
There’s a New Cyber Sheriff in Town
“Data protection” is an umbrella concept that incorporates both cybersecurity and data privacy. The European Union has been the leader in advancing this concept first with its Data Protection Directive and now with its General Data Protection Regulation. The influence of these laws on the U.S. has been profound. Recently, the SEC issued guidance for publicly-traded companies mandating, among other things, notification of data breaches within four days and publication of the company’s cybersecurity risk management processes. Such national-level breach notification mandates have appeared in other contexts in the U.S. as well as the EU. Moreover, the advent of generative artificial intelligence has greatly amplified the power of cyber threat actors. Private companies that conduct business with public companies or may merge with a public company will likely wish to adhere to these standards as well. Overall, data protection is now a board-level matter.




















