Finally Heard – Cyber Help for Small Businesses is on Its Way
Client Alert | 1 min read | 08.22.18
New cybersecurity legislation was recently passed that aims to help smaller government contractors in their efforts to safeguard sensitive customer data. The NIST Small Business Cybersecurity Act requires the National Institute of Standards and Technology (NIST) to issue guidance and resources, within the next year, to help small- and medium-sized businesses identify, assess, and reduce cybersecurity risks. Partly in response to the rising number of cyberattacks targeting small businesses, the legislation is the latest in a series of efforts more broadly focused on supply chain security throughout the procurement process. Under the Act, NIST must also:
- Ensure future resources can vary with the nature and size of the small business, as well as the nature and sensitivity of the data handled.
- Encourage the use of technology neutral, commercial off-the-shelf (COTS) solutions.
- Promote awareness of basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 03.25.26
NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know
The National Association of Insurance Commissioners (NAIC) is intensifying its oversight of how insurers use AI — and the pace of regulatory activity shows no signs of slowing. Over the past several months, the NAIC has published a formal Issue Brief staking out its position on federal AI legislation, launched a multistate AI Evaluation Tool pilot aimed at examining insurers’ AI governance programs, and continued to expand adoption of its AI Model Bulletin across state lines. These developments continue a trend towards enhancing regulation; the NAIC adopted AI Principles in 2020 and a Model Bulletin in 2023 clarifying that existing insurance laws apply to AI systems and establishing expectations for governance, documentation, testing, and third-party oversight. That Model Bulletin has now been adopted in approximately 24 states.
Client Alert | 11 min read | 03.25.26
White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children
Client Alert | 3 min read | 03.24.26
California Considering A Massive Expansion of Its Antitrust Laws
Client Alert | 2 min read | 03.23.26

