Cybersecurity

17 laws across all jurisdictions

US Federal (8)
Technology Standards & Compliance
Computer Fraud and Abuse Act
CFAA — 18 U.S.C. § 1030
The federal anti-hacking statute. Criminalizes unauthorized access to computer systems and creates a civil cause of action companies use against former employees and competitors who misuse credentials or exceed authorized access.
cybersecurity
Last updated
Cyber Incident Reporting for Critical Infrastructure Act
CIRCIA — 6 U.S.C. §§ 681–681g
Requires critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. CISA is developing final implementing rules. Applies to entities in the 16 critical infrastructure sectors — including IT, communications, financial services, and energy. Tech companies operating critical infrastructure or providing services to those that do should monitor CISA's rulemaking.
cybersecurity
Last updated
Electronic Communications Privacy Act
ECPA — 18 U.S.C. §§ 2510–2522
Governs how the government and private parties can access electronic communications and stored data, covering real-time interception, stored records, and metadata collection. It is the primary federal statute protecting the privacy of digital communications. Applies to any entity that intercepts, accesses, or stores electronic communications.
cybersecurity
Last updated
Federal Risk and Authorization Management Program
FedRAMP — 44 U.S.C. §§ 3607–3616
A government-wide program establishing security assessment standards for cloud services used by federal agencies. Not a law but effectively mandatory if you want to sell cloud services to the federal government. Authorization is expensive and time-consuming but creates a significant competitive moat — relatively few cloud providers have full authorization. Managed by GSA. Authorization levels: Low, Moderate, High corresponding to sensitivity of data processed.
cybersecurity
Last updated
Gramm-Leach-Bliley Act
GLBA — 15 U.S.C. §§ 6801–6809
Requires financial institutions to explain their information-sharing practices and protect sensitive customer data. The Safeguards Rule mandates specific administrative, technical, and physical data security measures.
cybersecurity
Last updated
Health Information Technology for Economic and Clinical Health Act
HITECH — 42 U.S.C. §§ 17931–17954
Strengthened HIPAA enforcement and extended HIPAA obligations directly to business associates. Introduced tiered civil penalties and required HHS to conduct periodic audits of covered entities and business associates. Relevant to any tech company that is or may become a HIPAA business associate.
cybersecurity
Last updated
Health Insurance Portability and Accountability Act
HIPAA — 42 U.S.C. §§ 1320d–1320d-9
Any tech company building health apps, handling patient records, operating as a business associate of a covered entity, or processing protected health information must understand HIPAA. The Privacy Rule, Security Rule, and Breach Notification Rule each impose distinct obligations. HIPAA's definition of "covered entity" and "business associate" is broader than most tech founders assume — a SaaS platform that processes health data on behalf of a hospital is a business associate and must have a signed BAA. HHS Office for Civil Rights actively enforces, particularly against tech companies following data breaches.
cybersecurity
Last updated
NIST Cybersecurity Framework 2.0
NIST CSF
A voluntary framework — not a law — but practically functions as a de facto compliance standard. Referenced in state breach notification laws (Tennessee), required or strongly encouraged for federal contractors, and used by courts and regulators to assess reasonableness of cybersecurity programs. CSF 2.0 released February 2024 adds a new "Govern" function to the original five (Identify, Protect, Detect, Respond, Recover). Any tech company should understand this framework before claiming to have "reasonable" security.
cybersecurity
Last updated
US States (1)
Virginia Breach of Personal Information Notification
Va. Code § 18.2-186.6
Virginia's data breach notification statute requires individuals and entities to notify the Attorney General and affected Virginia residents when unencrypted personal information is accessed without authorization in a way that causes or is likely to cause identity theft or fraud. The law defines personal information, sets notification procedures including substitute notice for large breaches, and authorizes civil penalties up to $150,000 per breach.
cybersecurity
Last updated
International (8)
Security of Critical Infrastructure Act 2018
SOCI Act — No. 29, 2018
Governs cybersecurity obligations for critical infrastructure sectors in Australia, including communications, data storage, financial services, and technology. It requires risk management programs, incident reporting, and allows government intervention during cyber emergencies. Applies to owners and operators of critical infrastructure assets in Australia.
cybersecurity
Last updated
General Data Protection Regulation
GDPR — Regulation (EU) 2016/679
The EU's landmark data protection regulation and the global benchmark for privacy law. It establishes comprehensive rules for collecting, processing, and transferring personal data, with fines up to 4% of global annual revenue. Applies to any organization processing personal data of individuals in the EU, regardless of where the organization is located.
cybersecurity
Last updated
Privacy Protection Regulations (Data Security) 2017
Privacy Protection Regulations 2017
Detailed security regulations under Israel's Privacy Protection Law, specifying technical and organizational security measures required for databases at four classification levels. Requirements scale with the sensitivity of the data held. Applies to all database owners and managers in Israel.
cybersecurity
Last updated
Computer Misuse Act
SG CMA
Criminalizes unauthorized access to computer systems, hacking, and cyber attacks in Singapore. Updated in 2023 to cover denial-of-service attacks and dealing in stolen credentials. Applies to offenses committed within Singapore or targeting systems located there.
cybersecurity
Last updated
Cybersecurity Act
SG Cybersecurity Act
Establishes a regulatory framework for the oversight and protection of critical information infrastructure in Singapore. CII owners must comply with codes of practice, report cybersecurity incidents, and undergo regular audits. Applies to owners and operators of designated critical information infrastructure.
cybersecurity
Last updated
Act on Promotion of Information and Communications Network Utilization and Information Protection
Network Act — Act No. 19310
Imposes data protection, security, and user consent obligations on operators of information and communications networks in South Korea. One of Asia's earliest comprehensive internet regulatory frameworks.
Official source is in Korean
cybersecurity
Last updated
Computer Misuse Act 1990
CMA 1990 — c.18
The UK's primary cyber crime statute, criminalizing unauthorized access to computer systems, unauthorized modification of computer material, and the creation or distribution of hacking tools. It was one of the first laws of its kind when enacted in 1990. Applies to offenses committed within or targeting systems in the United Kingdom.
cybersecurity
Last updated
UK General Data Protection Regulation
UK GDPR — UK Data Protection Act 2018, Sch. 1
The retained EU GDPR as incorporated into UK law after Brexit, substantively similar to the EU version but enforced by the UK Information Commissioner's Office (ICO). Companies serving both EU and UK markets must comply with both versions independently. Applies to all organizations processing personal data of individuals in the United Kingdom.
cybersecurity
Last updated

Press Enter to go · ESC to close · Press / to open