Nov. 3, 2023, 11:01 a.m. | Bruce Schneier

Schneier on Security www.schneier.com

Another example of a large and influential state doing things the federal government won’t:


Boards of directors, or other senior committees, are charged with overseeing cybersecurity risk management, and must retain an appropriate level of expertise to understand cyber issues, the rules say. Directors must sign off on cybersecurity programs, and ensure that any security program has “sufficient resources” to function.


In a new addition, companies now face significant requirements related to ransom payments. Regulated firms must now report any …

banking boards charged companies computer security cyber cybersecurity cybersecurity programs cybersecurity risk cybersecurity risk management directors doing expertise federal federal government financial government large management new york ransomware regulation retain risk risk management rules sign state things understand york

Principal Security Engineer

@ Elsevier | Home based-Georgia

Infrastructure Compliance Engineer

@ NVIDIA | US, CA, Santa Clara

Information Systems Security Engineer (ISSE) / Cybersecurity SME

@ Green Cell Consulting | Twentynine Palms, CA, United States

Sales Security Analyst

@ Everbridge | Bengaluru

Alternance – Analyste Threat Intelligence – Cybersécurité - Île-de-France

@ Sopra Steria | Courbevoie, France

Third Party Cyber Risk Analyst

@ Chubb | Philippines