NY DFS Cybersecurity Regulation (23 NYCRR 500): Financial Services Requirements
New York's cybersecurity regulation for financial services requires covered entities to maintain comprehensive security programs including CISO designation, MFA, encryption, and incident reporting. The 2023 amendments are fully effective as of November 2025.
HIPAA Security Rule Overhaul: What the 2026 Proposed Changes Mean for Healthcare
HHS proposed sweeping changes to the HIPAA Security Rule in January 2025, eliminating the addressable vs. required distinction and mandating encryption and MFA. Finalization targeted for May 2026.
Identity and Access Management: Best Practices for 2026
A practical guide to implementing identity and access management (IAM), covering authentication, authorization, privileged access, lifecycle management, and Zero Trust identity principles.
Snowflake Customer Data Theft Campaign — 165+ Organizations Compromised
A credential theft campaign targeting Snowflake customer accounts without MFA resulted in data theft from over 165 organizations including Ticketmaster, AT&T, Santander, and Advance Auto Parts.