Insights

Professional
Practice
Industry
Region
Trending Topics
Location
Type

Sort by:

Firm News 15 results

Firm News | 4 min read | 06.24.24

Crowell Earns Top Rankings from Legal 500 United States 2024

Washington – June 24, 2024: Crowell & Moring has been recommended in eight practice areas in the 17th edition of the Legal 500 United States. In addition, partner Daniel Forman, co-chair of the firm’s Government Contracts Group, has been named to the Legal 500’s “Hall of Fame” for Government Contracts.
...

Firm News | 4 min read | 06.04.24

ArmorText and Crowell & Moring Release New Open Source Cybersecurity Tabletop Exercises

MCLEAN, Va., June 4, 2024 - ArmorText, which safeguards communication for organizations worldwide, and the international law firm of Crowell & Moring LLP today released an update to their tabletop exercise guide, making new exercise scenarios publicly available under a Creative Commons license. The new Cyber Resilience: Incident Response Tabletop Exercises Q2 2024 addresses urgent challenges facing executives, including disruptive attacks by increasingly sophisticated criminal actors with well-publicized recent examples, as well as increasingly complex regulatory obligations.
...

Firm News | 2 min read | 02.08.24

Crowell & Moring’s Privacy and Cybersecurity Group Named a Law360 Practice Group of the Year

Washington – February 8, 2024: Crowell & Moring’s Privacy and Cybersecurity Group has been named a Practice Group of the Year for 2023 by Law360.
...

Client Alerts 165 results

Client Alert | 2 min read | 06.26.24

Another One: It Pays to Consult the DOJ under the Civil Cyber Fraud Initiative

On June 17, 2024, the Department of Justice (DOJ) announced a $11.3 million False Claims Act (FCA) settlement that touches on two key enforcement priorities:  the DOJ’s Civil Cyber-Fraud Initiative and pandemic-related fraud.  This settlement, the largest under the Civil Cyber-Fraud Initiative to date, resolved allegations that Guidehouse Inc. (Guidehouse) and its subcontractor, Nan McKay and Associates (Nan McKay), violated the FCA because they failed to conduct pre‑production cybersecurity testing on New York State’s Emergency Rental Assistance Program (ERAP) technology product before public launch, and that Guidehouse used an unapproved third-party data cloud software program to store personally identifiable information (PII).
...

Client Alert | 3 min read | 05.14.24

NIST Releases Final Version of NIST SP 800-171, Revision 3

On May 14, 2024, the National Institute of Standard and Technology (NIST) published the final versions of Special Publication (SP) 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations and its companion assessment guide, NIST SP 800-171A, Revision 3 (collectively, “Rev. 3 Final Version”).  While the Department of Defense (DoD) is not requiring contractors who handle Controlled Unclassified Information (CUI) to implement Rev. 3 for now, it is expected that DoD will eventually incorporate Rev. 3 into both DFARS 252.204-7012,  Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012) as well as the forthcoming Cyber Maturity Model Certification (CMMC) program. 
...

Client Alert | 1 min read | 05.03.24

“Miss Me with Rev. 3,” Says DoD: DoD Issues Class Deviation Linking DFARS 7012 to NIST SP 800-171, Rev. 2

On May 2, 2024, the Department of Defense (DoD) issued a class deviation to DFARS 252.204-7012,  Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 7012), specifying that contractors subject to the clause must comply with NIST SP 800-171, Revision 2.  The deviation (labeled Deviation 2024-O0013) will delay the incorporation of NIST SP 800-171, Revision 3—which is set to be finalized in the next few weeks—into DFARS 7012.
...

Press Coverage 49 results

Press Coverage | 11.09.23

SEC/SolarWinds Legal Analysis w/Evan Wolff (podcast)

The Cyber Ranch Podcast

Publications 32 results

Publication | 05.14.24

Critical Infrastructure: Updating the 2013 NIPP and other Risk Mitigation Actions

Privacy and Cybersecurity Outlook: The 2024 Landscape
Protecting critical infrastructure is paramount to today’s digital age. Critical infrastructure includes physical and virtual systems essential for the functioning of our society, economy, and national security. Such a definition may include power grids, communication networks, and financial institutions, among other networks that heavily rely on interconnected computer systems. These systems are also considered critical infrastructure, as they are used to protect critical cybersecurity infrastructure. 
...

Publication | 05.14.24

Tabletop Exercises: A Leading Practice to Strengthen Defenses

Privacy and Cybersecurity Outlook: The 2024 Landscape
Every day, organizations face a barrage of attacks from cybercriminals looking to do harm by gaining access to IT systems and sensitive data. Repercussions from these attacks can be significant—lost business data, legal liability, regulatory scrutiny, and a damaged reputation. To prepare for potential attacks, companies need a robust incident response plan that can be quickly and effectively deployed against cyber threats as they arise.
...

Events 46 results

Event | 07.23.24, 10:30 PM PDT - 12:00 PM PDT

NCMA World Congress 2024

Crowell & Moring's Jennie VonCannon, Evan Wolff, and Michael Gruden, members of the firm's Privacy & Cybersecurity and Government Contracts Groups, will be speaking at the NCMA World Congress, taking place on July 23, 2024, in Seattle, Washington. They will lead a skill-based session, "Making CMMC 2.0 Requirements Work for Your Organization," at 10:30 AM PST.

Event | 05.31.24, 2:30 PM EDT - 3:30 PM EDT

2024 Privacy in Practice Conference

Crowell & Moring Partner Evan Wolff, a member of the firm's Privacy & Cybersecurity Group, will be speaking at the 2024 Privacy in Practice Conference, taking place Friday, May 31, 2024 in Portland, Maine. His presentation, "Digital Threats and Innovation Opportunities: U.S. Priorities and Challenges," will take place at 2:30 PM EST. 

Event | 02.07.24, 3:00 PM EST - 5:00 PM EST

Energy Transition Summit

Crowell & Moring Partner Evan Wolff, a member of the firm's Privacy & Cybersecurity Group, will be speaking at Energy Transition Summit, taking place February 5 - 8 in Arlington, VA. His presentation, "Contracting and Legal Trends of Cybersecurity for the Energy Transition" will take place from 3:30 p.m. - 5:00 p.m. EST.

The U.S. Department of Energy Grid Modernization Initiative and Office of Cybersecurity, Energy Security, and Emergency Response are excited to host the Energy Transition Summit: Grid Modernization Initiative and Clean Energy Cybersecurity. Attendees will learn about opportunities to engage with DOE-led efforts that are modernizing the future power grid and enabling a more resilient, secure, and equitable energy transition. This event will host thought leaders and working sessions to have a dialog about strategies for future energy systems through partnerships and technology transition across government, industry, research organizations, and local communities.

Webinars 26 results

Webinar | 05.15.24, 1:00 PM EDT - 2:00 PM EDT

NIST SP 800-171 Transitions to Revision 3: What to Know

As the National Institute for Standards and Technology (NIST) prepares to release its highly anticipated Revision 3 to the security standard required by CMMC and current DoD contracts alike, join Crowell attorneys Evan Wolff and Michael Gruden in a robust discussion with one of the key architects of Revision 3, NIST’s own Senior Computer Scientist, Victoria Pillitteri.

Webinar | 02.14.24, 1:00 PM EST - 2:00 PM EST

CMMC 2.0: Legal, Assessor, and Threat Intelligence Perspectives

Members of Crowell’s Privacy & Cybersecurity practice and panelists from Coalfire and Mandiant will discuss the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC) issued by the Department of Defense (DOD) in December.

Webinar | 01.09.24, 1:00 PM EST - 2:00 PM EST

CMMC Proposed Rule: What to Know

The Department of Defense (DOD) has released the highly anticipated proposed rule for the Cybersecurity Maturity Model Certification Program (CMMC). CMMC is a unified assessment model released by the DoD in response to the growing threat of cyberattacks and data theft from its supply chain vendors. As proposed, this program requires every Federal contractor that handles DoD sensitive data to comply with certain cybersecurity controls. CMMC will bring greater scrutiny to contractors’ cybersecurity compliance and greater risks associated with failure to comply. To achieve certification, you’re required to prove that your organization can meet a myriad of security control obligations, a process that can be daunting if you’re not familiar with the policies, procedures, and practices that may be required when the program is finalized.

Blog Posts 17 results

Blog Post | 02.10.20

Energy Cybersecurity Act of 2019

Crowell & Moring's Data Law Insights

Blog Post | 08.20.19

Privacy & Cybersecurity – New York Enacts the SHIELD Act

Crowell & Moring's International Trade Law

Podcasts 19 results

Podcast | 02.15.22

Byte-Sized Q&A: What Should Contractors Know About the Cybersecurity Provisions Included In, and Left Out Of, the National Defense Authorization Act

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces.  In this episode, Evan Wolff and Chris Hebdon discuss the notable cybersecurity provisions and omissions in the National Defense Authorization Act (NDAA) for Fiscal Year 2022.
...

Podcast | 01.19.22

Byte-Sized Q&A: What is CISA and Why is it Important to Government Contractors?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode of Byte Sized Q&A, Evan Wolff and Michael Gruden discuss the Cybersecurity Infrastructure Security Agency (CISA) and why it is important for contractors to take note of CISA’s actions.
...

Podcast | 12.03.21

Byte-Sized Q&A: What’s not in CMMC 2.0?

Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, hosts Evan Wolff and Kate Growley talk through some key elements that are no longer expected under CMMC 2.0.
...