{"id":3694,"date":"2024-05-22T09:00:00","date_gmt":"2024-05-22T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/preparing-your-organization-upcoming-cybersecurity-deadlines"},"modified":"2024-05-22T09:00:00","modified_gmt":"2024-05-22T14:00:00","slug":"preparing-your-organization-for-upcoming-cybersecurity-deadlines","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/22\/preparing-your-organization-for-upcoming-cybersecurity-deadlines\/","title":{"rendered":"Preparing Your Organization for Upcoming Cybersecurity Deadlines"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt1a6050ca990197d7\/664cd88bdcead0c07daddecd\/Cybersecurity%281800%29_vska_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As our world becomes increasingly digitized, malicious actors have more opportunities to carry out attacks. Data breaches and ransomware are on the rise, and the urgency to fortify our digital defenses has never been greater. With <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/explodingtopics.com\/blog\/cybersecurity-stats\" rel=\"noopener\">one cyberattack occurring every&nbsp;39 seconds<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, there&#8217;s a critical and immediate need for enhanced cybersecurity measures.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aside from causing financial and reputational harm, cyberattacks also carry the real possibility of negatively impacting our physical world. We&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/news\/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years\" rel=\"noopener\">saw this happen in 2021<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> when a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/2-years-after-colonial-pipeline-attack-us-critical-infrastructure-remains-as-vulnerable-to-ransomware\" rel=\"noopener\">ransomware attack shut down Colonial Pipeline<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, causing shortages of gasoline, jet fuel, and home heating oil across the East Coast, which subsequently led to consumer panic-buying and a spike in gas prices.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat landscape is expanding rapidly, and everything from companies&#8217; data to our country&#8217;s critical infrastructure is at risk. Adding to the challenge, AI is enabling cybercriminals to execute more sophisticated attacks at a larger scale. Meanwhile, both federal and state regulators have introduced new rules and mandates aimed at holding organizations accountable when it comes to cybersecurity, and deadlines to comply are fast approaching.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Below, we&#8217;ll explore two of these new requirements and how organizations can prepare for them<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Two New Upcoming Mandates to Be Aware Of\">Two New Upcoming Mandates to Be Aware Of<\/h2>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Smaller reporting companies must comply with the SEC's new breach disclosure rules. (Deadline: June 15)\">1. Smaller reporting companies must comply with the SEC&#8217;s new breach disclosure rules. (Deadline: June 15)<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last December, the Securities and Exchange Commission (SEC) released cybersecurity&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/files\/rules\/final\/2023\/33-11216.pdf\" rel=\"noopener\">disclosure requirements for public companies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which will also apply to smaller reporting companies, beginning on June 15. The SEC&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/rules\/2018\/06\/smaller-reporting-company-definition#:~:text=We%20are%20amending%20the%20definition,of%20less%20than%20%24700%20million.\" rel=\"noopener\">defines smaller reporting companies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;as those with &#8220;a public float of less than $250 million, as well as registrants with annual revenues of less than $100 million for the previous year and either no public float or a public float of less than $700 million.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Smaller reporting <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-139\" rel=\"noopener\">companies will be&nbsp;required to disclose<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;&#8220;any cybersecurity incident they determine to be material and to describe the material aspects of the incident&#8217;s nature, scope, and timing, as well as its material impact or reasonably likely material impact on the registrant.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s important to note that the onus is on the organization that was breached to define and determine materiality. However, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/edgar\/searchedgar\/companysearch\" rel=\"noopener\">quick look through the&nbsp;EDGAR database<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;shows fewer reports of material breaches than one would expect, given the prevalence of cyberattacks. Are companies being disingenuous in how they define materiality in an attempt to avoid the decrease in shareholder confidence and the reputational hit associated with reporting a breach? In order for this rule to serve its intended purpose, companies need to create clearly defined processes for assessing the impact of cyberattacks, including indisputable parameters for what classifies as a material incident&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This new requirement is an important step for smaller reporting companies to maintain trust with consumers and stakeholders, but it goes even further than that. Smaller companies play a crucial role in the supply chain for larger companies, meaning an attack on a smaller organization could have a significant impact on a larger organization down the line, potentially resulting in harmful, far-reaching consequences.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Take weapons systems, for example: A few major defense industrial base (DIB) companies might be involved in creating a weapon system that provides a critical capability for the military. But drilling down a few levels, one of the parts necessary for the system to function might be manufactured by a smaller company. What happens if it is hacked?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Additionally, from a purely IT standpoint, there have been many instances where larger companies have been accessed via their connection to a smaller organization. A prime example of this is the data breach of Court Ventures, a subsidiary of Experian, which led to the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csoonline.com\/article\/534628\/the-biggest-data-breaches-of-the-21st-century.html\" rel=\"noopener\">exposure of 200 million personal records<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Federal agencies must meet zero-trust goals. (Deadline: Sept. 30)\">2. Federal agencies must meet zero-trust goals. (Deadline: Sept. 30)<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2022, the United States Office of Management and Budget (OMB)&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/01\/M-22-09.pdf\" rel=\"noopener\">released a memorandum<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;instructing federal agencies to start implementing a zero-trust framework to secure their data and information systems. By Sept. 30 of this year, agencies are required to have completed 19 specific tasks aligned with the five pillars (Identity, Devices, Networks, Applications and Workloads, and Data) of the Cybersecurity and Infrastructure Security Agency&#8217;s&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-04\/zero_trust_maturity_model_v2_508.pdf\" rel=\"noopener\">Zero Trust Maturity Model<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the requirements in the memorandum states that &#8220;agencies must operate dedicated application security testing programs&#8221; and &#8220;utilize high-quality firms specializing in application security for independent third-party evaluation,&#8221; highlighting the importance of application programming interface (API) security. APIs are integral to applications, allowing them to communicate with one another and exchange data. But they&#8217;re also a prime attack vector: One report found that a staggering&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nonamesecurity.com\/resources\/api-security-disconnect-2023\/\" rel=\"noopener\">78% of cybersecurity professionals<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;have experienced an API security incident in the past 12 months.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Government agencies need to take a hard look at API security. This will require the adoption of tools that provide a bird&#8217;s-eye view of everything happening within the organization&#8217;s network, including data flows, API movement, and which data APIs are exposing. In many cases, organizations aren&#8217;t even aware of how many APIs they have and which types of data are traversing them. Having this visibility will empower federal agencies to quickly identify anomalous behavior and flag malicious actors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These new requirements are a step in the right direction, but to be truly effective, a larger shift in philosophy regarding security must occur. Too often, organizations view security as a cost rather than an investment. But as the world becomes more digitized and the threat landscape expands, organizations must adequately fund security or they risk undermining the very innovations intended to fuel growth and profitability.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, any future regulations must be administered fairly and consistently with strong enforcement. This will involve striking the right balance of both incentives and penalties to ensure compliance. While it&#8217;s encouraging to see more cybersecurity regulations emerge, thwarting attacks will be an ongoing battle and more federal regulation plus continued cybersecurity investment is necessary.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/preparing-your-organization-upcoming-cybersecurity-deadlines\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY As our world becomes increasingly digitized, malicious actors have<\/p>\n","protected":false},"author":12,"featured_media":3695,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=1820%2C1053&ssl=1",1820,1053,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=300%2C174&ssl=1",300,174,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=640%2C370&ssl=1",640,370,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=640%2C370&ssl=1",640,370,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=1536%2C889&ssl=1",1536,889,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=1820%2C1053&ssl=1",1820,1053,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=1024%2C592&ssl=1",1024,592,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/preparing-your-organization-for-upcoming-cybersecurity-deadlines.jpg?fit=1820%2C1053&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3694"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3695"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}