Categories

Archives

The U.S. Federal Government Continues Its Focus on Ransomware Attacks: CISA, FBI, and NSA Publish Technical Advisory on the Conti Group

On September 22, 2021, the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) published a cybersecurity advisory (the “Advisory”) outlining the Conti ransomware group’s tactics, techniques, and procedures (“TTPs”) to help companies protect against their attacks. This Advisory is especially notable because it is an example of the type of information sharing promised by the Biden administration, which includes technical details about the Conti group’s TTPs. It also heralds the launch of new website called: StopRansomware.gov. (more…)

Is the SEC Coming for Your Texts? SEC’s New Enforcement Director Telegraphs a Warning to Registrants About Improper Use of Personal Devices for Business-Related Communications

The U.S. Securities and Exchange Commission (SEC) Division of Enforcement is stepping up investigative efforts looking at registered firms’ use of personal devices for business communications, which can implicate their recordkeeping obligations and result in failure to retain and produce responsive business-related communications in SEC investigations. These risks are particularly acute in the current work-from-home posture at many firms, where employees may more easily blur the line between personal and business communications. Firms should review their policies, procedures, and communication monitoring to ensure that employees are not engaging in business-related communications outside of the firm’s official channels and in a manner that the firm is unable to capture and preserve if required.

(more…)

Stephen L. Cohen

Washington, D.C., Boston, ...

scohen@sidley.com

Data Breaches are More Expensive than Last Year, New IBM Security Report Finds

Death, taxes and data breaches. Cybersecurity incidents have grown in frequency, scale and seriousness. As articulated in President Biden’s May 2021 Executive Order, Improving the Nation’s Cybersecurity, “[t]he United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy.” These threats lead to direct costs on victims, and these costs have also grown exponentially in recent years, as readers of the famed annual Ponemon data breach report well know.  This year’s report is out, and confirms the continuation of a troubling trend. (more…)

Changes to FTC Rulemaking Procedures Herald More Aggressive Action on Consumer Privacy

On July 22, 2021, the Federal Trade Commission finalized important changes to its procedures for rulemaking under Section 18 of the FTC Act. Section 18 authorizes the Commission to make regulations, termed “Trade Regulation Rules,” (or “Magnuson-Moss Rules” after their authorizing statute), which “define with specificity” conduct that violates the FTC Act’s ban on “unfair or deceptive” business practices. Section 18 rules are promulgated through a “hybrid rulemaking” process that includes, if an interested party requests it, an “informal hearing” with limited opportunities for oral presentation and cross-examination by representatives of stakeholder groups. (more…)

Rohit Chopra Confirmed as CFPB Director; Historically Active Enforcement and Regulatory Regime Begins

On September 30, the U.S. Senate confirmed Commissioner Rohit Chopra of the Federal Trade Commission as the new Director of the Consumer Financial Protection Bureau (CFPB). Director Chopra is expected to usher in a regime of dramatically increased enforcement and creative, expansive regulation. Many financial institutions will have questions and concerns about the CFPB, how it will affect their businesses and operations, and how to productively engage with this exceptionally powerful and opaque regulator. It is now more important than ever to closely follow the work of the CFPB as new leadership seeks to aggressively employ all of the agency’s tools in service of the American consumer. (more…)

SEC Fines Alternative Data Provider for Securities Fraud

On September 14, 2021, the U.S. Securities and Exchange Commission (SEC) settled an enforcement action against App Annie Inc., an alternative data provider for the mobile app industry, and its former CEO Bertrand Schmitt. The SEC charged App Annie and Schmitt with securities fraud, under Section 10(b) of the Securities Exchange Act of 1934 and Rule 10b-5, for engaging in deceptive practices and materially misrepresenting how App Annie derived its alternative data, thereby inducing trading firms to become subscribers to use App Annie’s data in their decisions to buy and sell securities.  (more…)

The Burden of Privacy In Discovery

*This article first appeared on Judicature in Summer 2021

With the proliferation of social media platforms and other new technologies has come a renewed legal focus on privacy. Most of that focus has centered on data collection, storage, sharing, and, in particular, third-party transactions in which customer information is harnessed for advertising purposes. But what about other contexts? Could a party, for instance, decline to produce, review, or even collect certain types of data due to privacy concerns? Should privacy be considered a “burden” under the proportionality analysis required by Federal Rule of Civil Procedure Rule 26(b)?

In this essay, Robert D. Keeling and Ray Mangum, a partner and associate, respectively, at Sidley Austin LLP, argue that privacy should be considered a burden under Rule 26(b).

(more…)

Federal Trade Commission Hosts Panels Related to Consumer Privacy and Data Security at PrivacyCon

This summer, the Federal Trade Commission (“FTC”) hosted its sixth annual PrivacyCon, an event focused on the latest research and trends related to consumer privacy and data security. This years’ event was divided into six panels: Algorithms; Privacy Considerations and Understandings; Adtech; Internet of Things; Privacy-Children and Teens; and, Privacy and the Pandemic. Welcoming attendees and kicking off the event, Commissioner Rebecca Kelly Slaughter called for minimization of data abuses and for a move away from the notice and consent model of privacy in favor of data minimization. PrivacyCon topics are selected by the FTC and often seen as an indication of enforcement priorities. (more…)

Upcoming Events

Resources

 

Meet the Team

<a target=‘_blank’ href="https://www.sidley.com/en/people/a/akowuah-kwaku-a">Kwaku A. Akowuah</a>

Kwaku A. Akowuah

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/a/armbrust-sheila-a-g">Sheila A.G. Armbrust</a>

Sheila A.G. Armbrust

San Francisco
<a target=‘_blank’ href="https://www.sidley.com/en/people/b/blythe-francesca">Francesca Blythe</a>

Francesca Blythe

London
<a target=‘_blank’ href="https://www.sidley.com/en/people/b/brown-colleen-theresa">Colleen Theresa Brown</a>

Colleen Theresa Brown

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/c/casanova-john-m">John M. Casanova</a>

John M. Casanova

London
<a target=‘_blank’ href="https://www.sidley.com/en/people/c/cunningham-thomas-d">Thomas D. Cunningham</a>

Thomas D. Cunningham

Chicago
<a target=‘_blank’ href="https://www.sidley.com/en/people/f/flanagan-sharon-r">Sharon R. Flanagan</a>

Sharon R. Flanagan

San Francisco, Palo Alto
<a target=‘_blank’ href="https://www.sidley.com/en/people/g/gordon-david-a">David A. Gordon</a>

David A. Gordon

Chicago
<a target=‘_blank’ href="https://www.sidley.com/en/people/i/ishiara-tomoki">Tomoki Ishiara</a>

Tomoki Ishiara

Tokyo
<a target=‘_blank’ href="https://www.sidley.com/en/people/k/keeling-robert-d">Robert D. Keeling</a>

Robert D. Keeling

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/lally-amy-p">Amy P. Lally</a>

Amy P. Lally

Century City
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/lashway-david-c">David C. Lashway</a>

David C. Lashway

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/long-william-rm">William RM Long</a>

William RM Long

London
<a target=‘_blank’ href="https://www.sidley.com/en/people/l/loughnane-joan-m">Joan M. Loughnane</a>

Joan M. Loughnane

New York
<a target=‘_blank’ href="https://www.sidley.com/en/people/m/malhotra-geeta">Geeta Malhotra</a>

Geeta Malhotra

Chicago
<a target=‘_blank’ href="https://www.sidley.com/en/people/n/nash-glenn-g">Glenn G. Nash</a>

Glenn G. Nash

Palo Alto
<a target=‘_blank’ href="https://www.sidley.com/en/people/r/ransom-rollin-a">Rollin A. Ransom</a>

Rollin A. Ransom

Los Angeles
<a target=‘_blank’ href="https://www.sidley.com/en/people/r/raul-alan-charles">Alan Charles Raul</a>

Alan Charles Raul

Washington, D.C., New York
<a target=‘_blank’ href="https://www.sidley.com/en/people/s/seale-jennifer-b">Jennifer B. Seale</a>

Jennifer B. Seale

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/t/tham-yuet-ming">Yuet Ming Tham</a>

Yuet Ming Tham

Singapore, Hong Kong
<a target=‘_blank’ href="https://www.sidley.com/en/people/w/wilan-jonathan-m">Jonathan M. Wilan</a>

Jonathan M. Wilan

Washington, D.C.
<a target=‘_blank’ href="https://www.sidley.com/en/people/w/woods-jr-john-w">John W. Woods Jr.</a>

John W. Woods Jr.

Washington, D.C.

SUBSCRIBE

To receive email alerts when we post a blog entry, please provide your name and email address.