In recent developments, the landscape of cybersecurity regulation is undergoing significant evolution in both the United States and internationally, driven by emerging risks and new technological paradigms. Central to this are the updates to the US Department of Defense (DOD) cybersecurity protocols and the New York Department of Financial Services (NY DFS) guidance on artificial intelligence-related risks.

On 11 October 2024, the US Department of Defense announced the finalisation of its Cybersecurity Maturity Model Certification (CMMC) rule. The CMMC framework introduces mandatory cybersecurity requirements for almost all DOD contracts, structured across three levels based on the sensitivity of information managed. Level 1 focuses on basic cybersecurity practices for contractors handling Federal Contract Information (FCI), necessitating an annual self-assessment. Level 2 is aimed at contractors dealing with Controlled Unclassified Information (CUI), mandating 110 security controls and typically requiring third-party assessments. However, a limited number of contractors may opt for self-assessment. Lastly, Level 3 applies to contractors engaged with CUI linked to critical programmes or high-value assets, requiring compliance with an additional 24 security controls assessed by the DOD’s internal team.

The implementation of the CMMC will be rolled out over the next four years, with Level 1 and Level 2 self-assessments commencing in the early phase, and full operational capability anticipated within several years. The DOD estimates that achieving compliance over the next decade will cost approximately $39 billion. This development bears significant implications, particularly for smaller firms, as meeting these standards, especially higher levels, demands substantial financial and operational investments. Importantly, contractors must secure the appropriate CMMC certification to be eligible for winning contracts.

Reflecting updates to the initial proposals, the final rule extends the phasing-in period and exempts External Service Providers (ESPs) from undergoing their own CMMC assessments unless they directly handle CUI. Further guidance on this framework is expected by mid-2025.

In a parallel move, on 16 October 2024, the New York Department of Financial Services issued a circular letter highlighting the cybersecurity risks associated with artificial intelligence, specifically within the financial and insurance sectors. While this guidance does not establish new regulatory requirements, it underscores the expectation for a risk-based cybersecurity programme capable of addressing AI-driven threats. The NY DFS guidance identifies particular threats posed by AI, including AI-enabled social engineering and the amplification of conventional cyberattacks through AI capabilities.

The guidance also addresses the risks associated with deepfakes. These AI-generated synthetic media can be misused in sophisticated phishing schemes by creating falsely authentic audio or visual content. One highlighted incident involved an employee at a multinational firm being duped into transferring $25 million following a manipulated video conference call that appeared to include the company’s CFO.

Existing regulations, such as the DFS’s Part 500 cybersecurity rule, require firms to conduct periodic and event-triggered risk assessments. These assessments must now integrate considerations related to AI utilisation, whether internally developed or deployed by third-party service providers. The DFS guidance includes recommendations for adopting AI threat training, enhancing access controls, and ensuring third-party notification of cybersecurity events. While some suggestions align with future regulatory expansions effective by November 2025, the DFS promotes proactive compliance.

Despite these risks, AI is also recognised for its potential as a cybersecurity tool. It can assist in tasks such as log review and threat detection, providing organisations with enhanced capabilities to safeguard their systems.

As cybersecurity continues to grapple with rapid technological advancement and escalating threats, these regulatory evolutions highlight a growing focus on resilience and preparedness in a world increasingly shaped by digital and AI-driven innovation.

Source: Noah Wire Services