Jul. 29, 2026
Jul. 29, 2026
State Cybersecurity Laws: Steps to Address Regulators’ Priorities
State regulators have ramped up their questions following cybersecurity incidents. After providing notice of a breach, companies should expect an extensive dialogue with AGs, in which inquiries are made about data minimization and retention, access controls, vendor due diligence, procedures for logging and patching, and risk-based resilience planning. This second article in a three-part series on state cybersecurity law and enforcement, published in conjunction with IAPP’s Cybersecurity Law Center, provides practical recommendations for building readiness for regulatory investigation and enforcement. It includes commentary from experts at BakerHostetler, Debevoise, Morrison & Foerster, Paul Hastings, Ropes & Gray, and Shook, Hardy & Bacon. Part one analyzed changes to the state law toolkit for regulators and examined key enforcement actions. The final installment will cover important reasonable security and business resilience steps and will discuss the first impacts of AI on state cybersecurity enforcement. See “Practical Compliance Implications From NYDFS’ Healthplex Settlement” (Sep. 17, 2025). Read full article …
Chatrie Expands the Fourth Amendment’s Protection Against Geofencing in Criminal Investigations
Companies that collect, use or disclose location data may need to rethink how they respond to law enforcement requests after a landmark Supreme Court ruling on geofence warrants. Last month, in Chatrie v. United States, the Court held that geofence warrants are searches under the Fourth Amendment because individuals have a reasonable expectation of privacy in their location history. Writing for a five-justice majority, Justice Kagan rejected the argument that short-term location tracking falls outside constitutional protection. The Court sent the case back to the U.S. Court of Appeals for the Fourth Circuit to address probable cause, particularity and the good-faith exception, issues that could have significant implications for companies that possess location data. This article examines the Chatrie decision and what it means for companies that collect and retain consumer location data, with insights from experts at Loeb & Loeb and Womble Bond Dickinson. See our two-part series on combatting privacy issues arising from geolocation data use: “Understanding the Legal Landscape” (Apr. 3, 2019), and “Five Risk-Mitigation Strategies” (Apr. 10, 2019). Read full article …
For the First Time, Verizon Data Breach Investigations Report Finds Exploitation of Vulnerabilities a Top Threat
Exploitation of vulnerabilities has become the most common way attackers gain initial access to a target’s systems – and organizations are having a harder time patching those vulnerabilities, according to the Verizon 2026 Data Breach Investigations Report (DBIR). This article, with insights from Verizon associate director and DBIR team lead Alex Pinto, parses those findings and distills aspects of the DBIR concerning ransomware’s onward march; the roles of humans, third parties and credential abuse in breaches; where AI sits in the cyber landscape; key characteristics of breaches and cyber incidents; and industry-specific data. See “Leading Attack Vectors and Other Key Findings From Verizon 2025 Data Breach Investigations Report” (Jun. 25, 2025). Read full article …
Constangy Welcomes Former DOJ Prosecutor to Cyber Team in Orange County
Constangy has welcomed seasoned cybersecurity and data privacy attorney Andrew Pak as a partner in the firm’s Orange County, California, office. He arrives from Perkins Coie. For insights from Pak, see “AI Compliance Playbook: Adapting the Three Lines Framework for AI Innovations” (Jun. 2, 2021). Read full article …
Most-Read Articles
-
Apr. 22, 2026
How Tech CLOs Think Attorneys Should Be Using AI -
Jun. 10, 2026
Checklist for Contracting With AI Vendors to Mitigate Risks -
Mar. 25, 2026
AI Agent Security: What CISOs and GCs Need to Know to Defend the Enterprise -
Jun. 24, 2026
Vermont’s Stringent Privacy Law and Louisiana’s Fast Compliance Timeline Amplify Enforcement Risk -
Jul. 22, 2026
State Cybersecurity Laws: Enforcers’ Growing Toolkit