1. Home
  2. |Insights
  3. |Congressional Sledgehammer Drops On DHS Cyber Insecurity

Congressional Sledgehammer Drops On DHS Cyber Insecurity

Client Alert | 1 min read | 09.27.07

Following a series of tough investigations and oversight hearings on cybersecurity in April and June with more to come, the House Homeland Security Committee dropped the hammer on DHS and its contractors in a letter on September 21, 2007, finding that cyber attacks on federal and contractor IT systems "have resulted in the loss of massive amounts of critical information," characterizing DHS and contractor responses as "misleading" and subject to potential criminal penalties under 18 U.S.C. 1001, and demanding a DHS IG investigation -- and referral for "criminal investigation" if appropriate. With contractors operating over 1,100 federal IT systems subject to the Federal Information Security Management Act (FISMA), future security breaches virtually assure Congressional investigations, as the Homeland Security Committee promised: "The Committee will continue to investigate security breaches, particularly those occurring among commercial contractors."

Insights

Client Alert | 13 min read | 06.12.26

EU Cyber Resilience Act Countdown: 11 September 2026 Incident/Vulnerability Reporting Deadline Less Than 100 Days Away

The EU Cyber Resilience Act (CRA) is an EU product cybersecurity law for connected products (formally, “products with digital elements” under the CRA) commercialized in the EU; it entered into force on 10 December 2024, with direct application across the EU. Full application begins 11 December 2027, but one of its most operationally demanding provisions takes effect in just under 100 days, on 11 September 2026: the mandatory vulnerability and incident reporting under Article 14 CRA....