The FTC finalized an order regarding Blackbaud’s failure to implement appropriate security after a 2020 ransomware attack. The company must delete unnecessary data, develop a comprehensive security program, and report data deletion practices. Blackbaud must also notify the FTC of any future data breaches. The company settled with the SEC and multiple states for misleading disclosures following the attack.
A Hit-and-Miss First Year for SEC’s Cyber-Incident Reporting Rules – MSSP Alert
In its first year, the SEC’s cyber-incident reporting rules had mixed results. While firms improved cyber incident reporting, there were challenges with compliance and non-disclosure