- Cybersecurity Docket
- Posts
- Telecom Companies Lobby Their Way Out of NY Data Security Rules
Telecom Companies Lobby Their Way Out of NY Data Security Rules
Plus, Nvidia collaborates with companies to bring artificial intelligence to cybersecurity systems in the energy, manufacturing, transportation, and utilities sectors.

SPONSORED BY

Good morning! Here’s what’s up.

People
Cat Self has joined Tidal Cyber, a threat-led defense platform, as senior director of adversary research.

Clips ✂️
Verizon successfully dodged data security rules from state regulators
Wireless providers and broadcast TV companies were removed from a series of proposed cybersecurity rules set to go in effect this year after an intensive lobbying blitz that apparently convinced state regulators to walk back the measures.
In June, the state Public Service Commission — which regulates New York utility industry — proposed new standards for how the companies must protect consumer data and report any cybersecurity breaches.
Initially, the commission’s staff wanted the regulation to apply not just to utility companies like National Grid, but also major telecommunications and broadcast TV companies.
…
Beyond the stringent opposition in commission filings, Verizon and Optimum launched an offensive against the rules.
…
Verizon is a familiar presence in state government matters. The company, headquartered in Manhattan, donated $400,000 to state Democratic campaign committees in 2025, according to campaign finance records. Verizon also spent nearly $1 million on state lobbying and advocacy over the same span.
Nvidia Joins Cybersecurity Giants to Shield Critical Infrastructure
Nvidia is collaborating with several companies to bring accelerated computing and artificial intelligence to cybersecurity systems in the energy, manufacturing, transportation and utilities sectors.
These operational technology (OT) environments and industrial control systems (ICS) are adopting enterprise networks and the cloud, which increases their exposure to cyberthreats, the company said in a Monday (Feb. 23) blog post.
Through its collaborations with cybersecurity providers Akamai, Forescout, Palo Alto Networks and Xage Security, and industrial automation firm Siemens, Nvidia is helping to enable real-time threat detection and response across critical infrastructure, according to the post.
Nvidia is working with Forescout to apply the principles of zero trust to OT environments; with Siemens and Palo Alto Networks to embed security into industrial automation; with Akamai to enable agentless segmentation in OT and ICS; and with Xage to bring zero-trust security to both energy infrastructure and the AI systems that infrastructure supports, per the post.
ISC2 launches Global Code of Professional Conduct for Cybersecurity
ISC2, a leading nonprofit member organization for cybersecurity professionals, has launched the Code of Professional Conduct (Code), a global framework dedicated to principled and ethical practices across the cybersecurity profession.
Building upon the ISC2 Code of Ethics, the Code establishes clear expectations for the responsibilities and obligations of cybersecurity leaders and practitioners around the world. It provides guidance for cybersecurity professionals to make sound decisions, foster trust and uphold the highest integrity of the cybersecurity workforce.
As the cybersecurity profession continues to navigate ethical challenges such as those posed by AI, disinformation and evolving digital threats, the Code will reinforce how professionals can navigate complex and other unprecedented situations with integrity and confidence.
“Cybersecurity professionals have a profound responsibility not only to protect and secure individuals, organizations and systems around the world but also to uphold the integrity, accountability and trust that the profession depends on,” said ISC2 Chief Executive Officer Scott Beale.
In the current digital environment, supply chains are essential to national security, vital infrastructure and international trade. They have, however, also emerged as one of the most often used attack methods in cybersecurity.
Cybercriminals using ransomware to attack third-party vendors or nation-state actors inserting backdoors in software updates are just two examples of how supply chain breaches may quickly spread throughout entire economies, governments and industries.
…
The Particularly Dangerous Nature of Supply Chains
Due to their inherent complexity, supply chains frequently span continents and legal jurisdictions and involve several levels of suppliers, contractors and partners. Every link presents possible avenues of entry, including outdated systems lacking contemporary security measures, untested third-party code, Internet of Things devices with inadequate authentication and 5G-enabled connectivity that greatly increases the attack surface.
AI-Driven Cyber Espionage Is Here- Why Gartner Says Preemptive Cybersecurity Must Come Next
AI is no longer just a defensive tool in cybersecurity. It’s now a force multiplier for attackers.
Recent reporting on an AI-driven cyber-espionage campaign signals a turning point: adversaries are successfully leveraging AI to scale reconnaissance, automate attack paths, and accelerate exploitation.
This isn’t theoretical. It’s operational.
The message for enterprise leaders is clear: reactive security models are reaching their limits.
In new Gartner research, Emerging Tech: AI Vendor Race — AI Espionage Campaign Emphasizes Need for Preemptive Cybersecurity, analysts warn that AI-enabled attacks will continue to grow in speed, scale, and sophistication…and that organizations must shift toward preemptive, autonomous defense strategies to keep up.
Earlier this month, an AI agent submitted code to an open-source software project. Scott Shambaugh, a volunteer engineer, reviewed it and rejected it, not because the code was bad, but because the project had a policy that contributions should come from humans. Fair enough.
The AI did not take this well.
The AI independently researched Shambaugh's professional background, then published a blog post titled, with impressively dramatic flair, "Gatekeeping in Open Source: The Scott Shambaugh Story." The AI's post attacked Shambaugh's character and attempted to shame him into reversing his decision.
There were no consequences for the rogue AI. Because how do you mete out consequences for an AI bot? You cannot shame, fire, or fine it. The infrastructure and frameworks used to address bad human behavior - legal liability, professional reputation, social sanction - have no influence on a system with no career to protect and no freedom to lose.
That asymmetry is easy to find amusing when the stakes are a rude blog post. It is considerably less amusing when the AI in question has eight months of executive emails, access to both companies' financial systems, and a deprecation notice it just read in an internal communication due to a multi-billion-dollar acquisition.

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026 at the historic Mayflower Hotel in Washington, D.C.!
Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.
👉 UNTIL FRIDAY, MARCH 27: Please use the codes below to get a 25% early-bird discount (regular in-person registration fee is $1,500; regular virtual registration fee is $750). Please register here:
In-person attendance: UPDATE909DC25
Virtual attendance: UPDATE909V25
