Cloud & IT Staffing Solutions in Chicago, Boston, Dallas
1

CyberSecurity

Cybersecurity Regulations: A Shifting Reality

Tech Hiring Company Chicago - Peterson Technology Partners
Tech Hiring Company Chicago - Peterson Technology Partners

DATE POSTED

August 16, 2024

Table of Contents

WRITTEN BY

Nick Shah
Nick Shah
Nick Shah is the Founder and President of Peterson Technology Partners (PTP), Chicago’s premiere IT staff augmentation agency. With his relationship-focused mentality and technical expertise, Nick has earned the trust of Chicago-based Fortune 100 companies for their technical staffing needs.
Cybersecurity Regulations

Do cybercrime statistics ever shock you anymore?  

The stats from emerging cyber threats are truly mind-boggling: cybercrime is up 30% in Q2 2024 (year to year), just under 90% of US businesses reported suffering a cyberattack in the last year, and global damage estimates are up to $10.5 trillion by 2025.  

Consider this, from Cybercrime Magazine: the growth in cybercrime from 2015 to 2025 will be the greatest transfer of financial wealth in history, and be greater than the global total for natural disaster damage over a year. It will generate more profit for the criminals than the global trade of all illegal drugs combined. 

It should be no surprise that governments across the world are desperate to act.  

Ransomware, which has drawn increasing focus as it has paralyzed health care institutions worldwide, has been a particular focus for law enforcement. But despite real victories (like the breakup of LockBit and outing of its notorious leader), there are still regular reports like the one I read on Forbes last week, that a Fortune 50 company paid out a $75 million ransom earlier this year.  

And we don’t even know who it is.  

Earlier we looked at EU regulations and their clash with big tech. In this article we take on government cybersecurity regulations for 2024, the impact recent Supreme Court rulings will have, and what companies must do to navigate such waters.   

The Current Regulatory Landscape 

It’s hard to see the full scope of the problem with so many unreported attacks, making it unsurprising that recent cybersecurity law changes emphasize reporting 

Of course, it’s easy to understand why companies don’t always report in a timely fashion—they risk further attack via vulnerabilities they may not yet fully understand, suffer damage to their reputation, and risk exposure to litigation and government rebuke. 

The Cybersecurity and Infrastructure Security Agency (CISA) dates back to 2018 (taking over from an office in the Department of Homeland Security) and has continued ramping up since its creation. It issues directives to steer other government agencies, oversees detection, and handles incident response.  

CISA was key in drafting the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), from 2022. CIRCIA mandates reporting, and for CISA CIRCIA compliance, critical infrastructure entities (or their lawyers, insurance providers, or cybersecurity specialists) must report incidents to CISA within 72 hours, and all ransomware payments within 24 hours.  

[CISA is also involved in AI regulation. For more information, see my article on Substack.] 

Other Federal Regulations 

The Securities and Exchange Commission (SEC) was not originally created with cybersecurity as a primary focus, but that has changed with its 2023 rules around cybersecurity risk management and incident reporting. Under these requirements, public companies must disclose significant cybersecurity incidents within four business days, including details about the nature, scope, timing, and impact of the event.

The SEC also requires annual disclosures outlining how companies manage cybersecurity risks, including their security strategies, processes, and leadership oversight.

The Federal Trade Commission (FTC) Safeguards Rule, originally introduced in 2003, has also evolved to address modern cybersecurity concerns. It applies to nonbank financial organizations and businesses that collect, store, or process customer information, including personally identifiable information (PII).

Under the updated requirements, organizations must implement security measures such as encryption, multi-factor authentication, risk assessments, security monitoring, employee training, and incident response plans. Companies must also designate a responsible individual to oversee cybersecurity efforts.

The FTC has introduced additional breach notification requirements, requiring organizations to notify the agency as soon as possible — and no later than 30 days — after breaches affecting more than 500 customers.

These regulations highlight a growing focus on accountability, requiring organizations to not only strengthen cybersecurity protections but also provide greater transparency when incidents occur.

State-Level Regulations 

Of course, it doesn’t end there. 

47 states and the District of Columbia have enacted their own cybersecurity laws, covering things like cybersecurity posture, breach notification, and data protection.   

California’s are among the most stringent, with the California Consumer Privacy Act (CCPA) from 2023 (inspired by the EU’s GDPA, joining additional regulations requiring detailed notifications. 

Sector-Specific Regulations 

In the healthcare sector, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) requires organizations to report breaches involving Protected Health Information (PHI). The Health Insurance Portability and Accountability Act (HIPAA) also establishes data protection requirements for healthcare organizations and cloud providers that handle sensitive health information.

The Gramm-Leach-Bliley Act (GLBA), enforced by the FTC, has expanded its focus on cybersecurity requirements for financial institutions, including stronger data protection and incident reporting expectations. Similarly, the Transportation Security Administration (TSA) has introduced cybersecurity requirements for passenger and freight rail carriers, airports, and aviation companies. These rules include measures such as designating cybersecurity contacts, conducting continuous monitoring and testing, maintaining incident response plans, and improving cyber resilience to support ongoing operations.

These regulations demonstrate the complex and evolving cybersecurity landscape, where requirements vary significantly based on an organization’s industry, location, and the type of data it manages.

The Shifting Ground 

For businesses, the cybersecurity regulatory landscape is becoming even more complex, especially as many requirements are based on agency rules rather than laws passed by Congress and signed by the President.

Recent Supreme Court decisions, including the Loper Bright decision, add further uncertainty. The ruling overturned the long-standing Chevron deference, which previously allowed government agencies greater authority to interpret unclear laws. This authority now shifts more toward the courts, meaning cybersecurity regulations may face more frequent reviews and changes.

For organizations, this creates an environment of ongoing regulatory uncertainty. Companies may need to adapt to evolving interpretations of rules such as CISA’s implementation of CIRCIA, proposed FTC updates related to children’s online privacy and healthcare data protection, as well as existing requirements from agencies like the SEC, GLBA regulators, and TSA.

As cybersecurity threats continue to grow, businesses will need to stay informed and remain flexible to comply with changing regulatory expectations across industries.

Cybersecurity Risk Management Strategies 

This is by no means an exhaustive look at regulations, when you consider the CFAA, FISMA, the ECPA, COPPA, and more.  

But at issue is this: facing such a varied tapestry, how can companies stay on top of cybersecurity compliance challenges? 

Budget, scale, and sector are key, of course, but overall, this is my advice: 

  • Designate your point of contact: Many regulations require a point of contact for cybersecurity issues, and of course it makes sense to have someone trusted within your organization to be the point of this spear.  
  • Understand current obligations: Begin by getting a comprehensive picture of what requirements you have now for cybersecurity protection, reporting, and crisis management. Given the wide spread of institutions and varied levels of coverage, this is not easy, but it is absolutely essential. 
  • Perform your own risk assessment: Assemble a cross-functional team if possible, to help compare current readiness matches to not only the required, but the likely trajectory. Do you have gaps that need addressing? Adequate legal counsel, demonstrable plans, and reporting? 
  • Monitor and test and be ready to demonstrate how: Many regulations require proof of consistent monitoring, so that companies are aware when events happen, and will not be late to learn of attacks. Consider automated testing innovations where possible and affordable.  
  • Have a tried and tested incident response plan: Also a common regulatory requirement, it’s just good sense to have rapid response capabilities in place, both to limit the fallout from cyber incidents and to help sustain business continuity. 
  • Invest in training: I repeat this over and over, but it’s relevant here as well—your best defense against cybercrime is a trained workforce. It’s also mandated by some regulations, and can be included in your readiness plans.  
  • Stay informed: Once you’re ready, expect change. As discussed, legal challenges in the US landscape are going to trigger changes in requirements and coverage, and this will require regulatory monitoring, just like your cybersecurity itself.  

[Another method to stay informed is to read The PTP Report, which includes regular cybersecurity roundups and coverage of current events.] 

For additional guidance on cybersecurity readiness, you can also look to my Substack, where I cover topics from essential strategies for business owners, to protecting a remote workforce. 

Conclusion 

The cybersecurity trends of 2024 highlight a growing challenge: cyberattacks are becoming more frequent and more sophisticated, and this trend is expected to continue.

At the same time, governments are increasing their focus on cybersecurity by introducing stronger requirements and placing more responsibility on organizations to improve their defenses.

While compliance and cybersecurity are separate areas, increased regulation means businesses must pay closer attention to both. With recent court decisions changing how regulatory uncertainty is handled, companies should be prepared for continued changes and legal challenges around cybersecurity requirements.

The best approach is to stay proactive. Organizations should continue monitoring regulatory developments and, when resources allow, invest in strong cybersecurity strategies that not only protect their systems but also support compliance requirements.

References 

Global law enforcement takes down ransomware group that targeted U.S. hospitals and schools, NBC News 

Cybersecurity Alerts & Advisories, CISA 

Cyber Incident Reporting for Critical Infrastructure Act of 2022 – Notice of Proposed Rulemaking Informational Overview, CISA 

SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies, U.S. Securities and Exchange Commission 

Supreme Court Ruling Threatens the Framework of Cybersecurity Regulation, Security Week 

The Loper Bright Decision: How it Impacts Cybersecurity Law, The Hacker News 

WRITTEN BY

Nick Shah
Nick Shah
Nick Shah is the Founder and President of Peterson Technology Partners (PTP), Chicago’s premiere IT staff augmentation agency. With his relationship-focused mentality and technical expertise, Nick has earned the trust of Chicago-based Fortune 100 companies for their technical staffing needs.

PREVIOUS POST

Spotlight on Innovation: Innovators Shaping 2024 and Beyond

NEXT POST

Adobe Experience Manager for Enhanced Digital Experiences

IT Staffing Firm - PTP