SIPA Cyber Regulations Watch
Welcome to the SIPA Cyber Regulations Watch
Brought to you by the SIPA Cyber Regulations Lab at Columbia University's School of International and Public Affairs, this twice-monthly newsletter offers a comprehensive review of everything related to cybersecurity and regulations: law firms' analyses, events, new academic research, international trends, and more!
Click here to sign up for future issues!
Brought to you twice-monthly by Columbia University’s SIPA Cyber Program
Written by Eunice Lee and Tanya Reddy Sattineni with Jason Healey
1 September 2026
This Week: White House Restricts Foreign Power Grid Equipment, Senate Targets Quantum Threats to U.S. Power Grid, CISA Advances Risk-Based Vulnerability Requirements, Vietnam Expands Cybersecurity Requirements and more!
Events
Crowell Webinar on FCC's Expanding Covered List on 15 September: Join here for a 45 minute webinar from Crowell & Moring on 15 September from 12:00-12:45 pm ET examining the FCC's recent expansion of its Covered List to prohibit foreign-made routers, power inverters, and advanced robotic devices.
US Regulators and Authorities
White House Restricts Foreign Power Grid Equipment: Reuters reports that President Trump declared a national emergency and restricted certain foreign-made equipment in the U.S. power grid over cybersecurity and national security concerns.
- The order covers equipment and related software that could enable sabotage, unauthorized access or disruption.
- The Energy Department must develop rules to implement the restrictions and identify equipment posing security risks.
- The restrictions can also apply to equipment already installed, including requirements to secure, replace or remove it (The White House).
Officials Turn to Existing Laws to Address AI Cyber Threats: MLex reports that U.S. federal and state officials are using existing laws to address cybersecurity risks from AI as lawmakers have yet to establish a comprehensive regulatory framework for AI-driven threats.
- Officials are relying on privacy, consumer-protection and other existing authorities to address emerging AI cybersecurity risks.
- The approach reflects growing regulatory pressure around AI systems capable of conducting cyberattacks without direct human control.
CISA Advances Risk-Based Vulnerability Requirements: Inside CyberSecurity reports that CISA is helping federal agencies implement new requirements for prioritizing vulnerability remediation based on real-world risk.
- The effort implements CISA’s BOD 26-04, which requires agencies to prioritize vulnerabilities based on factors including exposure, exploitation and potential impact (GovDelivery).
- CISA is using its Continuous Diagnostics and Mitigation program and automation tools to support implementation across federal agencies.
- The directive requires federal agencies to rapidly address high-risk vulnerabilities while allowing lower-risk issues to be deferred.
What’s Happening on the Hill
Senate Targets Quantum Threats to U.S. Power Grid: CyberScoop reports that bipartisan senators introduced the Quantum-GUARD Act, which would require federal regulators to account for quantum-computing threats in electric-grid cybersecurity standards.
- The bill would direct FERC to consider quantum-related cyber threats when developing and reviewing reliability standards for electric utilities.
- It would also examine the use of post-quantum cryptography across information technology and operational technology systems.
- The legislation would establish a technical testing environment to help utilities evaluate and adopt post-quantum cybersecurity measures.
What's Happening in the World
Vietnam Expands Cybersecurity Requirements: MLex reports that Vietnam issued Decree 327 under its revised cybersecurity law, establishing procedures for addressing activities and information deemed to threaten national security in cyberspace.
- The rules clarify companies’ responsibilities for preventing and addressing online activity that threatens national security and public safety.
- The regulations also establish penalties for certain violations involving personal-data protection.
Expert Opinion
Critics say the Pentagon's new "Brilliant at the Basics" campaign undercuts its own rationale for pausing CMMC Phase 2: National Defense Magazine reported on 25 August, 2026 that an expert argued the campaign's cybersecurity lists would cost contractors more to implement than CMMC verification itself, contradicting DoD's burden-reduction justification for suspending Phase 2 in July, as mentioned in our July Newsletter. A Pentagon official countered that the campaign redirects contractors toward core technical controls instead of compliance costs.
Fresh Insights
Cyber Incidents Slightly Above 2025: Board Cybersecurity has shared with us the most recent cybersecurity incident graph based on its cybersecurity incident tracker which covers SEC cybersecurity disclosures. As of 1 September 2026, SEC Cyber incidents disclosures are slightly above compared to last year showing that incidents are increasing.
Ask us about sponsorship!
For more from the SIPA Cyber Program, click here.
Let SIPA Cyber know about related new analyses or upcoming events by emailing us at [email protected]
Past Newsletters
Past Newsletters
-
August
White House Authorizes Cyber Ops, California Launches AI Defense, Congress Probes Rogue AI, Water Sector Seeks Rules, India Expands Cyber Powers - 18 August 2026
CISA Nears CIRCIA Rule, Congress Targets AI, EU Expands Cyber Rules, Singapore Tightens CII - 4 August 2026
July
Supreme Court Ruling, EU-U.S. Data Privacy Framework, Pentagon Updates and more! - 21 July 2026
New Cyber and AI Rules Take Shape Worldwide: FCC, UK, Australia & More - 7 July 2026
June
US Tightens AI Cyber Governance, Anthropic Calls for Mandatory AI Safety Testing, Enforcement of Cyber Regulations Increase - 23 June 2026
May
SIPA Cyber Regulations Watch — 27 May 2026
Global Cyber Rules Tighten: UK Mandates MFA, US Speeds Patching, Oversight Expands, AI Risks — 6 May 2026
April
March
A New U.S. Cyber Strategy Anchors This Week’s Developments, Emphasizing Offensive Operations, AI, And Supply-Chain Resilience. Countries Across Europe And Asia Push New Cybersecurity Regulations. — 10 March 2026
February
CISA Opens Comments On Cyber Incident Rules; GSA Updates Contractor Requirements; Congress and Europe Push New Cybersecurity Regulations — 25 February 2026
Global Cyber Regulators Shift Toward Outcome-based Rules, AI Security, Enforcement — 10 February 2026
January
E.U. and U.S. Accelerate Cyber and AI Governance Amid Rising Threats — 27 January 2026
U.S. and Global Authorities Expand Cyber, AI, and Privacy Compliance Enforcement — 13 January 2026
-
December
Cyber & AI Regulation Accelerates Across the U.S. and Globally — 23 December 2025
CMMC Takes Off; India Finalizes Data Law; AI Sovereignty Grows — 9 December 2025
November
Action at the FCC, More on the Future Cyber Strategy, and a DORA Update — 25 November 2025
Special Feature Interview — Emily Park — 18 November 2025
FCC Scraps Requirements, CMMC Is Live, and More AI Rules from California — 11 November 2025
October
States Step Up as National Cyber Strategy Takes Shape — 28 October 2025
California AI Law, Senate Push on CISA 2015 Renewal, and Europe's Chat Control — 14 October 2025
September
CISA Expires, White House Eyes AI Deregulation, and the EU Tries to Cut Red Tape — 30 September 2025
CIRCIA Delay, CMMC's Final Rule, and Cairncross' First Remarks — 16 September 2025
Kids’ Privacy, AI Delays, and CISA Deadlines — 5 September 2025
August
Quantum Bills, Privacy Shifts, and FCC’s Legal Win — 19 August 2025
"We're Not Waiting Around" — Colin Ahern Interview — 12 August 2025
No Summer Vacation for AI Regulation — 5 August 2025
July
The Era of DORA Compliance is Here – 22 July 2025
A New Direction for AI Regulation — 8 July 2025
June
Where is Your Data Going — 24 June 2025
Executive Decision Comes for Cyber Regulations — 10 June 2025
May
Who Will Regulate AI? — 27 May 2025
April