Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
Rising Cyberattacks on U.S. Water Infrastructure: Federal Guidance and Next Steps for Operators
Blog August 17, 2026
Recent guidance issued by Federal agencies warns that malicious cyber actors are targeting internet-facing operational technology (“OT”) used by water and wastewater utilities, particularly PLCs…
FERC Issues Proposed Rules to Enhance Grid Cybersecurity Reliability Standards
Blog September 30, 2024
Cyberattacks on U.S. energy infrastructure have been on the rise in 2024…
U.S. Department of Energy Releases Cybersecurity Baselines for Utilities and DERs
Blog March 06, 2024
As part of the Biden Administration’s efforts to align energy cybersecurity efforts across the country, the U.S. Department of Energy has funded the release of a set of energy distribution cybersecurity baselines for entities participating in the nationwide grid transition…
Cyberattacks on the Energy Sector Continue to Rise
Blog June 23, 2023
Cyberattacks on the energy sector have been rapidly growing since 2017, and we saw an all-time high of cyberattack events on the sector in 2022. The energy sector is particularly vulnerable due to these types of attacks due to the outdated and unsecured networks oftentimes used in the industry, as well as the increased use of distributed energy resources (“DER”), which creates more openings to attack and requires more resources to monitor and manage…
Physical and Cyber-Attacks on Energy Infrastructure Expected to Continue
Blog May 03, 2023
Over the past several years, the energy sector has become a prime target for hacking and ransomware attacks, with over 40 attacks on the industry since 2017.  Cyber attacks have only continued to rise, with a record high of 13 reported attacks in one year occurring in 2022. Physical Security Threats to U.S. Energy Infrastructure A new type of threat against the energy sector crystallized at the end of 2022: physical attacks on the grid…
Cybersecurity 2022 – The Year in Preview: Continued Threats to Nation's Energy Supply as Regulators Race to Keep Up
Blog February 02, 2022
Continued Threats of Ransomware Attacks As we reported in our 2021 Year in Preview series, we began 2021 anticipating that ransomware would be a serious threat to critical energy infrastructure.  These concerns were realized in May 2021 when the Colonial Pipeline Company's (“Colonial”) entire 5,500-mile pipeline system carrying liquid fuels was shut down due to a ransomware attack by DarkSide, a hacking group that allegedly has loose ties to the Russian government…
Biden Issues Memorandum Aimed at Improving Cybersecurity
Blog July 30, 2021
On July 28, 2021, President Biden issued a Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems.  The Memo recognizes that the protection of the nation's critical infrastructure lies not only with government, i.e., at the federal, state, local, tribal, and territorial levels, but with critical infrastructure owners and operators.  In addition, the Memo states that cybersecurity threats to critical infrastructure, and the systems that control and operate it…
Cybersecurity 2021 - The Year in Preview: Ransomware, the Latest Threat to the Nation's Energy Supply
Blog December 16, 2020
Editors' Note:  This is the first in our fifth-annual end-of-year series examining important trends in data privacy and cybersecurity in the coming year.   The Growing Threat of Ransomware According to media reports, ransomware attacks against the manufacturing industry have more than tripled compared with last year. This dramatic rise in cyberattacks poses serious concerns about the vulnerability of critical energy infrastructure serving the nation's electric grid…
Cybersecurity and Infrastructure Security Agency Identifies Essential Critical Energy Infrastructure Workers During COVID-19 Response
Blog March 20, 2020
On March 19, 2020, the Cybersecurity and Infrastructure Security Agency (CISA) issued its Memorandum on Identification of Essential Critical Infrastructure Workers During COVID-19 Response (“Memo”).  The Memo identifies workers who conduct “a range of operations and services that are essential to continued critical infrastructure viability” and who support a wide-spectrum of industries such as medical and healthcare, telecommunications, information technology systems, defense, and……
1 of 2

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors