State AGs are expanding their role in cybersecurity enforcement, drawing on a robust toolkit that includes a growing mix of consumer protection laws, sector-specific statutes and emerging legislation to scrutinize how companies secure personal data. For privacy and cybersecurity professionals, this creates both heightened risk and a more complex compliance landscape that they need to understand and address. In this guest article, the first in a three-part collaborative series with IAPP, Jim Dempsey, managing director of the IAPP Cybersecurity Law Center, examines the key authorities that states are using, highlights recent enforcement trends across industries and explains how the relevant laws are reshaping compliance expectations. See “Examining Security Mandates, Including California’s Draft Audit Regulations, in State Privacy Laws” (Nov. 1, 2023).