Legal Cyber Academy

Cheat Sheet: The State of Cybersecurity and Privacy Regulatory Oversight

Privacy Law· PremiumLevel: Intermediate

Overview of Cheat Sheet: The State of Cybersecurity and Privacy Regulatory Oversight

The U.S. cybersecurity and privacy regulatory environment is not a single unified regime but a patchwork of federal agency rules, state laws, and sector-specific mandates that organizations must navigate simultaneously. This course examines three frameworks that frequently affect a broad range of organizations and their advisors: the FTC's authority over privacy and security practices, the New York Department of Financial Services cybersecurity regulation applicable to covered financial entities, and the California Consumer Privacy Act governing consumer data rights. By placing these frameworks side by side, the course clarifies where requirements align, where they diverge, and where compliance with one does not guarantee compliance with another. The result is a practical reference that supports more informed decision-making across legal, risk, and governance functions.

What you’ll learn in Cheat Sheet: The State of Cybersecurity and Privacy Regulatory Oversight

  • Describe the core obligations imposed by the FTC's privacy and security rulemaking and the types of organizations it covers
  • Explain the key requirements of the NYDFS cybersecurity regulation and identify which entities fall within its scope
  • Summarize the consumer rights and business obligations established under the California Consumer Privacy Act
  • Compare how these three frameworks overlap, conflict, or create cumulative compliance burdens for organizations
  • Identify the primary gaps and risks an organization may face when operating across multiple regulatory regimes
  • Apply this regulatory overview as a reference tool when advising on compliance strategy or governance decisions

Audience and prerequisites

Who should take this courseCheat Sheet: The State of Cybersecurity and Privacy Regulatory Oversight

Board members, executives, legal advisors, CISOs and security teams, and cyber-insurance professionals who need a working understanding of the major U.S. cybersecurity and privacy regulatory frameworks affecting their organizations or clients.

Prerequisites for Cheat Sheet: The State of Cybersecurity and Privacy Regulatory Oversight

None — designed for non-technical professionals.

Curriculum

  1. 1. Attorney Rulebook: FTC Privacy and Security Rulemaking

    Technologies have evolved dramatically in recent decades, with the speed of their adoption by consumers leaving regulators to play catch-up in their oversight. The Federal Trade Commission (FTC) is a federal regulatory body that enforces consumer protection laws and prevents unfair business practices. As businesses’ exploitative or grossly inadequate data privacy practices increasingly come to light, the FTC is taking recourse in its rulemaking authority to address issues of data privacy and security, as well as commercial surveillance. Attorneys wanting to better understand the horizon for privacy and security regulatory rulemaking and enforcement, as well as the role their clients can play it, will find this concentrated discussion essential to their practice. In this course, our e

    Video coming soon
  2. 2. Understanding NYDFS Cybersecurity Regulations

    In the last few years, cybersecurity strategies and risk management practices have been put to the test. The increased reliance on remote work, digital communications, and cloud-based storage accelerated by the pandemic has greatly expanded the opportunities and incentives for phishing campaigns or ransomware demands, among other challenges. The fallout of cyber incidents has time and time again demonstrated that they represent a major risk for organizations’ legal, financial, and reputational well-being. In response, the New York Department of Financial Services has one of the leading state bodies to introduce comprehensive cybersecurity regulations, specifically aimed at protecting the sensitive information held by financial institutions and related entities. This course is designed to h

    Video coming soon
  3. 3. 2022 Year in Review: CCPA and What Lies Ahead

    The California Consumer Privacy Act (CCPA) was the first state data privacy law in the United States. In 2023, three years after the CCPA went into effect, it is now joined by an increasing number of state privacy regulations and data privacy oversight measures from federal regulators. Yet, in its short lifespan, the CCPA has already come a long way, with its most significant development, the California Privacy Rights Act (CPRA), going into effect this year. Attorneys advising clients potentially covered under the CCPA will find looking at the key CCPA amendments, shifts in enforcement authority, and cases in 2022, as well as what to look forward to in 2023, an essential tool to their practice. In this seminar, our experts begin by providing an overview of the CCPA. They discuss the new a

    Video coming soon

Learning track

Part of a learning trackPrivacy & Data Protection LawCourse 6 of 8 — see the full path