5. Consumer Businesses
Businesses that have direct contact with consumers, such as restaurants, retailers, and consumer product companies, are increasingly using digital technologies and data initiatives to improve the customer experience. While customer data is necessary for these interactions, legislation requires that businesses protect and ensure consumer data privacy.
For instance, the General Data Protection Regulation (GDPR) instituted new requirements for how businesses – including U.S. businesses – collect and store the private data of European Union citizens. Fines for non-compliance are high; up to €20,000,000 or 4% of global revenue, and the EU is not shy about enforcing them. In 2018, the California Consumer Privacy Act (CCPA) enacted similar legislation. Other states are following suit. In May 2021, the Commonwealth of Virginia passed a Consumer Data Protection Act, which adds data protection assessment requirements.
6. Publicly Traded Companies
In 2023, The Securities and Exchange Commission (SEC) has implemented new rules regarding cybersecurity disclosure for publicly traded companies. These rules create new obligations for reporting material cybersecurity incidents and disclosing critical information related to cybersecurity risk management, expertise, and governance. Companies will be required to disclose risks in their annual reports beginning on December 15, 2023.
The SEC also encourages companies to have policies and procedures in place to prevent insider trading based on nonpublic information about cybersecurity risks and incidents. Failure to comply with these rules can result in regulatory action, investor lawsuits, and potential reputational damage.
7. Retail
The retail sector isn’t federally regulated, but it does follow regulations from the Payment Card Industry Security Council’s Data Security Standard (or PCI DSS).
Any organization that process, store or transmit payment cardholder information are required to follow regulations from PCI DSS which stipulates standards for securing cardholder data. Several provisions within PCI DSS requirements concern identification, monitoring and remediation of software vulnerabilities that, when exploited by threat actors, could jeopardize the security of payment cardholder information.
8. Defense
As a condition of providing a service to the U.S. Department of Defense (DOD), businesses must meet cyber requirements set up in the Defense Federal Acquisition Regulation Supplement (DFARS) and Procedures, Guidance, and Information (PGI). DFARS outlines cybersecurity standards a third party must meet and comply with prior to doing business with the DOD in order to protect sensitive defense information.
9. Insurance
While regulations for insurance departments and companies vary state by state, many have issued requirements to protect consumer information. Furthermore, we’ve seen increased interest in adding more regulations in this area. In October 2016, the New York State Department of Financial Services (DFS) proposed new regulation around cybersecurity for both financial organizations and insurance companies.
The Challenge of Cybersecurity Compliance
From Europe’s general data protection regulations and California’s Consumer Privacy Act to PCI DSS and HIPAA regulations, CISOs are under pressure to comply with a variety of mandates related to cybersecurity and the protection of sensitive data.
The stakes are high. Failure to achieve and maintain legal compliance can often result in fines and litigation that may cost millions of dollars. When compliance failure contributes to a cyberattack or data breach, the impact can be even more devastating. Breaches typically cause customers to lose confidence and stock to prices drop. The company’s reputation inevitably suffers, and profitability takes a hit.
Achieving compliance with the broad array of regulatory frameworks requires solutions that can accomplish several key objectives. Cybersecurity compliance technology must be able to:
- Identify and address data risk and system vulnerabilities, aligning them with business regulatory objectives.
- Provide visibility, enhance enforcement and demonstrate efficacy of the security controls needed to meet compliance.
- Deliver the ability to take a prioritized, risk-based approach to cybersecurity compliance.
- Automate and streamline data security and privacy programs.
- Eliminate compliance silos, reduce control clutter and empower executives to gather answers more quickly.
- Minimize security assessment control creep.
- Reduce the administrative burden of risk assessments and increase the efficiency of personnel dedicated to security risk management.
- Lower the cost of cyclical security and IT audits or assessments.
Compliance Summary
While cybersecurity compliance is an essential goal if your organization operates in these sectors, you can also mature your cybersecurity program by modeling it after common cybersecurity frameworks like NIST, ISO 27000, and CIS 20.
Use Bitsight Security Ratings to assess and score your cybersecurity performance and continuously monitor your third parties to ensure they don’t pose a hidden risk to your network. With cybersecurity compliance frameworks as your guidepost and the insight that Bitsight brings, you can better understand what regulators are looking for and continue to mature your cybersecurity performance.
Additionally, Bitsight Cyber Threat Intelligence helps organizations comply with PCI DSS by enhancing the vulnerability assessment and prioritization process. Bitsight CTI uses real-time vulnerability exploit intelligence from the cybercriminal underground to accurately predict which vulnerabilities are most likely to be exploited in the next 90 days. This intelligence enables security teams to more effectively prioritize these vulnerabilities to increase security and ensure cybersecurity compliance with PCI DSS requirements.