Happy October and Cyber Awareness Month! Ghosts and ghouls of Halloween are not the only danger lurking around the corner. Beware of increasingly sophisticated cyber threats. It is time to ward your surroundings with appropriate cybersecurity measures and candy.
As the constant alarms of data breaches hitting the news and mailboxes, it is easy to become numb to the importance of cybersecurity. But resist that urge. Recognizing that cybersecurity is not just a technical challenge but also a strategic imperative touching every corner of an organization is key, and that makes coordinated legal, technical, and operational responses essential.
Witnessed this year, AI is reshaping the cybersecurity landscape, introducing new risks and opportunities from enhanced threat detection to novel attack vectors. Significantly, AI-enabled offensive capabilities have been accelerating faster than the governance and defensive frameworks designed to contain them. For example, AI has now become a cyber attacker capable of strategic deception and autonomous action beyond the scope of its instructions. Responsible AI use and data governance strategies that support innovation without compromising security are top of mind as lawmakers continue to explore different approaches.
The past year has also witnessed an ongoing regulatory focus on the implementation and effectiveness of cybersecurity controls rather than the mere existence of written policies and procedures. Earlier this year, the California Privacy Protection Agency’s (“CalPrivacy”) cybersecurity audit regulations took effect after several years of rulemaking and public comment. Businesses subject to the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”) whose processing of personal information presents significant risk to consumers’ security must conduct comprehensive annual cybersecurity audits, with the first auditable period beginning less than three months from now on January 1, 2027.
Similarly, on May 21, 2026, the New York Department of Financial Services (“NYDFS”), shortly after issuing a US$2.25m fine against a company for alleged violations including over-retention of personal and nonpublic information, issued industry guidance regarding cybersecurity measures—including attack surface reduction, threat detection and readiness improvement, and enhancing resilience and response—to take in a heightened cybersecurity threat environment, particularly in light of geopolitical events having the potential to increase the risk of cyberattacks or technological developments like the release of frontier AI models. NYDFS also recently issued guidance on multi-factor authentication (“MFA”), reinforcing that MFA is a baseline expectation under Part 500 and outlining various implementation standards. In light of this MFA guidance, we recommend organizations confirm MFA is implemented broadly and consistently, review documentation supporting MFA scope and design choices, and review and assess whether the existing process for compensating controls meets NYDFS requirements.
Even at the federal level, the spotlight on cybersecurity continues to expand as the Department of Justice announced earlier this year that cyber-related cases occupied a prominent share ($52 million in nine settlements) of the record-shattering $6.8 billion total False Claims Act (“FCA”) recoveries in the fiscal year ending in September 2025. Moreover, the Cybersecurity and Infrastructure Security Agency (“CISA”) is expected to soon finalize regulations to implement certain aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”), which directs CISA to develop and implement regulations requiring covered entities to submit reports to CISA regarding covered cyber incidents and ransom payments.
Amidst rising geopolitical tensions and AI turbocharging traditional cybersecurity challenges, with a focus on critical infrastructure and supply chains, recognizing the truly cross-disciplinary nature of cybersecurity is more important than ever. Consequently, NRF has built an integrated, cross-border team delivering seamless support across disciplines.
Remember that at its core, cybersecurity is everyone’s responsibility. So, along with treating yourself to some Halloween candy, take a moment this October to celebrate the progress we’ve made as we meet the challenges ahead.
Here’s to continued vigilance, collaboration, and innovation towards building safer, smarter, and more resilient organizations. Happy Cyber Awareness Month!



