Reference · Sectors

Sectors tracked in the briefing.

The sectors below match the filter set on the daily briefing. Banks and generic software or IT vendors sit within their host industry wherever their customers run — open a card to see today’s stories for that sector.

HEALTHCARE

Healthcare

Healthcare in the US is anchored by HIPAA and the HHS HPH cybersecurity proposed rule. Covered entities and business associates that handle PHI are in scope, and a breach affecting more than 500 records, or ransomware that hits unencrypted ePHI, is the kind of event that triggers breach notification, OCR scrutiny, and class-action exposure.

FINANCIAL

Financial services

Banks, broker-dealers, and investment advisers sit here — both US (SEC cyber disclosure, FFIEC) and EU (DORA for ICT risk). Attention is triggered by a "material" cyber incident under the SEC 8-K Item 1.05 four-business-day clock, an operational outage that disrupts a regulator-reportable service, or an unresolved vendor concentration finding in the DORA register.

OT

OT / ICS

Operational technology and industrial control systems — pipelines, water utilities, manufacturing floors, building automation. CISA and TSA advisories, plus NIST SP 800-82r3, are the language regulators and auditors speak here. Attention is triggered when a remote-access pivot reaches a human-machine interface, when an engineering workstation is found exposed, or when a sector-wide campaign hits an OT vendor that a critical facility depends on.

RETAIL

Retail & e-commerce

Retail and e-commerce are bound by PCI-DSS v4.0 whenever cardholder data passes through the environment. Merchants, processors, and acquirers are all in scope, and QSAs focus on script integrity on checkout pages, 3DS implementation, tokenization coverage, and segmentation between the CDE and the rest of the store network.

PUBLIC

Public sector

Federal, state, and local government entities and the contractors that run their systems. CIRCIA reporting sits alongside the patchwork of state breach laws, TSA Security Directives for pipelines and rail, and NIST CSF adoption programmes. Attention is triggered by a ransomware outage that interrupts resident services, by a vendor incident at a managed-service provider, or by a CISA "must patch" directive on a known exploited vulnerability.

MANUFACTURING

Manufacturing

Manufacturing covers the protection of both production IP and the OT line that runs it. NIS2 supply-chain duties (Annex I) reach European manufacturers directly and buyers of their components indirectly. Attention is triggered when ransomware stops a production cell, when a dual-use export is at risk of exfiltration, or when a sector-wide campaign targets a small specialist with privileged access to tier-1 OEMs.

ENERGY

Energy & utilities

Grid operators, transmission system operators, distribution utilities, and the upstream midstream operators that feed them. TSA Pipeline Security Directives apply in the US; in the EU, NIS2 "essential entity" duties apply to most large energy operators. Attention is triggered by a firmware gap on remote-access VPN or jump host, by an intrusion disclosed by CISA or a sector ISAC, or by a near-miss at a peer operator triggering a precautionary review.

INSURANCE

Insurance

Health payers sit under HIPAA; P&C and life carriers sit under state breach notification laws and the NYDFS Part 500 cybersecurity regulation; EU insurers are caught by DORA and Solvency II ICT risk guidance. Attention is triggered by a phishing wave that reaches claims handlers, by exposure of policyholder or claims data, or by an ICT vendor incident that interrupts underwriting or claims processing.