Low Library Column

SIPA Cyber Regulations Watch

Welcome to the SIPA Cyber Regulations Watch

Brought to you by the SIPA Cyber Regulations Lab at Columbia University's School of International and Public Affairs, this twice-monthly newsletter offers a comprehensive review of everything related to cybersecurity and regulations: law firms' analyses, events, new academic research, international trends, and more! 

Click here to sign up for future issues!

 

Brought to you twice-monthly by Columbia University’s SIPA Cyber Program

Written by Eunice Lee and Tanya Reddy Sattineni with Jason Healey 

1 September 2026

This Week: White House Restricts Foreign Power Grid Equipment, Senate Targets Quantum Threats to U.S. Power Grid, CISA Advances Risk-Based Vulnerability Requirements, Vietnam Expands Cybersecurity Requirements and more!

Events

Crowell Webinar on FCC's Expanding Covered List on 15 September: Join here for a 45 minute webinar from Crowell & Moring on 15 September from 12:00-12:45 pm ET examining the FCC's recent expansion of its Covered List to prohibit foreign-made routers, power inverters, and advanced robotic devices.

US Regulators and Authorities

White House Restricts Foreign Power Grid EquipmentReuters reports that President Trump declared a national emergency and restricted certain foreign-made equipment in the U.S. power grid over cybersecurity and national security concerns.

  • The order covers equipment and related software that could enable sabotage, unauthorized access or disruption.
  • The Energy Department must develop rules to implement the restrictions and identify equipment posing security risks.
  • The restrictions can also apply to equipment already installed, including requirements to secure, replace or remove it (The White House).

Officials Turn to Existing Laws to Address AI Cyber ThreatsMLex reports that U.S. federal and state officials are using existing laws to address cybersecurity risks from AI as lawmakers have yet to establish a comprehensive regulatory framework for AI-driven threats.

  • Officials are relying on privacy, consumer-protection and other existing authorities to address emerging AI cybersecurity risks.
  • The approach reflects growing regulatory pressure around AI systems capable of conducting cyberattacks without direct human control.

CISA Advances Risk-Based Vulnerability RequirementsInside CyberSecurity reports that CISA is helping federal agencies implement new requirements for prioritizing vulnerability remediation based on real-world risk.

  • The effort implements CISA’s BOD 26-04, which requires agencies to prioritize vulnerabilities based on factors including exposure, exploitation and potential impact (GovDelivery).
  • CISA is using its Continuous Diagnostics and Mitigation program and automation tools to support implementation across federal agencies.
  • The directive requires federal agencies to rapidly address high-risk vulnerabilities while allowing lower-risk issues to be deferred.

What’s Happening on the Hill

Senate Targets Quantum Threats to U.S. Power Grid: CyberScoop reports that bipartisan senators introduced the Quantum-GUARD Act, which would require federal regulators to account for quantum-computing threats in electric-grid cybersecurity standards.

  • The bill would direct FERC to consider quantum-related cyber threats when developing and reviewing reliability standards for electric utilities.
  • It would also examine the use of post-quantum cryptography across information technology and operational technology systems.
  • The legislation would establish a technical testing environment to help utilities evaluate and adopt post-quantum cybersecurity measures.

What's Happening in the World

Vietnam Expands Cybersecurity RequirementsMLex reports that Vietnam issued Decree 327 under its revised cybersecurity law, establishing procedures for addressing activities and information deemed to threaten national security in cyberspace. 

  • The rules clarify companies’ responsibilities for preventing and addressing online activity that threatens national security and public safety.
  • The regulations also establish penalties for certain violations involving personal-data protection.

Expert Opinion

Critics say the Pentagon's new "Brilliant at the Basics" campaign undercuts its own rationale for pausing CMMC Phase 2: National Defense Magazine reported on 25 August, 2026 that an expert argued the campaign's cybersecurity lists would cost contractors more to implement than CMMC verification itself, contradicting DoD's burden-reduction justification for suspending Phase 2 in July, as mentioned in our July Newsletter. A Pentagon official countered that the campaign redirects contractors toward core technical controls instead of compliance costs.

Fresh Insights

Cyber Incidents Slightly Above 2025: Board Cybersecurity has shared with us the most recent cybersecurity incident graph based on its cybersecurity incident tracker which covers SEC cybersecurity disclosures. As of 1 September 2026, SEC Cyber incidents disclosures are slightly above compared to last year showing that incidents are increasing.

Image
2026 Updated Chart

Ask us about sponsorship!

For more from the SIPA Cyber Program, click here.

Let SIPA Cyber know about related new analyses or upcoming events by emailing us at [email protected]

 

Past Newsletters

Past Newsletters