{"id":19616,"date":"2024-08-19T15:37:00","date_gmt":"2024-08-19T19:37:00","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19616"},"modified":"2024-08-19T15:37:00","modified_gmt":"2024-08-19T19:37:00","slug":"2024-august-newsletter","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19616","title":{"rendered":"2024 August Newsletter"},"content":{"rendered":"<h1>ELTENI&#8217;S CYBER SCOOP<\/h1>\n<h3>Latest News<\/h3>\n<p>In this newsletter, we highlight the addition of a Chief Artificial Intelligence Officer in the CISA as well as the importance of cybersecurity incident disclosure.\u00a0 Also, additional commentary on the Crowdstrike incident.<\/p>\n<h1>REGULATORY CORNER<\/h1>\n<p><strong>CISA Names First Chief Artificial Intelligence Officer<\/strong><\/p>\n<p><em>WASHINGTON \u2013 Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced its first CISA Chief Artificial Intelligence Officer, Lisa Einstein. This selection reflects CISA\u2019s commitment to responsibly use AI to advance its cyber defense mission and to support critical infrastructure owners and operators across the United States in the safe and secure development and adoption of AI. Einstein has led CISA\u2019s AI efforts since 2023 as CISA\u2019s Senior Advisor for AI. Since 2022, Einstein also served as the Executive Director of the CISA Cybersecurity Advisory Committee.<\/em><\/p>\n<p><em>Strong cybersecurity is foundational to trustworthy AI, and the responsible use of AI is increasingly relevant for the security of critical infrastructure. CISA has established this new position to institutionalize our ongoing efforts to responsibly govern our own uses of AI and to ensure critical infrastructure partners develop and adopt AI in ways that are safe and secure.<\/em><\/p>\n<h3>Notes<\/h3>\n<p>Artificial Intelligence (AI) has become increasingly pivotal in cybersecurity for its ability to enhance threat detection and response. This is important as cyberattacks grow in sophistication, requiring advanced solutions that can adapt and respond at machine speed. However, with the reliance of this technology comes the need for a careful and strategic approach to integrating AI into cybersecurity frameworks. By naming a chief artificial intelligence officer, the CISA is taking notable steps to ensure cybersecurity governance is keeping up with the ever-changing landscape of the industry.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-names-first-chief-artificial-intelligence-officer\">CISA Names First Chief Artificial Intelligence Officer | CISA<\/a><\/p>\n<h1>ENFORCEMENT NEWS<\/h1>\n<p><strong>SEC Remains Focused on Disclosure of Cybersecurity Incidents<\/strong><\/p>\n<p><em>Recent Securities and Exchange Commission (SEC) enforcement action and statements by SEC officials show that the Commission remains focused on disclosures regarding cybersecurity incidents. On May 21, 2024, Erik Gerding, director of the SEC\u2019s Division of Corporate Finance, issued a statement to clarify\u00a0that public companies are only required to disclose a cybersecurity incident under Item 1.05 of Form 8-K if the incident is \u201cdetermined by the registrant to be material.\u201d The next day, on May 22, 2024, the SEC announced that it has settled charges with The Intercontinental Exchange (ICE) relating to ICE\u2019s alleged failure to timely inform the SEC of a cyber intrusion under Regulation Systems Compliance and Integrity (SCI). While Regulation SCI only applies to a small number of key market participants, the SEC\u2019s enforcement order and recent statements signal that the SEC will not hesitate to enforce regulations that require disclosures of cybersecurity incidents.<\/em><\/p>\n<h3>Notes<\/h3>\n<p>The enforcement against the Intercontinental Exchange (ICE) underscores the SEC\u2019s strict enforcement of cybersecurity disclosure requirements, emphasizing the importance of key market participants reporting any cyber incident immediately if they have a reasonable basis to believe an event occurred. This incident highlights the importance of prompt and accurate reporting, regardless of the incident\u2019s immediate impact or materiality. Overall, it reinforces the need for thorough and timely reporting to ensure transparency and integrity. \u00a0In essence, the SEC is signaling that cybersecurity is a critical aspect of corporate governance. Companies must be proactive and transparent in their cybersecurity practices, as the consequences of non-compliance can be severe.<\/p>\n<p><a href=\"https:\/\/corpgov.law.harvard.edu\/2024\/07\/02\/sec-remains-focused-on-disclosure-of-cybersecurity-incidents\/\">SEC Remains Focused on Disclosure of Cybersecurity Incidents | harvard.edu<\/a><\/p>\n<h1>CYBER NEWS<\/h1>\n<p><u><a href=\"https:\/\/www.cnbc.com\/2024\/05\/21\/family-offices-target-cyber-hacks-ransomware.html\">Security Firm Accidentally Hires North Korean Hacker, Did Not KnowBe4 | darkreading.com<\/a><\/u><\/p>\n<p>A security firm recently hired a software engineer for its internal AI team that turned out to be a North Korean threat actor, who immediately began loading malware to his company-issued workstation.<\/p>\n<p><u><a href=\"https:\/\/www.cnbc.com\/2024\/05\/21\/family-offices-target-cyber-hacks-ransomware.html\">Cybersecurity regulations face \u2018uphill battle\u2019 after Chevron ruling | CyberScoop<\/a><\/u><\/p>\n<p>President Joe Biden\u2019s executive branch has distinguished itself on cybersecurity policy from previous administrations with its willingness to embrace regulations \u2014 often with a bit of creative lawyering involved. But a landmark ruling by the Supreme Court last week that overturned the so-called Chevron doctrine \u2014 which holds that courts should defer to federal agencies when interpreting parts of federal law not specified by Congress \u2014 threatens to make it much more difficult for the Biden administration to put in place more stringent cybersecurity rules.<\/p>\n<p><a href=\"https:\/\/www.reuters.com\/legal\/legalindustry\/really-what-cybersecurity-requirements-standards-does-my-company-need-follow-why-2024-07-31\/\">But really, what cybersecurity requirements and standards does my company need to follow and why? | Reuters<\/a><\/p>\n<p>Cybersecurity is at the top of everyone&#8217;s mind and budget, but the legal and regulatory compliance landscape is often unclear. As a result, the following questions are usually, &#8220;What does it mean practically to be compliant, and what laws require that compliance?&#8221; &#8220;What are companies required to do?&#8221; &#8220;What best practices should a company follow even if not required?&#8221;<\/p>\n<p><a href=\"https:\/\/news.stanford.edu\/stories\/2024\/07\/an-expert-s-overview-of-the-crowdstrike-outage\">A computer scientist\u2019s take on the CrowdStrike crash | Stanford Report<\/a><\/p>\n<p>On July 19, millions of Windows users encountered the dreaded \u201cblue screen of death.\u201d A bug in a critical piece of cybersecurity software, called CrowdStrike, was causing the operating system to crash. For some people and companies, the issue is ongoing, and costs are projected to be in the billions. There\u2019s little we can do to protect against bugs in the software we\u2019re using, says Zakir Durumeric, who is an assistant professor of computer science.\u00a0 \u201cIn general though, one of the best things that people can do to protect themselves against attacks is to regularly update their computers and phones.\u201d He shares his insights on the outage.<\/p>\n<h1>DECODE THE TERMS<\/h1>\n<p><strong>BIA &#8211; <\/strong>(Business impact analysis) is a systematic process to determine and evaluate the potential effects of an interruption to critical business operations because of a disaster, accident, or emergency.<\/p>\n<p><strong>MTD &#8211; <\/strong>(Mobile threat defense) is a set of tools and processes used by organizations to protect mobile devices against various threats.<\/p>\n<p><strong>XDR &#8211; <\/strong>(Extended Detection and Response) is a comprehensive cybersecurity approach that integrates multiple security tools and unifies security operations across various layers, including endpoints, networks, cloud environments, and applications.<\/p>\n<p><strong>SOC &#8211; <\/strong>(Security Operations Center) is a centralized unit within an organization dedicated to monitoring, detecting, analyzing, and responding to cybersecurity incidents.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the addition of a Chief Artificial Intelligence Officer in the CISA as well as the importance of cybersecurity [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":19618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,134,113,68,3,133,135,101,102,103,18,140,136,47,17,25,106,137,89,138,90,127,19],"tags":[],"class_list":["post-19616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-breaches","category-business-email-compromise","category-cloud","category-cyber","category-finra","category-ftc","category-hackers","category-hedge-fund","category-investment-adviser","category-microsoft","category-newsletter","category-nydfs","category-ocie","category-password","category-pii","category-private-equity","category-private-funds","category-regulatory","category-rules","category-sec","category-technology","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2024 August Newsletter - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19616\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2024 August Newsletter - Insights\" \/>\n<meta property=\"og:description\" content=\"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the addition of a Chief Artificial Intelligence Officer in the CISA as well as the importance of cybersecurity [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19616\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-19T19:37:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png\" \/>\n\t<meta property=\"og:image:width\" content=\"868\" \/>\n\t<meta property=\"og:image:height\" content=\"1123\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dtuck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dtuck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616\"},\"author\":{\"name\":\"dtuck\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"headline\":\"2024 August Newsletter\",\"datePublished\":\"2024-08-19T19:37:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616\"},\"wordCount\":1003,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/August-Newsletter-Thumbnail.png\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Breaches\",\"Business Email Compromise\",\"Cloud\",\"Cyber\",\"FINRA\",\"FTC\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Microsoft\",\"Newsletter\",\"NYDFS\",\"OCIE\",\"Password\",\"PII\",\"Private Equity\",\"Private Funds\",\"Regulatory\",\"Rules\",\"SEC\",\"Technology\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616\",\"name\":\"2024 August Newsletter - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/August-Newsletter-Thumbnail.png\",\"datePublished\":\"2024-08-19T19:37:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/August-Newsletter-Thumbnail.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/August-Newsletter-Thumbnail.png\",\"width\":868,\"height\":1123},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19616#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2024 August Newsletter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\",\"name\":\"dtuck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"dtuck\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2024 August Newsletter - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19616","og_locale":"en_US","og_type":"article","og_title":"2024 August Newsletter - Insights","og_description":"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight the addition of a Chief Artificial Intelligence Officer in the CISA as well as the importance of cybersecurity [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19616","og_site_name":"Insights","article_published_time":"2024-08-19T19:37:00+00:00","og_image":[{"width":868,"height":1123,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png","type":"image\/png"}],"author":"dtuck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dtuck","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19616#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616"},"author":{"name":"dtuck","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"headline":"2024 August Newsletter","datePublished":"2024-08-19T19:37:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616"},"wordCount":1003,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png","articleSection":["Alternative Asset Management","Awareness","Breaches","Business Email Compromise","Cloud","Cyber","FINRA","FTC","Hackers","Hedge Fund","Investment Adviser","Microsoft","Newsletter","NYDFS","OCIE","Password","PII","Private Equity","Private Funds","Regulatory","Rules","SEC","Technology","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19616","url":"https:\/\/www.elteni.com\/insights\/?p=19616","name":"2024 August Newsletter - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png","datePublished":"2024-08-19T19:37:00+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19616#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19616"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19616#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/08\/August-Newsletter-Thumbnail.png","width":868,"height":1123},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19616#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"2024 August Newsletter"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b","name":"dtuck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"dtuck"},"url":"https:\/\/www.elteni.com\/insights\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19616"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19616\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19618"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}