Policy & Regulation


  • A large entrance sign that reads "Gate A, NIST, National Institute of Standards and Technology, U.S. Department of Commerce" is mounted on a rock base and surrounded by grass and trees. In the background to the left of the sign, there is a commercial building.
    Image attribution tooltip
    Retrieved from R. Eskalis/NIST.
    Image attribution tooltip

    NIST loses key cyber experts in standards and research

    The head of the agency’s Computer Security Division and roughly a dozen of his subordinates took the Trump administration’s retirement offers, placing key programs at risk.

    By May 6, 2025
  • Military Surveillance Officer Working on a City Tracking Operation in a Central Office Hub for Cyber Control and Monitoring for Managing National Security, Technology and Army Communications.
    Image attribution tooltip
    gorodenkoff via Getty Images
    Image attribution tooltip

    DOD plans to fast-track software security reviews

    The Pentagon will lay out new security requirements and approval processes for the software it purchases.

    By May 5, 2025
  • Harrods is one of three UK-based retail companies responding to a spree of attacks beginning in April 2025.
    Image attribution tooltip
    Hollie Adams via Getty Images
    Image attribution tooltip

    UK authorities warn of retail-sector risks following cyberattack spree

    Three major retail brands, including Harrods and M&S, have been targeted in recent weeks.

    By May 5, 2025
  • Medical Coding Bill And Billing Codes Spreadsheets
    Image attribution tooltip

    Shutterstock / Andrey_Popov

    Image attribution tooltip
    Sponsored by Zilla, a CyberArk Company

    Access reviews can be fixed - here’s how

    Drowning in spreadsheets for access reviews? There’s a smarter solution.

    May 5, 2025
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    Trump proposes major cut to CISA’s budget, citing false ‘censorship’ claims

    The president’s budget proposal repeated a debunked claim about the nation’s cyber agency engaging in censorship.

    By Updated May 5, 2025
  • Justice Department Pam Bondi
    Image attribution tooltip
    Anna Moneymaker via Getty Images
    Image attribution tooltip

    Recent DOJ settlements suggest Biden cyber-fraud initiative still active

    The Justice Department under Trump has now settled three cases that bear the hallmarks of a Biden-era cyber enforcement initiative.

    By Updated May 2, 2025
  • DHS logo
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    Salt Typhoon telecom hacks one of the most consequential campaigns against US ever, expert says

    A prominent former member of a recently shuttered cyber-incident review panel said the board should be reconstituted with independent authority.

    By May 1, 2025
  • DHS Secretary Kristi Noem delivered a keynote at the RSAC conference in San Francisco.
    Image attribution tooltip
    Eric Thayer via Getty Images
    Image attribution tooltip

    DHS secretary vows to refocus CISA, saying it strayed from mission

    Kristi Noem said the agency should be focused on securing critical infrastructure.

    By April 30, 2025
  • Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency.
    Image attribution tooltip
    Tasos Katopodis via Getty Images
    Image attribution tooltip

    Cyber experts urge Trump to abandon Chris Krebs investigation

    Dozens of cyber industry luminaries, many from the election security community, said the investigation could discourage important cyber work.

    By April 28, 2025
  • The FBI seal
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    FBI seeks public tips about Salt Typhoon

    The bureau’s public alert follows months of conversations with the telecom industry about the far-reaching cyber espionage campaign by a Chinese nation-state threat actor.

    By April 28, 2025
  • DHS logo
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    CISA gets a deputy director as it braces for major layoffs

    Madhu Gottumukkala, a state CIO, lacks the homeland security experience of his two predecessors.

    By April 25, 2025
  • Leaders of the G7 nations gathered at the Leaders Summit in Italy in June 2024.  A group of top CISOs sent a letter to the G7 in April 2025 asking for harmonization of global cyber regulations.
    Image attribution tooltip
    Antonio Masiello via Getty Images
    Image attribution tooltip

    CISOs band together to urge world governments to harmonize cyber rules

    Policymakers have moved slowly to reduce regulatory overlap, but the new industry plea could help change that.

    By April 24, 2025
  • Sen. Marco Rubio sits at a senate conference.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    State Department reorganization could imperil cyber diplomacy

    Congress told the U.S. State Department how to approach global cyber challenges, but the administration’s plan would upend that strategy.

    By April 23, 2025
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA’s Secure by Design initiative in limbo after key leaders resign

    Companies have been urging CISA to scale back its software security pressure campaign. Two new resignations from the agency could accelerate that shift.

    By April 22, 2025
  • Capitol building, DC
    Image attribution tooltip
    Getty Images via Getty Images
    Image attribution tooltip

    Bill extends cyber threat info-sharing between public, private sector

    The Cybersecurity Information Sharing Act of 2015, set to expire in September, “moved the needle.”

    By Elizabeth Montalbano, Contributing Reporter • April 16, 2025
  • Smiling businesswoman in headphones taking notes, working with laptop and talking smartphone, blue glowing information protection icons. Padlock, cloud and digital interface. Cyber security concept - stock photo
    Image attribution tooltip
    iStock via Getty Images
    Image attribution tooltip

    Mitre CVE program regains funding as renewal deal reached

    The information security industry feared a lapse would lead to industrywide exposures of software vulnerabilities.

    By April 16, 2025
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA launches new wave of job cuts

    Critics warn that drastic downsizing of the DHS unit will threaten the nation’s ability to counter cyber adversaries.

    By April 16, 2025
  • A family stands at a Delta Air Lines ticketing counter trying to rebook a flight after a CrowdStrike software update caused thousands of cancelations.
    Image attribution tooltip
    Jessica McGowan / Stringer via Getty Images
    Image attribution tooltip

    Aviation sector faces heightened cyber risks due to vulnerable software, aging tech

    A report calls on federal authorities to conduct comprehensive risk assessments and take steps to modernize the air traffic control system.

    By April 14, 2025
  • Sen. Ron Wyden, D-Ore.
    Image attribution tooltip
    Drew Angerer/Getty Images via Getty Images
    Image attribution tooltip

    Plankey nomination at CISA placed on hold after Wyden pushes for telecom report

    The Oregon senator is demanding CISA release a report on security practices in the industry, citing concerns about the Salt Typhoon hacking campaign. 

    By April 10, 2025
  • The exterior of the U.S. Capitol on Jan. 3, 2024.
    Image attribution tooltip
    Colin Campbell/Cybersecurity Dive
    Image attribution tooltip

    Trump administration under scrutiny as it puts major round of CISA cuts on the table

    Congressional members plan to raise questions Tuesday as hundreds of critical jobs could be slashed in the coming weeks.

    By April 7, 2025
  • photo of Lt. General Timothy Haugh
    Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    Head of NSA and US Cyber Command reportedly fired

    Gen. Timothy D. Haugh served as the head of two government organizations that play integral roles for U.S. cybersecurity.

    By April 4, 2025
  • A man and a woman shake hands in front of a desk that has flags from the U.S. and Ukraine. The people are in front of a blue background with CISA logos.
    Image attribution tooltip
    Retrieved from Jen Easterly/CISA.
    Image attribution tooltip

    CISA, FBI warn of fast flux technique used to hide malicious servers

    Criminal and state-linked hackers use fast-changing DNS records to make it harder for defenders to detect or disrupt malicious activity.

    By April 4, 2025
  • Commerce Secretary Lutnick on the White House lawn after speaking to the press.
    Image attribution tooltip
    Andrew Harnik via Getty Images
    Image attribution tooltip

    House members press Commerce Secretary Lutnick on DOGE-related job cuts at NIST

    The agency has already slashed dozens of probationary workers, and further cuts could have major consequences for cybersecurity standards and AI development. 

    By April 3, 2025
  • Mark Uyeda during May 2022 Senate hearing
    Image attribution tooltip
    Tasos Katopodis via Getty Images
    Image attribution tooltip

    SEC should avoid ‘overly prescriptive’ AI rules, acting chair says

    The comments follow actions taken by President Trump that have effectively upended the U.S. approach to AI policy under Biden, according to analysts.

    By Alexei Alexis • March 28, 2025
  • FCC Brendan Carr
    Image attribution tooltip
    Kevin Dietsch via Getty Images
    Image attribution tooltip

    FCC investigating China-linked companies over evasion of US national security measures

    The agency is cracking down on the use of prohibited technologies following a series of hacks into US telecommunications firms.

    By March 24, 2025