Cybersecurity 2026

USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

latory frameworks, states often act as the frontline co-ordinators for implementing resilience strategies, facilitating information sharing, and supporting critical infrastructure owners and operators. Resilience Responsibilities State responsibilities for enhancing the cyber-resil - ience of critical infrastructure are as follows. • Development of statewide cybersecurity strategies – many states have established cybersecurity offic - es or task forces to develop and implement strate - gies aimed at strengthening the resilience of public and private critical infrastructure. These strategies often align with federal initiatives, such as the NIST Cybersecurity Framework, while addressing state- specific risks and priorities. • Incident response co-ordination – states frequently serve as co-ordinators for incident response efforts through their state fusion centres and emergency operations centres. These entities work closely with CISA, local governments and private-sector stakeholders to respond to and recover from cyber incidents. • Infrastructure resilience grants and programmes – states administer federal grant programmes, such as the State and Local Cybersecurity Grant Pro - gram, to fund projects that enhance the resilience of critical infrastructure. These grants support initiatives such as system upgrades, cybersecurity State responsibilities regarding identifying cyberse - curity threats to critical infrastructure are as follows. • Threat intelligence sharing – state governments act as intermediaries between federal agencies and local entities by disseminating threat intelligence. This includes leveraging the federal Multi-State Information Sharing and Analysis Centre (MS- ISAC), which provides cybersecurity threat moni - toring, analysis and early warnings tailored to state and local governments. • Sector-specific threat monitoring – many states focus on monitoring threats to key sectors, such as water utilities, energy grids and healthcare facili - ties, which are often regulated at the state level. training and vulnerability assessments. Threat Identification Responsibilities

State public utility commissions and health depart - ments often collaborate with federal agencies to identify and mitigate threats. • Mandatory reporting and oversight – states enforce data breach reporting requirements for businesses and other entities operating within their jurisdic - tion. Virtually all states have enacted data breach notification laws, requiring organisations to report breaches involving personally identifiable informa - tion (PII) to affected individuals and, in many cases, the state Attorney General or other regulatory bod - ies. For instance: (a) some states (eg, California) mandate detailed reporting on the nature of the breach and steps taken to address it; and (b) some state laws also impose specific dead - lines for breach notifications, typically ranging between 30 and 90 days, depending on the jurisdiction. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation The Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Cur - rency (OCC) (together, the “prudential regulators”) consider cybersecurity to be a component of US financial institutions’ operational risk management framework, as described in the regulatory capital rules and elsewhere. Title V of the GLBA was the first federal law to require that financial institutions safeguard their customers’ non-public personal information (NPPI). The statute requires each prudential regulator to establish stand - ards for financial institutions to: • ensure the security and confidentiality of records containing NPPI; • protect against “any anticipated threats or haz - ards” to such records; and • protect against unauthorised access of such records (the “Safeguards Rule”).

467 CHAMBERS.COM

Powered by