- Cybersecurity Docket
- Posts
- NIST Releases CSF 2.0 Quick-Start Guides Aligning Cyber Risk, Risk Management, Workforce Strategy
NIST Releases CSF 2.0 Quick-Start Guides Aligning Cyber Risk, Risk Management, Workforce Strategy
Plus, experts warn of ‘loud and aggressive’ extortion wave following Trivy hack.

SPONSORED BY

Good morning! Here’s what’s up.

People
Christopher Barton has joined CYPFER, a global market leader in ransomware post-breach remediation and cyber-attack first response, as chief operating officer.

Clips ✂️
The U.S. NIST (National Institute of Standards and Technology) released two new NIST Cybersecurity Framework (CSF) 2.0 quick-start guides (QSG), adding to an expanding portfolio of implementation resources that offer tailored pathways for different audiences to engage with CSF 2.0. One document positions cybersecurity risk as a core component of enterprise risk management and integrates it with workforce planning to improve how organizations assess, communicate, and respond to threats, while the other explains what informative references are and how they support achieving the outcomes of CSF 2.0.
NIST published the final version of NIST Special Publication (SP) 1308, NIST Cybersecurity Framework 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick-Start Guide, which draws on concepts and practices from enterprise risk management, cybersecurity risk management, and workforce management to help organizations improve communication about cybersecurity risks, plan workforce decisions, and implement risk-informed responses. Currently available, the document identifies that cybersecurity risks are one of many types of risk that all organizations should manage and integrate into their broader enterprise risk management (ERM) strategy.
Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack
Mandiant is responding to a major, ongoing supply-chain attack involving the compromise of Trivy, a widely used open-source tool from Aqua Security that’s designed to find vulnerabilities and misconfigurations in code repositories.
The fallout from the attack spree, which was first detected March 19, is extensive and poses substantial risk for follow-on compromises and threatening extortion attempts.
“We know over 1,000 impacted SaaS environments right now that are actively dealing with this particular threat campaign,” Charles Carmakal, chief technology officer at Mandiant Consulting said during a threat briefing held in conjunction with the RSAC 2026 Conference. “That thousand-plus downstream victims will probably expand into another 500, another 1,000, maybe another 10,000.”
Attackers stole a privileged access token and established a foothold in Trivy’s repository automation process by exploiting a misconfiguration in the tool’s GitHub Actions environment in late February, Aqua Security said in a blog post.
Companies face difficult choices in blaming hackers for an attack
Businesses need to think carefully about when they publicly blame a threat actor for a cyberattack, lest they invite unwanted consequences, experts said at a panel at the RSAC 2026 Conference here on Tuesday.
“The rush to attribute is a risky one,” Megan Stifel, the chief strategy officer at the Institute for Security and Technology, a cybersecurity think tank, said during a panel discussion.
Brett Callow, a ransomware expert and senior adviser at FTI Consulting who advises cyberattack victims, called attribution “extremely risky” because “you are bringing third parties into the discussion, and those third parties may very well respond.”
That response could take the form of diplomatic retaliation, in the case of a nation-state actor, or a data leak, in the case of a cybercrime gang. In either case, Callow said, public blame “can attract considerable blowback” and even “result in your losing control of the narrative, which isn’t a good thing at all.”
Expert says AI is the top cybersecurity issue faced by retailers
When cybersecurity expert Jeff Greene was asked at NRF’s recent Retail Law Summit what should be at the top of the checklist for in-house attorneys in charge of cyber compliance this year, his answer was clear.
“It’s AI,” he said without hesitation. “It’s the No. 1 issue that companies face.”
Greene, an attorney who previously headed the cybersecurity division at the federal Cybersecurity and Infrastructure Security Agency and was chief of cyber response at the White House National Security Council during the Biden administration, is now co-founder of the security consulting firm Civira Partners. He was the keynote speaker during a session on security and threats to retail data moderated by NRF Chief Administrative Officer and General Counsel Stephanie Martz.
“There are so many angles to it,” Greene said of issues involving artificial intelligence that need to be addressed. “How you’re using it … how your vendors are using it, what they’re doing with your data, what your policies are.”
3.1 Million Impacted by QualDerm Data Breach
Healthcare management services provider QualDerm Partners is notifying more than 3.1 million people that their personal, medical, and health insurance information was stolen in a December 2025 data breach.
The incident, the company says, was discovered on December 24 and involved unauthorized access to its network for two days.
During this window, the attackers exfiltrated certain information from the “limited number of systems” that they compromised, the company notes in an incident notification (PDF).
The stolen information, it says, includes names, addresses, dates of birth, email addresses, medical record numbers, doctor names, treatment and diagnosis information, health insurance information, dates of death, and, in some cases, government-issued ID information.
QualDerm also notes that its investigation into the data breach continues, and that it has decided to notify the patients who have been identified to date.
Oklahoma Enacts Consumer Data Privacy Law
On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law. In doing so, Oklahoma becomes the 20th state to enact a broadly applicable consumer data privacy law.
Passage of a consumer data privacy law in Oklahoma has been a multiyear process. The Oklahoma House first passed a consumer data privacy bill authored by then-Representative Collin Walke in 2021, but the bill stalled in the Senate. The House again passed a bill in 2022, and it again stalled in the Senate.
The new law is a more business-friendly blend of the 2022 version of Virginia’s consumer data privacy law and the Texas consumer data privacy law. Ultimately, entities subject to other state privacy laws will not have any new compliance obligations. In the below article, we provide an overview of the new law.

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026 at the historic Mayflower Hotel in Washington, D.C.!
Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.
👉 UNTIL FRIDAY, MARCH 27: Please use the codes below to get a 25% early-bird discount (regular in-person registration fee is $1,500; regular virtual registration fee is $750). Please register here:
In-person attendance: UPDATE909DC25
Virtual attendance: UPDATE909V25
