Cybersecurity Resource Center
“While AI will help us improve cyber defense over time, it also accelerates the speed, scale, and sophistication of cyber threats.”
—Five Eyes Cyber Security Agencies
The need for collective action and cyber resilience has never been more urgent. Cybersecurity is a business, economic, and national security imperative in an increasingly AI-driven and geopolitically fragmented world.
Organizations and individuals are confronting a rapidly evolving threat landscape where cyber-enabled fraud, phishing, smishing, ransomware, and AI-enhanced attacks are affecting businesses, governments, and households at unprecedented levels. At the same time, the rapid deployment of increasingly autonomous AI agents is introducing a new generation of security, governance, and legal challenges. As AI becomes more deeply integrated into enterprise operations, Boards and executives are asking whether AI systems can be trusted, how AI agents should be governed, and how organizations can maintain meaningful human oversight.
The proliferation of powerful open-weight AI models, including models developed in jurisdictions with differing regulatory frameworks and safety controls, has expanded the attack surface. Organizations must now address not only malicious actors using AI to automate reconnaissance, exploit vulnerabilities, generate sophisticated social engineering campaigns, and develop malware, but also the risks of AI systems accessing sensitive information, interacting with enterprise applications in unintended ways, or operating beyond established governance and security controls. At the same time, deploying AI at scale requires significant investment in security, governance, compliance, and infrastructure, making effective risk management essential to realizing AI’s promised value.
Meanwhile, nation-state actors continue to target critical infrastructure and strategic industries, while geopolitical instability, supply chain vulnerabilities, and the transition to quantum-safe security further underscore the need for long-term resilience planning.
Against this backdrop, collaboration among the private sector, governments, regulators, and industry partners has become the cornerstone of effective cybersecurity. Building resilience requires secure AI adoption, strong governance, workforce awareness, and comprehensive incident preparedness.
Morrison Foerster’s renowned Data, Cyber + Privacy team helps organizations navigate these evolving issues, from AI governance and cybersecurity preparedness to incident response, ransomware, cyber-enabled fraud, regulatory investigations, and complex litigation. Join us throughout Cybersecurity Month, #MoFoCyberAware, for thought leadership and complimentary resources to help your organization securely adopt AI, strengthen cyber resilience, and reduce cybersecurity risk in an increasingly autonomous digital world.
Cybersecurity Webinar Series
The Lawyer’s Field Guide to Cybersecurity Incidents
The Lawyer’s Field Guide to Cybersecurity Incidents
Miriam Wugmeister from Morrison Foerster and Yinan Yang from CrowdStrike will break down the key concepts every lawyer needs to understand when advising during a cybersecurity incident.
North Korean IT Workers: Recent Developments, Risks & Best Practices
North Korean IT Workers: Recent Developments, Risks & Best Practices
Increasingly, the DPRK is disguising remote North Korean IT workers as U.S. based contractors—allowing them to evade U.S. sanctions, generate revenue for the regime, and potentially compromise networks.
CTRL+ALT+DEFEND: Insights on Emerging Threats and Best Practices for Cyber Risk Mitigation
CTRL+ALT+DEFEND: Insights on Emerging Threats and Best Practices for Cyber Risk Mitigation
Join Kaylee Bankston and Linda Clark for an engaging and informative webinar exploring the most pressing cybersecurity topics of 2025 and beyond.
Featured Insights
WebinarHow the New DOJ Rules on Sensitive Bulk Data Will Impact Your Company
The clock is ticking – U.S. companies that share “sensitive bulk data” with non-U.S. entities have until early April to comply with the new requirements under DOJ’s Sensitive Bulk Data Security Regulation.
Client AlertTrump Issues Executive Order on Cybersecurity Rolling Back Some Prior Policies and Introducing New Ones
Last week, the Trump administration made its priorities clear for the nation’s cybersecurity posture in the form of the newly issued executive order entitled “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13964 and Executive Order 14114” (the “Order”).
Client AlertChina’s New CBDT Regime: One Year On
China rolled out its “new,” streamlined cross-border data transfer (CBDT) regime on March 22, 2024, with the issuance by the Cyberspace Administration of China (CAC) of the Provisions on Facilitating and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》, the CBDT Provisions)
Client AlertDOJ Bulk Sensitive Data Regulations Update: New Compliance Guidance and Temporary Non-Enforcement Policy for Companies Working in Good Faith to Achieve Compliance
On Friday, April 11, 2025, the U.S. Department of Justice (DOJ) issued guidance about how the regulations would be applied, namely, a Compliance Guide and answers to 108 Frequently Asked Questions.
EventHow the New DOJ Rules on Sensitive Bulk Data Will Impact Your CompanyThis webinar discusses cybersecurity initiatives underway in the EU and assesses how they match up to what China’s cybersecurity laws have been developing into over the last few years.
WebinarResponding to a Cyber Security Incident – Best Practices
Morrison Foerster invites you to join an interactive webinar where you will learn more about the best practices for responding to a cybersecurity incident.
Client AlertThe SEC’s Controls-Based Approach to Cybersecurity Enforcement Continues, with an Accounting Twist
This settlement marks the SEC’s second application of Section 13(b)(2)(B) to cybersecurity controls in the aftermath of cyber incident threat actors accessing a public company’s IT systems and networks.
VideoFive Things to Know About the EU Cybersecurity Framework
Alex van der Wolk discusses how the EU has been bolstering its stance on cybersecurity through the implementation of various regulations.
Client AlertAn Unprecedented Cross-Border Data Regulatory Regime Version 3.0: Department of Justice Issues Final Rule Regulating Bulk Sensitive Data Transfers
The U.S. Department of Justice (“DOJ”) released final guidance on its new regulatory regime governing transactions involving certain sensitive data of U.S. persons and government‑related data and countries of concern. Read our analysis.














