Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Firm News 13 results

Firm News | 2 min read | 02.08.24

Crowell & Moring’s Privacy and Cybersecurity Group Named a Law360 Practice Group of the Year

Washington – February 8, 2024: Crowell & Moring’s Privacy and Cybersecurity Group has been named a Practice Group of the Year for 2023 by Law360.
...

Firm News | 4 min read | 10.18.23

New Cyber Resilience Guide Helps Executives Strengthen Cybersecurity

Today, ArmorText, a leading secure out-of-band communications platform, and the international law firm of Crowell & Moring released an innovative guide, Cyber Resilience: Incident Response Tabletop Exercises 2023. Written for C-suite executives, in-house counsel, and incident response teams, the toolkit is a resource for leaders as they help their organizations mitigate cyber threats and strengthen their incident response capabilities.

Firm News | 1 min read | 03.09.21

Crowell & Moring Participates In New York Cyber Task Force Report on Cyber Response Readiness

New York – March 9, 2021: Crowell & Moring partner Evan D. Wolff served as co-chair for Columbia University’s New York Cyber Task Force as it released a new report calling for businesses and governments to work together to establish a national cyber response network. The report, “Enhancing Readiness for National Cyber Defense through Operational Collaboration,” details recommendations to create a “whole-of-nation” approach to combat malignant cyber activity and improve cyber readiness.
...

Client Alerts 162 results

Client Alert | 2 min read | 03.21.24

Software Developments: CISA Finalizes Attestation Form, Triggering Secure Software Development Implementation

On March 11, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget (OMB) published an updated Secure Software Development Attestation Form, meaning that producers of software and providers of products containing software used by the federal government may be required to submit their attestations in the very near future. The Attestation Form, first published in April 2023, is a key cog in CISA’s implementation of software supply chain security requirements in accordance with Executive Order 14028, Improving the Nation’s Cybersecurity and OMB Memoranda M-22-18 and M-23-16.
...

Client Alert | 5 min read | 02.08.24

Who I(aa)S Your Foreign Customer? Department of Commerce Proposes Foreign Customer Identification Requirements For U.S. IaaS Providers

On January 29, 2024, the Department of Commerce released a proposed rule:  Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities, which solicits comments regarding a proposed  new set of regulations that would introduce significant new requirements for U.S.-based Infrastructure as a Service (IaaS) providers.  The proposed rule implements requirements from the January 2021 Executive Order Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities and part of the October 2023 Executive Order Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.  If Commerce implements the regulations as proposed, IaaS providers would be required to create a Customer Identification Program (CIP), ensure any foreign resellers maintain a CIP, track all customer identities, verify the identities of foreign customers, and report certain transactions implicating large AI models that could be used for malicious cyber-enabled activities.  The Department is soliciting comments on all aspects of the proposed rule by April 29, 2024.
...

Client Alert | 2 min read | 01.09.24

No Longer Cloudy: DoD Issues New Guidance on FedRAMP Moderate Equivalency Cloud Security Requirements

The Department of Defense (DoD) recently published a memorandum clarifying what it means for a cloud service provider (CSP) to be Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline “equivalent” and meet incident reporting requirements under Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012). The memorandum states, in order to be considered FedRAMP equivalent going forward, CSPs must (1) be FedRAMP Moderate/High-Authorized, or (2) secure a third-party assessment confirming their compliance with all FedRAMP Moderate baseline security controls.
...

Press Coverage 49 results

Press Coverage | 11.09.23

SEC/SolarWinds Legal Analysis w/Evan Wolff (podcast)

The Cyber Ranch Podcast

Publications 29 results

Publication | January 2024

Solarwinds Whips Up a Software Cybersecurity Storm

Contract Management Magazine

Events 44 results

Event | 02.07.24, 3:00 PM EST - 5:00 PM EST

Energy Transition Summit

Crowell & Moring Partner Evan Wolff, a member of the firm's Privacy & Cybersecurity Group, will be speaking at Energy Transition Summit, taking place February 5 - 8 in Arlington, VA. His presentation, "Contracting and Legal Trends of Cybersecurity for the Energy Transition" will take place from 3:30 p.m. - 5:00 p.m. EST.

The U.S. Department of Energy Grid Modernization Initiative and Office of Cybersecurity, Energy Security, and Emergency Response are excited to host the Energy Transition Summit: Grid Modernization Initiative and Clean Energy Cybersecurity. Attendees will learn about opportunities to engage with DOE-led efforts that are modernizing the future power grid and enabling a more resilient, secure, and equitable energy transition. This event will host thought leaders and working sessions to have a dialog about strategies for future energy systems through partnerships and technology transition across government, industry, research organizations, and local communities.

Event | 01.25.24, 5:00 PM PST - 7:30 PM PST

What Tech Start-Ups Need to Know in the Era of CMMC: Federal Government Contracting Perspectives

The Department of Defense (DOD)’s recent release of the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC) has shaken up cybersecurity requirements for companies looking do business with the Federal Government. These emerging requirements become increasingly arduous for startup companies in the technology space – albeit cloud computing, software or artificial intelligence.

Event | 06.29.23, 4:30 PM BST - 7:00 PM BST

Attack & Respond: Changing Cyber Strategies, What's New?

Registration is closed.

Join DXC Technology, Mandiant, and Crowell & Moring at Google's London office for networking and an informative discussion on recent cyber threats, security incidents, and best practices to reduce the risk of compromises.

Webinars 26 results

Webinar | 05.15.24, 1:00 PM EDT - 2:00 PM EDT

NIST SP 800-171 Transitions to Revision 3: What to Know

As the National Institute for Standards and Technology (NIST) prepares to release its highly anticipated Revision 3 to the security standard required by CMMC and current DoD contracts alike, join Crowell attorneys Evan Wolff and Michael Gruden in a robust discussion with one of the key architects of Revision 3, NIST’s own Senior Computer Scientist, Victoria Pillitteri.

Webinar | 02.14.24, 1:00 PM EST - 2:00 PM EST

CMMC 2.0: Legal, Assessor, and Threat Intelligence Perspectives

Members of Crowell’s Privacy & Cybersecurity practice and panelists from Coalfire and Mandiant will discuss the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC) issued by the Department of Defense (DOD) in December.

Webinar | 01.09.24, 1:00 PM EST - 2:00 PM EST

CMMC Proposed Rule: What to Know

The Department of Defense (DOD) has released the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC). CMMC is a unified assessment model released by the DoD in response to the growing threat of cyberattacks and data theft from its supply chain vendors. As proposed, this program requires every Federal contractor that handles DoD sensitive data to comply with certain cybersecurity controls. CMMC will bring greater scrutiny to contractors’ cybersecurity compliance and greater risks associated with failure to comply. To achieve certification, you’re required to prove that your organization can meet a myriad of security control obligations, a process that can be daunting if you’re not familiar with the policies, procedures, and practices that may be required when the program is finalized.

Blog Posts 17 results

Blog Post | 02.10.20

Energy Cybersecurity Act of 2019

Crowell & Moring's Data Law Insights

Blog Post | 08.20.19

Privacy & Cybersecurity – New York Enacts the SHIELD Act

Crowell & Moring's International Trade Law

Podcasts 19 results

Podcast | 02.15.22

Byte-Sized Q&A: What Should Contractors Know About the Cybersecurity Provisions Included In, and Left Out Of, the National Defense Authorization Act

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces.  In this episode, Evan Wolff and Chris Hebdon discuss the notable cybersecurity provisions and omissions in the National Defense Authorization Act (NDAA) for Fiscal Year 2022.
...

Podcast | 01.19.22

Byte-Sized Q&A: What is CISA and Why is it Important to Government Contractors?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode of Byte Sized Q&A, Evan Wolff and Michael Gruden discuss the Cybersecurity Infrastructure Security Agency (CISA) and why it is important for contractors to take note of CISA’s actions.
...

Podcast | 12.03.21

Byte-Sized Q&A: What’s not in CMMC 2.0?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, hosts Evan Wolff and Kate Growley talk through some key elements that are no longer expected under CMMC 2.0.
...