These Are a Few of Our Favorite IoT: NIST Finalizes Internet of Things Cyber Guidance
Client Alert | 1 min read | 07.02.19
NIST has finalized Internet of Things (IoT) risk management guidance, which derived from a draft publication. The guidance informs government agencies how to understand and manage IoT risks throughout device lifecycles. Industry can anticipate government focus on three high-level goals:
- Device security;
- Data security; and
- Individual privacy.
The publication highlights three differences between managing risks for IoT devices and conventional information technology devices:
- IoT devices interact with the physical world differently than conventional devices;
- IoT devices cannot be accessed and monitored the same as conventional devices; and
- The availability and effectiveness of cybersecurity and privacy capabilities are different for IoT devices than conventional devices.
While not mandatory, the guidance provides useful considerations for IoT cybersecurity and privacy risk management.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
On August 13, 2026, the Centers for Medicare and Medicaid Services (CMS) published its final rule banning the use of federal funds — through Medicaid and the Children’s Health Insurance Program (CHIP) — to pay for gender-affirming care for children and youth. The final rule takes effect October 13, 2026 (“Prohibition on Federal Medicaid and Children's Health Insurance Program Funding for Sex-Rejecting Procedures Furnished to Children”). While CMS finalized several key elements of its late-2025 proposed rule (Client Alert December 24, 2025), the proposed Medicare hospital Condition of Participation rule remains in proposed form.
Client Alert | 2 min read | 08.19.26
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

