Reference · Sectors

Sectors tracked in the briefing.

The sectors below match the filter set on the daily briefing. Banks and generic software or IT vendors sit within their host industry wherever their customers run — open a card to see today’s stories for that sector.

HEALTHCARE

Healthcare

Healthcare in the US is anchored by HIPAA and the HHS HPH cybersecurity proposed rule. Covered entities and business associates that handle PHI are in scope, and a breach affecting more than 500 records, or ransomware that hits unencrypted ePHI, is the kind of event that triggers breach notification, OCR scrutiny, and class-action exposure.

FINANCIAL

Financial services

Banks, broker-dealers, and investment advisers sit here. US regulators run the show — SEC cyber disclosure, FFIEC guidance, the FTC Safeguards Rule, GLBA, and NYDFS Part 500 — and attention is triggered by a "material" cyber incident under the SEC 8-K Item 1.05 four-business-day clock, an operational outage that disrupts a regulator-reportable service, or a vendor concentration finding in a SOC 2 attestation.

OT

OT / ICS

Operational technology and industrial control systems — pipelines, water utilities, manufacturing floors, building automation. CISA and TSA advisories, plus NIST SP 800-82r3, are the language regulators and auditors speak here. Attention is triggered when a remote-access pivot reaches a human-machine interface, when an engineering workstation is found exposed, or when a sector-wide campaign hits an OT vendor that a critical facility depends on.

RETAIL

Retail & e-commerce

Retail and e-commerce are bound by PCI-DSS v4.0 whenever cardholder data passes through the environment. Merchants, processors, and acquirers are all in scope, and QSAs focus on script integrity on checkout pages, 3DS implementation, tokenization coverage, and segmentation between the CDE and the rest of the store network.

PUBLIC

Public sector

Federal, state, and local government entities and the contractors that run their systems. CIRCIA reporting sits alongside the patchwork of state breach laws, TSA Security Directives for pipelines and rail, FedRAMP for federal cloud workloads, and NIST CSF adoption programmes. Attention is triggered by a ransomware outage that interrupts resident services, by a vendor incident at a managed-service provider, or by a CISA "must patch" directive on a known exploited vulnerability.

MANUFACTURING

Manufacturing

Manufacturing covers the protection of both production IP and the OT line that runs it. CMMC applies across the defense industrial base, NIST CSF remains the lingua franca for control mappings, and buyers now send due-diligence questionnaires through the supplier risk-management register. Attention is triggered when ransomware stops a production cell, when a dual-use export is at risk of exfiltration, or when a sector-wide campaign targets a small specialist with privileged access to tier-1 OEMs.

ENERGY

Energy & utilities

Grid operators, transmission system operators, distribution utilities, and the upstream midstream operators that feed them. TSA Pipeline Security Directives and NERC CIP cyber-security standards apply in the US, with NIST CSF as the cross-program mapping language. Attention is triggered by a firmware gap on remote-access VPN or jump host, by an intrusion disclosed by CISA or a sector ISAC, or by a near-miss at a peer operator triggering a precautionary review.

INSURANCE

Insurance

Health payers sit under HIPAA; P&C and life carriers sit under state breach notification laws and the NYDFS Part 500 cybersecurity regulation; SOC 2 carries the attestation weight for vendors serving all three. Attention is triggered by a phishing wave that reaches claims handlers, by exposure of policyholder or claims data, or by an ICT vendor incident that interrupts underwriting or claims processing.