Cybersecurity 2026

USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

3.6 Threat-Led Penetration Testing While other jurisdictions have implemented cyber- resiliency stress testing as part of their supervisory and review processes, the USA does not have an equivalent required-scenario stress test. Instead, financial institutions are encouraged to use stand - ardised tools that incorporate industry standards and best practices to determine their cybersecurity risk. These tools include: • the FFIEC Cybersecurity Assessment Tool (sunset - ting in August 2025); • the NIST Cybersecurity Framework, the Centre for Internet Security Critical Security Controls; and • the Financial Services Sector Coordinating Council Cybersecurity Profile. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation Legislation around cyber-resilience continues to develop in the USA, as follows. • The Federal Reserve, in co-ordination with the OCC and the FDIC, has issued guidance in the form of a paper on operational resilience, including an appendix of practices for cyber-risk manage - ment. • Some regulations impose transparency obligations related to cyber-resiliency. By way of example, the SEC requires publicly traded companies to disclose the measures they have taken to man - age certain cyber-related risks. NYDFS regulations (described in greater detail in 6.2 Cybersecurity and AI ) impose similar disclosure requirements and technical obligations regarding backup systems to promote resiliency. • Draft legislation that would create a task force to report on conclusions and recommendations to protect critical infrastructure from foreign state- sponsored threats has passed one house of Con - gress. 4.2 Key Obligations Under Legislation Draft legislation would create a task force to consider steps that critical infrastructure companies can take to

a speciality examination, such as an IT examination. The prudential regulators have the authority to super - vise TSPs (as described in 3.2 ICT Service Provider Contractual Requirements ) and TSPs are examined based on their risk level as calculated using a URSIT rating. Examinations of TSPs focus on issues such as: • the management of technology; • the integrity of data; and • the confidentiality of information. • Financial institutions are entitled to copies of the Report of Examination (ROE) of a TSP with which they have a contract. Cybersecurity control deficiencies are generally not subject to public enforcement actions by prudential regulators unless a financial institution suffers a major cybersecurity breach. Instead, the prudential regula - tors may issue a “matter requiring attention” (MRA), a “matter requiring immediate attention” (MRIA), or – in the case of the FDIC – a “matter requiring board attention” (MRBA), which are confidential supervisory findings that require the financial institution to take corrective action. The board of directors is expected to respond to MRAs, MRIAs, and MRBAs through written responses and progress reports, and the pru - dential regulators will continue to monitor corrective actions until they are resolved. If the corrective action is not satisfactory to the prudential regulators, MRAs and MRIAs could lead to further formal or informal investigation or enforcement action. Formal enforce - ment actions may include cease-and-desist orders, civil monetary penalty orders or other actions. 3.5 International Data Transfers The primary US restrictions on data transfers are not specific to the financial sector but apply more broadly to a range of identified transaction catego - ries. The restrictions were established via Executive Order 14117 (2024) and implemented via DOJ regula - tion at Title 28, CFR 202.101 et seq and restrict the transfer of certain categories of bulk sensitive data and government information to identified countries of concern. The executive order also identifies certain control measures for defined categories of sensitive transactions that are not outright forbidden.

470 CHAMBERS.COM

Powered by