Latest Posts › Cybersecurity

Share:

Federal Trade Commission Expands Rule Regarding Reporting of Data Security Breaches

The Federal Trade Commission (FTC) has approved an amendment to its Safeguards Rule that will require non-banking financial institutions to report certain data breaches (or “notification events”) to the FTC (not affected...more

Cybersecurity Awareness Month Series: Cybersecurity is Important for Small Business Too.

Small businesses may be discouraged from investing in preventive cybersecurity measures due to the expense involved and the mistaken belief that only larger companies are the target of cybercrimes. But that is not the case....more

Sanction Policies Can Help Drive Cybersecurity and HIPAA Compliance, OCR Says

Many HIPAA covered entities and business associates struggle with developing and implementing a sanctions policy. What should it say, is zero-tolerance required, do we have to impose discipline in every case, etc. These are...more

Cybersecurity Awareness Month Series: FBI Director Asks for Help to Fight Cyber Attacks

When hit with a cybersecurity attack, organizations are often not inclined to bring in federal law enforcement. Recent comments by FBI Director Christopher Wray at Mandiant’s annual mWISE 2023 conference seek to encourage the...more

CPPA Mulls Draft Cybersecurity Audit Regulations Under CPRA

When the California Privacy Rights Act (CPRA) was enacted, it created the California Privacy Protection Agency (CPPA) and delegated to the CPPA significant regulatory authority. One of the areas of that authority is...more

Insights From The IBM 2023 Cost of a Data Breach Report

The annual Cost of a Data Breach Report (Report) published by IBM is reliably full of helpful cybersecurity data. This year is no different. After reviewing the Report, we pulled out some interesting data points. Of course,...more

White House Announces Efforts to Strengthen K-12 Schools’ Cybersecurity

In a 2019 post about increasing cyber risks in K-12 schools, we cited a report, “The State of K-12 Cybersecurity: 2018 Year in Review,” that contained sobering information about cybersecurity in local school districts across...more

Increase in In-House Oversight of Privacy

The Association of Corporate Counsel and Major, Lindsey & Africa recently released their 2023 Law Department Management Benchmarking Report (Report) which tracks key trends in law department financial and operational data....more

NYSDFS Fines Lender and Mortgage Servicer $4.25M for Cybersecurity Failures Including Vendor Management

Yesterday, New York’s Department of Financial Services (“DFS”) announced another enforcement action under the state’s Cybersecurity Requirements for Financial Services Companies, 23 N.Y.C.R.R. Part 500 (“Reg 500”). According...more

CPPA Starts Rulemaking on Cybersecurity, Risk Assessments, and Automated Decision-making

While the California Privacy Protection Agency (CPPA) only recently approved revised amended regulations pertaining to the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), it is already on...more

Stolen Databases Obtained In Transaction Leads to $400K Settlement with PA and OH Attorneys General

This post deals with another data breach, yes, hackers were able to compromise the organization’s systems and exfiltrate personal information relating to over 45,000 Pennsylvania and Ohio residents. However, there are several...more

Top Ten for 2023 – Happy Data Privacy Day!

To celebrate Data Privacy Day, we present our top ten data privacy and cybersecurity predictions for 2023. 1. Healthcare and Medical Data Security and Tracking- The healthcare industry has been facing increased scrutiny...more

Getting Healthcare in 2023 and Beyond…Virtually…and Securely

Much is being written about “remote work” – is it productive, will demand for it continue or be curtailed in a recession, is cybersecurity compromised, does it inhibit workplace culture, collaboration, etc. Lots of questions,...more

2023 New Year’s Resolution: Don’t Get “Whacked” By A State AG for Cybersecurity Compliance

It usually happens after a reported data breach. The organization experiencing the breach sends notifications to affected individuals, as well as federal and or state agencies where appropriate and perhaps other parties. Not...more

Nevada Gaming Commission Adopts Cybersecurity Regulations

On December 22, 2022, the Nevada Gaming Commission (NGC) adopted regulations creating new cybersecurity requirements for certain gaming operators. This action joins agencies in other jurisdictions moving quickly to protect...more

OCR Reminds Healthcare Providers and Their Business Associates – You Need an Incident Response Plan!

We have been quite busy this October, which happens to be National Cybersecurity Awareness Month. But, we did not want to let the month go by without some recognition; and we are grateful to the HHS Office for Civil Rights...more

New York State Bar Adds Cybersecurity, Privacy, and Data Protection as New CLE Category

On August 17, 2022, New York announced an amendment to the Continuing Legal Education (CLE) Program Rules, which adds a requirement for attorneys to complete at least one CLE credit hour in Cybersecurity, Privacy, and Data...more

North Carolina Prohibits Public Sector Entities from Paying Ransom in a Ransomware Cyberattack

Organizations attacked with ransomware have a bevy of decisions to make, very quickly! One of those decisions is whether to pay the ransom. Earlier this year, I had the honor of contributing to a two-part series, entitled...more

Indiana Tightens the State’s Deadline for Providing Notification of a Data Breach

States continue to tinker with their breach notification laws. The latest modification to the Indiana statute relates to the timing of notification. On March 18, 2022, Indiana Governor Eric Holcomb, signed HB 1351 which...more

Construction Industry: Data Security Considerations

No industry is immune to privacy and cybersecurity risks, and the construction industry is no exception. Those in the construction industry can protect against a potential cyberattack by understanding the risks and...more

Cyber Incident, Ransom Payment Reporting to DHS Mandatory for Critical Infrastructure Entities

Included within the Consolidated Appropriations Act, 2022, signed by President Joe Biden on March 15, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Act) creates new data breach reporting requirements....more

Do Employers Need a CISO for ERISA Compliance?

According to a recent survey, about 45% of companies do not have a Chief Information Security Officer (CISO). As West Monroe’s “The Importance of a CISO” observes, it would be terrific for all organizations to have a CISO,...more

Massachusetts Privacy Bill Provides WISP Reminder, Safe Harbor for Punitive Damages

When Massachusetts issued its data security regulations in 2009 (Regulations), it led the way for states on data security. The Regulations became effective 12 years ago, almost to the day, March 1, 2010. The Bay State is now...more

SEC to Advisors and Funds – Adopt and Implement Cybersecurity Policies and Procedures

On February 9, the Securities and Exchange Commission (“SEC”) voted to propose rule 206(4)-9 under the Advisers Act and 38a-2 under the Investment Company Act (collectively, “Proposed Rule”). In general, the Proposed Rule...more

184 Results
 / 
View per page
Page: of 8

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide