Photo of Sierra Stubbs

Sierra Stubbs

Drawing on her experience at the U.S. Department of Commerce, Sierra Stubbs advises clients on a range of regulatory issues related to cybersecurity, national security, data privacy, artificial intelligence, and public policy. Sierra helps clients navigate government enforcement matters and internal investigations, including on the theft of trade secrets, supply chain security, and cybersecurity compliance. More broadly, Sierra advises clients on risks related to their compliance with cybersecurity controls and standards, such as those related to cryptography, infrastructure security, and network security.

Additionally, Sierra counsels clients through technology-related security incidents, including cybersecurity breaches and incidents impacting dual use and emerging technologies. In the course of this work, Sierra routinely advises clients on crisis management and engagement with law enforcement and other regulators. Further, Sierra advises clients on their compliance with U.S. state and federal privacy and technology laws, such as the Gramm-Leach-Bliley Act, the California Consumer Privacy Act, the Colorado AI Act, and similar statutes. Sierra also supports clients’ public policy strategies and initiatives, including those related to technology and innovation, artificial intelligence, privacy, intellectual property, and national security.

Prior to joining Covington, Sierra served in the Office of the Chief of Staff to the U.S. Secretary of Commerce, most recently as a Special Advisor.

Oklahoma recently enacted Senate Bill 626, which substantially amends the state’s data breach notification law to broaden the scope of notification obligations and add a new regulator notification requirement along with a new “safe harbor”-style provision that provides liability protections if certain security measures are implemented.  The changes to Oklahoma’s law follow changes to other state data breach notification laws within the past year, including New York’s addition of a 30-day deadline for notice to individuals (added in early 2025) and Pennsylvania’s addition of a regulator notification requirement and obligations to provide free credit monitoring (added in mid-2024).  Key updates from Oklahoma’s bill, which will go into effect on January 1, 2026, are discussed in further detail below.

Continue Reading Oklahoma Substantially Amends Its Data Breach Notification Statute

The Senate Intelligence Committee’s January 30, 2025, confirmation hearing for former Representative Tulsi Gabbard, President Trump’s nominee for Director of National Intelligence, previewed a potentially difficult reauthorization path for Section 702 of the Foreign Intelligence Surveillance Act (“FISA”).  While Gabbard appears to now publicly favor reauthorization of Section 702, her

Continue Reading Tulsi Gabbard’s Confirmation Hearing for Director of National Intelligence: A Preview of a FISA Section 702 Reauthorization Fight?