White House Issues Cybersecurity Plan for Agencies and Contractors
Client Alert | 1 min read | 11.03.15
On October 30, the White House issued a "Cybersecurity Strategy and Implementation Plan" that directs all agencies to undertake a series of specific actions to identify and address cybersecurity gaps and priorities, including the "efficient and effective acquisition and deployment of existing and emerging technology." The Plan builds upon the proposed OMB guidance issued in August and calls for several actions, including (i) enhancing personal identity verification credentials for all federal employees and contractors; (ii) exploring contract vehicles for rapid incident response services; (iii) developing recommendations for how agencies can collectively implement commercially available products and services; (iv) improving government-wide incident reporting, response, and recovery practices; and (v) identifying gaps in cyber-talent across agencies and their contractors.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 3 min read | 09.15.26
Until recently, Belgian law did not have a general regulatory framework for internal investigations. Companies wishing to conduct an investigation had to navigate a fragmented set of rules that covered general principles and, to a limited extent, privacy and employee rights. The application of these rules to internal investigations was not clear, and it was therefore often difficult to put the rules into practice. This legal vacuum created significant risks, both for the integrity of the investigation itself and for the admissibility of any evidence gathered.
Client Alert | 7 min read | 09.14.26
AI in Life Sciences: Ten Legal Considerations and Risks of AI Use in Drug Discovery and Development
Client Alert | 6 min read | 09.14.26
Mental Health Parity Bulletin Restates Best Practices for Evaluating Compliance
Client Alert | 6 min read | 09.11.26
It’s LIVE: The Cyber Resilience Act Reporting Is Mandatory as of Today - 11 September 2026

