Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

In this episode, Brian Hengesbaugh, Global Chair of Data Privacy and Security, is joined by Stephen Reynolds, partner in Chicago, as they discuss the Strengthening American Cybersecurity Act, a law recently signed by President Biden, which requires key businesses to report certain ransomware incidents to the Cybersecurity and Infrastructure Security Agency (CISA). Listen in to hear about:

  • An overview of the new law, including key elements such as mandatory reporting requirements, timelines and which “critical infrastructure” sectors are affected by the legislation
  • How the scope and ambiguity of the new law impacts organizations and complicates the response process effort
  • What to expect in terms of engaging with CISA and how to preserve privilege applying to such communications
  • How to manage and coordinate the new reporting mandates with existing incident reporting obligations
  • Suggested action items to help companies address top-of-mind concerns and challenges they encounter as ransomware continues to be a prevalent threat

Want to Learn More?
Stay tuned for more podcasts and subscribe to the Connect On Tech Blog at connectontech.bakermckenzie.com

Subscribe on your player of choice: Apple | Android | Spotify
Author

Brian Hengesbaugh is Global Chair of Baker McKenzie's Data & Cyber Practice. Formerly special counsel to the general counsel of the US Department of Commerce, Brian played a key role in the development and implementation of the US Government’s domestic and international policy in the area of privacy and electronic commerce. In particular, he served on the core team that negotiated the US-EU Safe Harbor Privacy Arrangement (Safe Harbor) and earned a Medal Award from the US Department of Commerce for this service.

Author

Stephen Reynolds frequently advises clients on complex matters involving data privacy and security laws and serves on the board of directors of the International Association of Privacy Professionals (IAPP). Stephen’s expertise adds value to organizations by mitigating cyber threats through proactive preventative measures and navigating complex litigation on behalf of clients in data privacy and security. He is uniquely able to and routinely uses his computer background in cases involving data privacy and security, electronic discovery, social media discovery, and computer forensics.