and data security legislation.  From the first data breach notification law back in 2003, to the first IoT data security law in 2018, it seems that California will […]

Brexit and its Possible Impact on Data Transfers

In its strictest construction, what ‘Brexit’ means is clear, what it entails and what comes next is absolutely not. Therefore, this article will not focus on matters relating to any such future relationship, but rather only on the terms on which the UK may leave the EU and how that […]

Cooley’s Michael Rhodes Joins 41 California Privacy Experts Urging Major Changes to the California Consumer Privacy Act

Michael Rhodes, chair of Cooley’s cyber/data/privacy practice, joins 41 California privacy lawyers, professionals and professors urging major changes to the California Consumer Privacy Act (CCPA). Led by Santa Clara University School of Law professor, Eric Goldman, the group is urging the legislature to address six significant issues posed by the […]

The Department of Health and Human Services Issues Guidelines on Cybersecurity

On December 28, 2018, the U.S. Department of Health and Human Services (“HHS”) released the “Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients” publication (the “Cybersecurity Guidelines”), which provides voluntary cybersecurity practices designed to reduce security risks and improve security for various healthcare organizations. Specifically, the Cybersecurity Guidelines […]

Notes from first CCPA Public Forum in San Francisco

On Tuesday in San Francisco, the California Department of Justice (“DOJ”) held its first of six public forums on the California Consumer Privacy Act of 2018 (“CCPA”) before a packed room of industry representatives and public citizens. The forums are intended to fulfill the Attorney General’s mandate under CCPA to […]

“New” Application to an Old Problem: Pennsylvania Supreme Court’s Ruling Likely to Lead to More Cybersecurity Negligence Lawsuits

Pennsylvania’s Supreme Court (“Court”) cleared a path for employees seeking to hold employers responsible for data breaches affecting their information.  The Court found that employers are legally obligated to implement and maintain reasonable security measures to protect employees’ personal data in their possession.  The Court’s logic, however, may extend beyond […]

California Attorney General Announces CCPA Workshops

The California State Attorney General’s office announced that it will be holding six rulemaking workshops for the California Consumer Privacy Act of 2018 (“CCPA”). The workshop dates and locations are: January 8 – San Francisco January 14 – San Marcos January 24 – Riverside January 25 – Los Angeles February […]