Legal Questions Abound About Cybersecurity
At NATAS, Lisa Sotto laid out the various legal regimes that oversee cybersecurity.

There's a simple reason why the heads of financial services firms are taking cybersecurity much more seriously today than five years ago—a major breach will cost them their jobs.
Sure, there are laws that require them to be vigilant, and a hack can be devastating to business, so it's best practice to be prepared. But the fact of the matter is that cyber defense doesn't add any competitive advantage and even with the best protections in place, you're always a step behind and vulnerable.
But a
More on Regulation
SEC pulls rulemaking proposals in bid for course correction
The regulator withdrew 14 Gensler-era proposals, including the controversial predictive data analytics proposal.
Trading venues seen as easiest targets for Esma supervision
Platforms do not pose systemic risks for member states and are already subject to consistent rules.
The Consolidated Audit Trail faces an uncertain fate—yet again
Waters Wrap: The CAT is up and running, but with a conservative SEC in place and renewed pressure from politicians and exchanges, Anthony says the controversial database faces a death by a thousand cuts.
Exchanges plead with SEC to trim CAT reporting requirements
Letters from Cboe, Nasdaq and NYSE ask that the new Atkins administration reduce the amount of data required for the Consolidated Audit Trail, and scrap options data collection entirely.
EU banks want the cloud closer to home amid tariff wars
Fears over US executive orders have prompted new approaches to critical third-party risk management.
Friendly fire? Nasdaq squeezes MTF competitors with steep fee increase
The stock exchange almost tripled the prices of some datasets for multilateral trading facilities, with sources saying the move is the latest effort by exchanges to offset declining trading revenues.
Europe is counting its vendors—and souring on US tech
Under DORA, every financial company with business in the EU must report use of their critical vendors. Deadlines vary, but the message doesn’t: The EU is taking stock of technology dependencies, especially upon US providers.
Regulators can’t dodge DOGE, but can they still get by?
The Waters Wrap: With Trump and DOGE nipping at regulators’ heels, what might become of the CAT, the FDTA, or vendor-operated SEFs?