Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
FBI and CISA Issue Advisory on Scattered Spider Ransomware Attacks
Blog November 27, 2023
On October 30, 2023, President Biden issued an executive order (EO) to guide federal agencies on the development and use of artificial intelligence (AI). The administration views AI as holding numerous benefits but at the same time cautions it could exacerbate societal harms if not responsibly managed…
CISA and Partners Update the #StopRansomware Guide, Developed through the Joint Ransomware Task Force
Blog May 24, 2023
On May 23, 2023, CISA, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published an updated version of the #StopRansomware Guide, as ransomware actors have accelerated their tactics and techniques since its initial release in 2020. The update incorporates lessons learned from the past two years and includes additional recommended actions…
Physical and Cyber-Attacks on Energy Infrastructure Expected to Continue
Blog May 03, 2023
Over the past several years, the energy sector has become a prime target for hacking and ransomware attacks, with over 40 attacks on the industry since 2017.  Cyber attacks have only continued to rise, with a record high of 13 reported attacks in one year occurring in 2022. Physical Security Threats to U.S. Energy Infrastructure A new type of threat against the energy sector crystallized at the end of 2022: physical attacks on the grid…
HHS Office for Civil Rights Posts HIPAA Security Rule Security Incident Procedures
Blog October 26, 2022
Every October, in recognition of National Cybersecurity Awareness Month, the federal government and its partners work to educate stakeholders on cybersecurity awareness and how best to protect the privacy and security of confidential data. Within the health care industry, the HIPAA Security Rule applies to covered entities and their business associates (“regulated entities”) and electronic protected health information (ePHI).  Because ePHI identifies individuals and includes information……
Federal Agencies Issue Alert Regarding Maui Ransomware
Blog July 26, 2022
On July 7, 2022, three federal agencies – the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and the Department of the Treasury – issued a joint alert regarding Maui Ransomware, which has been linked to ransomware attacks on healthcare and public health entities carried out by North Korean state-sponsored cyber actors. These are the key recommendations of the alert: Since at least May 2021…
CISA on Russia, Ukraine and Ransomware
Blog January 30, 2022
According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the potential hostilities between Russia and Ukraine are likely to spill over into cyber warfare.  In this months CISA Insights: Every organization in the United States is at risk from cyber threats that can disrupt essential services and potentially result in impacts to public safety. Over the past year, cyber incidents have impacted many companies…
Ransomware Payments – OFAC Updates its Advisory and Congress Gets Involved
Blog October 01, 2021
Ransomware payments continue to be a focus of the U.S. Treasury Department's Office of Foreign Assets Control (“OFAC”). As previously reported by Foley Hoag, on October 1, 2020, OFAC released an advisory regarding potential sanctions risks related to facilitating ransomware payments. Almost a year later, on September 21, 2021, OFAC updated its advisory to provide additional guidance regarding what OFAC considers to be mitigating factors if facilitating a ransomware payment results in an……
Biden Issues Memorandum Aimed at Improving Cybersecurity
Blog July 30, 2021
On July 28, 2021, President Biden issued a Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems.  The Memo recognizes that the protection of the nation's critical infrastructure lies not only with government, i.e., at the federal, state, local, tribal, and territorial levels, but with critical infrastructure owners and operators.  In addition, the Memo states that cybersecurity threats to critical infrastructure, and the systems that control and operate it…
Kaseya VSA Cyberattack:  What Kaseya and the Feds Are Saying
Blog July 06, 2021
If you arent following the ransomware attack on Kaseyas VSA product and approximately 800-1500 of its users, you should be.  Like many cyberattacks, this one came on the verge of a holiday weekend.  As the company itself notes, Kaseya's VSA product has unfortunately been the victim of a sophisticated cyberattack.   Due to our teams' fast response, we believe that this has been localized to a very small number of on-premises customers only…
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors