Cybersecurity 2026

USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields

strengthen resilience against foreign state-sponsored attacks (see 4.1 Cyber-Resilience Legislation ).

• regular monitoring and testing; • training; and • assessments of third-party service providers. The Safeguards Rule also requires covered financial institutions to designate an individual with responsibil - ity for the programme, who must report in writing to the board at least annually. The Safeguards Rule also requires financial institutions to notify the FTC of secu - rity breaches involving the unauthorised acquisition of at least 500 consumers’ unencrypted information, no later than 30 days after discovering the event. In June 2025, the FTC provided new guidance on the Safeguards Rule, clarifying that automobile dealers that finance (or facilitate the financing of) automobiles are covered. HIPAA is the primary law that regulates data privacy and security for healthcare providers (see 6.3 Cyber- security and the Healthcare Sector for more details). Additionally, the SEC’s Regulation S-P (“Reg S-P”) requires broker-dealers, investment companies and registered investment advisers to: • provide notices about privacy practices; • institute written policies and procedures that safe - guard customer information; • securely dispose of consumer report information; and • adequately oversee third-party service providers. Reg S-P was amended in 2024 to require covered entities to implement an incident response plan and provide data breach notifications to affected individu - als whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorisation. Larger entities (eg, investment advisers with USD1.5 billion or more in assets under management) needed to comply by 3 December 2025, while smaller entities must comply with the amend - ments by 3 June 2026. State-Level Data Protection Regulation Many states have passed comprehensive data priva - cy laws that also include cybersecurity requirements. Typically, these state laws require covered entities to

5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Unlike Europe, the USA does not have any security certification requirements for information and commu - nications (ICT) products or services. CISA co-chairs the ICT Supply Chain Risk Management Task Force, a PPP tasked with identifying challenges and solutions for managing risks in the global ICT supply chain. That task force has issued several handbooks and resource guides to help the private sector manage supply chain risk in ICT. Separately, the Federal Com - munications Commission (FCC) has created a volun - tary cybersecurity labelling programme for wireless consumer internet of things (IoT) products – namely, the US Cyber Trust Mark. The Cyber Trust Mark is a label designed to demonstrate to consumers that devices with the label have met robust cybersecurity standards and was launched in 2025. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Federal Data Protection Regulation At the federal level, the GLBA directs covered financial institutions to provide notices about their information- sharing practices and to implement appropriate safe - guards to ensure the security of customer information and to protect against unauthorised access to it. The Safeguards Rule, one of the GLBA’s implementing regulations, includes prescriptive security require - ments, including the requirement to implement a written information security programme. This written information security programme must include: • risk assessments; • access controls; • data inventories; • encryption; • multi-factor authentication; • logging of access to customer information;

471 CHAMBERS.COM

Powered by