On February 9, 2022, the SEC issued proposed rules for investment managers and mutual fund managers that would require these firms to adopt basic cybersecurity policies.[1] The cybersecurity regulatory language requires to account for: (1) Risk assessment; (2) User security and access; (3) Information protection; (4) Cybersecurity threat and vulnerability […]
Technology & Intellectual Property Update
Federal Circuit May Be Poised to Consider Copyrightability of Software APIs
In 2021, the Supreme Court ruled in Google LLC v. Oracle America, Inc., a case involving allegations of infringement by Google of Oracle’s copyrights in its Java APIs, that Google’s use of the Java code constituted fair use. In applying the fair use doctrine and skirting the issue of copyrightability, […]
Several States Introduce Data Privacy Bills to Start the 2022 Legislative Session
Florida Florida Senate Bill 1864 (the Florida Privacy Protection Act) introduces a number of requirements on companies that control personal information of Florida residents, including notice at or before the collection of personal information, consent requirements related to the collection of sensitive data, and requirements for responding to verified consumer […]
R.I.P. Data or Rip Data?
Plaintiffs filed a class-action suit against Morgan Stanley because sensitive client data was discovered on IT assets, which had been decommissioned and sold by Morgan Stanley. The suit recently settled, and the resulting agreement provides insight into the data security incident, potential legal liability, and possible preventions for such issues […]
Can Computer Forensics Reports be Protected by Attorney Work-Product Privilege?
The answer is maybe; if the proper steps are taken after a cybersecurity attack. After a cybersecurity attack has occurred, when a company is in the midst of containment and recovery is beginning, hiring an attorney may not seem like a priority. But, hiring an attorney at the right time […]

