Debevoise & Plimpton LLP has been shortlisted for the Financial Times’ Innovative Lawyers North America awards in the “Innovation in New Services to Manage Risk” category.  The firm was selected for its global and interdisciplinary Data Strategy and Security practice (DSS) and the approach taken by DSS to developing its people and their skills. As a result of this initiative, DSS is recognized…

Earlier this year, the U.S. Department of Housing and Urban Development (“HUD”) released an unannounced and immediately effective Cyber Incident Reporting Requirement (the “Original Requirements”) in Mortgagee Letter 2024-10, which imposed onerous requirements for Federal Housing Administration (“FHA”)-approved Mortgagees. These requirements included a 12-hour notification to HUD of even suspected incidents or incidents that violated policy. (We wrote about the…

On Thursday, October 17th, at 10:40-11:25 AM (ET), Robert Maddox will speak on a virtual panel entitled “Ransomware in Europe: Best Practices and Pitfalls for Corporates and Other Organizations.” To learn more about the conference please click here. To register for free, please click here and use the code DEBEVOISE24EU Incident Response Forum Europe 2024 is a unique, one-day conference that brings together…

As companies slowly ramp up the depth and breadth of their AI adoption, one of the most difficult challenges they face is managing third-party risk. Most companies contemplating AI adoption will look to third-party vendors to provide AI-enabled products or services for their businesses. Companies often struggle when deciding what diligence to perform for these vendors and how to mitigate…

In the UK, unannounced inspections of businesses’ premises, or “dawn raids”, are most often associated with authorities such as the Serious Fraud Office, National Crime Agency, Competition and Markets Authority and Metropolitan Police. However, data controllers and processers should be aware that the UK’s Information Commissioner’s Office (“ICO”) can also carry out dawn raids as part of investigations into compliance…