Do cybercrime statistics ever shock you anymore?
The numbers behind emerging cyber threats are difficult to ignore.
Cybercrime was up 30% in Q2 2024 compared with the previous year. Nearly 90% of US businesses reported suffering a cyberattack in the last year. Global damage estimates could reach $10.5 trillion by 2025.
Consider this, from Cybercrime Magazine:
The growth in cybercrime from 2015 to 2025 may become the greatest transfer of financial wealth in history.
It may also exceed the annual global damage caused by natural disasters.
Cybercrime could generate more profit for criminals than the global trade of all illegal drugs combined.
It should be no surprise that governments across the world are desperate to act.
Ransomware has received growing attention because of its impact on healthcare institutions worldwide.
Law enforcement has achieved some major victories.
These include:
- The disruption of LockBit
- The identification of its leader
- Increased international cooperation
However, major incidents continue.
Forbes recently reported that a Fortune 50 company paid a $75 million ransom earlier this year.
And we don’t even know who it is.
Earlier, we looked at EU regulations and their clash with big tech.
In this article, we look at government cybersecurity regulations for 2024.
We also explore:
- The impact of recent Supreme Court rulings
- Current reporting requirements
- Sector-specific regulations
- Steps companies can take to stay compliant
The Current Regulatory Landscape
It is difficult to understand the full scope of cybercrime because many attacks are never reported.
That helps explain why recent cybersecurity law changes place a strong focus on reporting.
Companies may delay reporting for several reasons.
They may fear:
- Further attacks
- Damage to their reputation
- Legal action
- Government penalties
- Exposure of security weaknesses
The Cybersecurity and Infrastructure Security Agency (CISA) was created in 2018.
It took over responsibilities from an office within the Department of Homeland Security.
Since then, CISA has expanded its role.
It now:
- Issues directives to government agencies
- Supports cyber threat detection
- Coordinates incident response
- Develops cybersecurity guidance
CISA also played a key role in drafting the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in 2022.
CIRCIA mandates reporting.
For CISA CIRCIA compliance, critical infrastructure organizations must report certain incidents within 72 hours.
Reports may also be submitted by:
- Lawyers
- Insurance providers
- Cybersecurity specialists
Ransomware payments must be reported within 24 hours.
[CISA is also involved in AI regulation. For more information, see my article on being smart about AI regulation.]
Other Federal Regulations
The Securities and Exchange Commission (SEC) was not created with cybersecurity as a primary focus.
That has changed.
Its 2023 cybersecurity rules added new requirements for public companies.
These rules focus on:
- Cybersecurity risk management
- Incident reporting
- Governance
- Leadership oversight
Public companies must disclose significant cybersecurity incidents within four business days.
The disclosure must include key details about:
- The nature of the incident
- Its scope
- Timing
- Business impact
The SEC also requires annual disclosures.
Companies must explain how they manage cybersecurity risks.
This includes their:
- Security strategies
- Internal processes
- Leadership oversight
The Federal Trade Commission (FTC) Safeguards Rule has also changed over time.
It was first introduced in 2003.
Today, it applies to nonbank financial organizations and other businesses that handle customer information.
This may include personally identifiable information (PII).
Organizations must use security controls such as:
- Encryption
- Multi-factor authentication
- Risk assessments
- Security monitoring
- Employee training
- Incident response plans
Companies must also appoint someone to oversee cybersecurity efforts.
The FTC has added breach notification rules as well.
Organizations must notify the agency as soon as possible after certain breaches.
The deadline is no later than 30 days when more than 500 customers are affected.
These regulations show a clear trend.
Companies are expected to strengthen security and provide more transparency when incidents happen.
State-Level Regulations
Of course, it doesn’t end there.
Forty-seven states and the District of Columbia have their own cybersecurity laws.
These rules may cover:
- Cybersecurity posture
- Breach notification
- Data protection
- Consumer privacy
California has some of the strictest requirements.
The California Consumer Privacy Act (CCPA) from 2023 was influenced by the EU’s GDPA.
California has also added other rules that require detailed notifications.
Sector-Specific Regulations
The healthcare sector has its own cybersecurity requirements.
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) requires organizations to report breaches involving Protected Health Information (PHI).
The Health Insurance Portability and Accountability Act (HIPAA) also sets data protection rules.
These apply to healthcare organizations and cloud providers that handle sensitive health information.
The Gramm-Leach-Bliley Act (GLBA), enforced by the FTC, also includes cybersecurity rules for financial institutions.
These requirements focus on:
- Data protection
- Security controls
- Incident reporting
The Transportation Security Administration (TSA) has also introduced cybersecurity rules.
These apply to:
- Passenger rail carriers
- Freight rail carriers
- Airports
- Aviation companies
Requirements may include:
- Naming cybersecurity contacts
- Continuous monitoring
- Security testing
- Incident response plans
- Cyber resilience planning
These regulations show how complex the cybersecurity landscape has become.
Requirements can vary based on:
- Industry
- Location
- Type of data
- Business size
- Regulatory authority
The Shifting Ground
For businesses, cybersecurity regulation is becoming even more complex.
Many requirements come from agency rules rather than laws passed by Congress and signed by the President.
Recent Supreme Court decisions have added more uncertainty.
One important example is the Loper Bright decision.
The ruling overturned the long-standing Chevron deference.
Chevron deference gave government agencies more authority to interpret unclear laws.
That authority now shifts more toward the courts.
As a result, cybersecurity regulations may face more legal reviews and changes.
For organizations, this creates ongoing uncertainty.
Companies may need to adapt to changing interpretations of rules such as:
- CISA’s implementation of CIRCIA
- Proposed FTC updates
- Children’s online privacy rules
- Healthcare data protection rules
- SEC requirements
- GLBA requirements
- TSA cybersecurity rules
Cyber threats will continue to grow.
Businesses will need to stay informed and remain flexible as regulatory expectations change.
Cybersecurity Risk Management Strategies
This is not a complete list of cybersecurity regulations.
Other important laws include:
- CFAA
- FISMA
- ECPA
- COPPA
So how can companies manage cybersecurity compliance in such a complex environment?
Budget, scale, and industry all matter.
But overall, this is my advice:
- Designate your point of contact: Many regulations require a point of contact for cybersecurity issues, and of course it makes sense to have someone trusted within your organization to be the point of this spear.
- Understand current obligations: Begin by getting a comprehensive picture of what requirements you have now for cybersecurity protection, reporting, and crisis management. Given the wide spread of institutions and varied levels of coverage, this is not easy, but it is absolutely essential.
- Perform your own risk assessment: Assemble a cross-functional team if possible, to help compare current readiness matches to not only the required, but the likely trajectory. Do you have gaps that need addressing? Adequate legal counsel, demonstrable plans, and reporting?
- Monitor and test and be ready to demonstrate how: Many regulations require proof of consistent monitoring, so that companies are aware when events happen, and will not be late to learn of attacks. Consider automated testing innovations where possible and affordable.
- Have a tried and tested incident response plan: Also a common regulatory requirement, it’s just good sense to have rapid response capabilities in place, both to limit the fallout from cyber incidents and to help sustain business continuity.
- Invest in training: I repeat this over and over, but it’s relevant here as well—your best defense against cybercrime is a trained workforce. It’s also mandated by some regulations, and can be included in your readiness plans.
- Stay informed: Once you’re ready, expect change. As discussed, legal challenges in the US landscape are going to trigger changes in requirements and coverage, and this will require regulatory monitoring, just like your cybersecurity itself.
[Another method to stay informed is to read The PTP Report, which includes regular cybersecurity roundups and coverage of current events.]
For additional guidance on cybersecurity readiness, you can also look to my Substack, where I cover topics from essential strategies for business owners, to protecting a remote workforce.
Conclusion
The cybersecurity trends of 2024 show a growing challenge.
Cyberattacks are becoming more frequent and more advanced.
This trend is likely to continue.
Governments are responding with stronger cybersecurity rules.
They are also placing more responsibility on organizations to improve their defenses.
Compliance and cybersecurity are separate areas.
However, increased regulation means businesses must pay close attention to both.
Recent court decisions have also changed how regulatory uncertainty may be handled.
Companies should be prepared for:
- New legal challenges
- Changing interpretations
- Updated reporting rules
- New compliance requirements
The best approach is to stay proactive.
Organizations should continue to monitor regulatory developments.
When resources allow, they should also invest in strong cybersecurity strategies.
These strategies should protect systems while also supporting compliance.
References
Global law enforcement takes down ransomware group that targeted U.S. hospitals and schools, NBC News
Cybersecurity Alerts & Advisories, CISA
Cyber Incident Reporting for Critical Infrastructure Act of 2022 – Notice of Proposed Rulemaking Informational Overview, CISA
SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, U.S. Securities and Exchange Commission
Supreme Court Ruling Threatens the Framework of Cybersecurity Regulation, Security Week
The Loper Bright Decision: How it Impacts Cybersecurity Law, The Hacker News


