On April 22, 2026, Rep. Brett Guthrie (R-KY), chairman of the House Committee on Energy & Commerce, and Rep. John Joyce (R-Pa.), leader of the Energy and Commerce Data Privacy Working Group and chairman of the Energy and Commerce Subcommittee on Oversight and Investigations, introduced HR 8413, the Securing and Establishing Consumer Uniform Rights and Enforcement Over Data Act (the “SECURE Data Act”).
As cybersecurity breaches grow more complex and frequent, regulators are increasingly focused on organizational compliance. Organizations such as Crowdstrike report that in 2025, cyberattacks are increasing in speed, volume, and sophistication—and cybercrime has evolved as a “highly efficient business.” The escalating threat landscape demands robust security frameworks that can withstand evolving risks.
Enter the amendments announced in November 2023 to the New York’s Department of Financial Services (NYDFS) Cybersecurity Regulation, 23 NYCRR Part 500 (“Amended Regulation”), that became effective on November 1, 2025. This post explores the breadth of these Amended Regulations, and the steps that covered entities need to take now.
As featured in #WorkforceWednesday®: Starting October 1, 2025, new AI rules in California will change how businesses in the state use automated tools in hiring, promotions, and other workplace decisions.
Key Takeaways for Employers:
- Anti-Discrimination Measures: The new regulations specifically target discriminatory practices in employers’ use of automated decision systems (ADS).
- Recordkeeping Requirements: Employers are now mandated to retain all ADS records and data for a minimum of four years.
- Regulatory Precedent: California’s proactive stance on AI regulation is anticipated to influence similar regulatory frameworks nationwide, establishing a precedent for other states.
In this episode of Employment Law This Week®, Epstein Becker Green attorney Frances M. Green provides an essential breakdown of the new California regulations, including actionable insights on conducting risk assessments and aligning them with existing cybersecurity and privacy audits to ensure compliance.
Blog Editors
Recent Updates
- Watch: Words Matter - How to Draft Arbitration Agreements That Hold Up in Court - Employment Law This Week
- One Nation, One Privacy Law: GOP Introduces Federal Privacy Legislation
- DOL Proposes New Safe Harbor for Selection of Designated Investment Alternatives for Defined Contribution Plans
- Watch: Joint Employment, Misclassification, I-9s, and Web Accessibility - New Rules and Rulings Reshape Employer Risk - Employment Law This Week
- Critical Infrastructure at Risk: Project Glasswing Urges Attention to AI-Driven Cyber-Risks