USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
ment and also regulates the manner in which the government may seek compelled access to stored electronic communications and data through legal process. In addition, the Wiretap Act and the Pen Register Act criminalise the unlawful interception of content and non-content data, respectively. In addition to these cybersecurity-specific laws and regulations, some more general regulations have been enforced with regard to cybersecurity. For example, Section 5 of the Federal Trade Commission Act empowers the Federal Trade Commission (FTC) to regulate and enforce against unfair or deceptive trade practices in general. The FTC and federal courts have interpreted this regulation to permit the regula - tion and enforcement of cybersecurity where com - panies’ security practices (and public representations concerning those practices) may qualify as unfair or deceptive. In addition to formal statutory and regulatory require - ments, recent administrations have made broad use of executive orders to direct regulators’ investigatory scrutiny and rulemaking priorities. Finally, in addition to federal regulations, many states impose cybersecurity obligations through statutes or regulations. Some states require, by statute, that companies take reasonable measures to protect the sensitive personal information of state residents, with varying levels of specificity about which measures are required or deemed reasonable if employed. Oth - er states have more developed regulatory regimes, including the California Consumer Privacy Act. For more details on cybersecurity regulations promul - gated by New York State’s Department of Financial Services (NYDFS), see 6.2 Cybersecurity and AI . 1.3 Cybersecurity Regulators At the federal level, the main cybersecurity regulators include: • the FTC, which – as noted in 1.2 Cybersecurity Laws – regulates cybersecurity as part of its broad authority to regulate and enforce against unfair or deceptive trade practices; • the Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), and the Department
of Homeland Security (DHS), which investigate and prosecute federal criminal activity, including cyber- intrusions and cyber-enabled crime; • the DHS, which regulates critical infrastructure and other aspects of national security; • the Department of Health and Human Services (HHS), which enforces HIPAA regulations – includ - ing those related to data protection – over covered providers; and • the SEC, which regulates publicly traded compa - nies and imposes disclosure obligations following cybersecurity breaches. Federal regulators have the authority to promulgate regulations with the force of law following a public notice-and-comment process, as well as to enforce those regulations through civil investigations (includ - ing compulsory disclosure of documents and testi - mony) and litigation. At the state level, cybersecurity may be regulated by state Attorneys General or subdivisions within their offices. Some states have established cybersecurity- specific agencies, such as the Utah Cyber Centre, and others have conferred authority to sector-specific regulators, such as the NYDFS. For more details on the NYDFS, see 6.2 Cybersecurity and AI . 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation In the USA, CIRCIA requires critical infrastructure enti - ties to report covered cyber-incidents to the Cyberse - curity and Infrastructure Security Agency (CISA) within 72 hours and ransomware payments within 24 hours. The applicable rules for covered entities under CIR - CIA are still under development and, though slated for finalisation in 2026, the status or prospects for final release are unclear as of the time of writing. The regulation, released in draft form on 4 April 2024, pur - ports to further define the categories of entities and incidents subject to the reporting regime. The scope of application under CIRCIA is intention - ally broad, encompassing entities across all 16 criti -
464 CHAMBERS.COM
Powered by FlippingBook