Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Client Alerts 15 results

Client Alert | 4 min read | 08.14.26

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).  It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans.
...

Client Alert | 4 min read | 08.03.26

Short-Circuited: FCC Updates Covered List to Prohibit Foreign Power Inverters and Advanced Robotic Devices

On July 28, 2026, the Federal Communications Commission (FCC) updated its Covered List, established through the Secure and Trusted Communications Networks Act to include foreign-produced connected power inverters and advanced robotic devices. The designation of these products to the Covered List follows an Executive Branch national security determination that they “pose unacceptable risks to the national security of the United States or the safety and security of United States persons.” Equipment listed on the Covered List is ineligible for FCC equipment authorization, effectively prohibiting the import, sale, or marketing of those products absent an exception or approval. This action comes only months after the FCC added consumer-grade routers to the Covered List on March 23, 2026 and uncrewed aircraft systems (UAS) on December 22, 2025. Taken together, these actions reflect the FCC’s increasingly expansive approach to using its authorities to guard against foreign produced connected technologies that may create vulnerabilities enabling disruption of critical infrastructure, unauthorized access to sensitive information, or cyber intrusions. The shift is a departure from the FCC’s previous focus on equipment and services produced by certain PRC and Russian companies.
...

Client Alert | 7 min read | 07.08.26

Illinois Imposes Transparency and Safety Obligations on Frontier AI Systems

On July 6, 2026, Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence (AI) Safety Measures Act (the Illinois Act), to establish a framework for AI safety, transparency, and accountability for the world’s most powerful AI models. The governor’s approval follows unanimous passage of the bill by the Illinois House and nearly-unanimous support in the Illinois Senate in May. 
...

Client Alert | 4 min read | 06.25.26

Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity

On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking. The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it. Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking.
...

Client Alert | 6 min read | 06.17.26

GSA Issues Proposed AI Contract Clause, Seeks Feedback

The General Services Administration (GSA) is seeking public comment on a new GSA Regulation clause, 552.239-7001, Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems (LLMs), governing data safeguards and requirements prime contractors must comply with when providing or using LLMs under federal contracts. This updated clause (Revised Clause) reflects substantial revisions from an earlier version released in March 2026 (Original Clause) that faced substantial pushback from industry. Where the Original Clause cast a wide net — imposing obligations broadly across AI systems with little differentiation among supply-chain participants — the Revised Clause is more narrowly tailored. The Revised Clause:
...

Client Alert | 6 min read | 06.03.26

Executive Order Creates Voluntary Regulatory Regime of Frontier AI Models

On June 2, 2026, President Trump signed a highly anticipated artificial intelligence and cybersecurity Executive Order, “Promoting Advanced Artificial Intelligence Innovation and Security” (the EO), directing several national security and civilian agencies to ramp up scrutiny of cutting-edge AI models and bolster federal cybersecurity defenses against AI-enabled threats.
...

Client Alert | 7 min read | 05.19.26

American and Allied Cyber Agencies Issue First Joint Guidance on Securing Agentic AI

On May 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.S. National Security Agency (NSA), the Australian Cyber Security Centre, the UK National Cyber Security Centre, the Canadian Centre for Cyber Security, and the New Zealand National Cyber Security Centre, published joint guidance on the “Careful Adoption of Agentic AI Services” (Guidance).
...

Client Alert | 3 min read | 05.14.26

CISA’s “CI Fortify” Initiative Signals New Expectations for Critical Infrastructure Resilience: What Operators and Vendors Need to Know

On May 5, 2026, CISA announced CI Fortify — an initiative directing critical infrastructure owners and operators to prepare for geopolitical conflict in which OT networks are actively targeted while communications infrastructure is simultaneously degraded.
...

Client Alert | 5 min read | 04.27.26

Drift Protocol Exploit: Why “Social Trust” Is the Newest Cybersecurity Gap

The recent $285 million theft from Drift Protocol serves as a high-stakes reminder that the human element remains one of the biggest cybersecurity gaps in any organization. This was not a “hack” in the traditional sense of breaking through a digital wallet. North Korean actors used sophisticated social engineering to exploit human trust ―  highlighting what looks like a “hacking” risk into valuable lessons learned for cybersecurity oversight.
...

Client Alert | 2 min read | 04.10.26

Federal Agencies Warn of Iranian-Affiliated Cyber Actors Exploiting Internet-Facing Operational Technology Devices

On April 7, 2026, six federal agencies (FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command – Cyber National Mission Force) published a joint advisory warning that Iranian-affiliated threat actors are targeting internet-facing OT devices, particularly PLCs.  In some cases, the threat actors have caused operational disruptions and financial losses at U.S. critical infrastructure organizations by manipulating software files that contain configuration settings as well as showing false data on hardware and software dashboards and displays.
...

Client Alert | 7 min read | 04.02.26

Reducing Your Exposure: Liability Limitations for Cybersecurity-Compliant Organizations

Organizations facing cyber incidents increasingly encounter follow-on civil litigation alleging failures to implement reasonable security measures. In response, a growing number of states — the most recent being Oklahoma this year — have enacted safe harbor laws designed to both protect consumers and reward organizations that take a proactive, documented, and structured approach to cyber threats.
...

Client Alert | 5 min read | 03.30.26

Firewall Up: FCC Bars Foreign-Made Routers in New Covered List Update

On March 23, 2026, the Federal Communications Commission (FCC) updated its Covered List—a list of communications equipment and services deemed to pose an unacceptable risk to U.S. national security or the safety and security of U.S. persons—to include consumer-grade routers produced in a foreign country, absent an exemption granted by the U.S. Departments of War (DoW) or Homeland Security (DHS). This designation effectively prohibits the import of all consumer routers that are not produced in the United States.
...

Client Alert | 11 min read | 03.25.26

White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children

In its latest attempt to establish a national AI regulatory standard and quash “cumbersome” state AI laws, the White House on Friday, March 20, 2026, released legislative recommendations for a National Policy Framework on Artificial Intelligence. 
...

Client Alert | 5 min read | 03.11.26

Senate Advances Bipartisan Health Care Cybersecurity Reform

On February 26, 2026, the Senate Health, Education, Labor, and Pensions (HELP) Committee voted 22-1 to advance the Health Care Cybersecurity and Resiliency Act of 2026. Sponsored by a bipartisan group — led by HELP Committee Chair Senator Bill Cassidy (R-LA); and Senators Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX) — the bill represents perhaps the most significant federal legislative effort to overhaul health care cybersecurity since the passage of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009, and would compel health care companies to make major investments in cybersecurity.
...

Client Alert | 6 min read | 03.11.26

White House’s New Cyber Strategy and Executive Order Seek to Deter Adversaries and Strengthen Resilience

On March 6, 2026, the White House released its National Cyber Strategy (Strategy) and issued an accompanying Executive Order, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens” (EO). These documents outline the administration’s priorities for combating cybercrime and call for coordination across the federal government and the private sector to invest in new technologies, continue innovation, and prioritize the United States’ cyber capabilities. Key sectors of concern include energy, financial services, telecommunications, data centers, water, and health care. The Strategy and EO encourage increased public-private coordination, signal greater latitude for private sector offensive cyber operations, prioritize securing critical infrastructure, elevate cybercrime as a national security priority, outline a path for victim compensation, and promote streamlining cyber regulations.
...