Companies must be prepared for a data breach. It is just a fact of life, plain and simple. The developing standard of care requires that companies give some thought to how they will respond when the inevitable occurs — and they really, really, really should have a written Incident Response Plan in place. This is part …
Author Archives: Shawn E. Tuma
12 Timeless Password Tips for Improved Security
Excellent advice from my friend Allan Pratt:
Cybersecurity & Data Breach: You Don’t Drown From Falling Into the Water
“You don’t drown from falling into the water, you drown from not getting out.” Think about that — and think about how that applies to cyber security and data breach issues facing companies in today’s cyber world. Here, in my first ever video blog post, I explain this issue with more detail.
Kevin O’Keefe Interviews Shawn Tuma About Blogging at State Bar of Texas 2015 Annual Meeting
I had the wonderful opportunity to visit with and get to know Kevin O’Keefe (@kevinokeefe) at the State Bar of Texas 2015 Annual Meeting in San Antonio. Kevin is the Founder and CEO of LexBlog, the preeminent source for legal blogging (where I plan to head, one day). Kevin and I both did presentations during …
Cyber Trial Lawyer Lesson: Stick With the Chronological Story
There is a well-known rule among experienced trial lawyers: when presenting your case, you always tell your story of the case in a chronological order unless there is an exceptional reason not to. The problem is, for most of us, the deeper we get into a case and the further into the weeds we get, …
Continue reading “Cyber Trial Lawyer Lesson: Stick With the Chronological Story”
Businesses Beware: You need to understand and adopt EMV / Chip-and-PIN Technology
“Visa, MasterCard, Discover, American Express and their banking partners have set a government-enforced deadline of Oct. 15 for a “liability shift” that, for the first time, would make merchants liable for fraudulent charges that result from using point-of-service readers that can’t read chip-and-pin EMV cards. The issuers have been implementing the technology, but it’s still …
Continue reading “Businesses Beware: You need to understand and adopt EMV / Chip-and-PIN Technology”
What is ‘cybersecurity law’? Orin Kerr’s 4 Categories
Regular readers know I have a tremendous amount of respect for Orin Kerr as a — if not the — true scholar on cyber law issues. Kerr recently wrote an article in which he explained his view of cybersecurity law and broke it down into four distinct categories: The law governing steps that potential or …
Continue reading “What is ‘cybersecurity law’? Orin Kerr’s 4 Categories”
Presentation tomorrow – Collin County Bar Ass’n Corporate Counsel Section – here’s the question:
“What do I talk about?” No, it’s not that I don’t have anything to say — for goodness sakes, you all know that I always have something to say! The problem I am having is that I had planned to talk about cyber risk compliance and the key elements of what a good cyber risk …
UPDATE: “This is not a security breach.” Really? IRS hit by cyberattack, thousands of taxpayers’ information stolen
UPDATE: We now think we know a little more about this: Russian hackers are believed to have been behind it (CNN Story); Tax return information of more than 100,000 taxpayers was stolen; The information was used to obtain $50 million in fraudulent tax refunds; The taxpayers whose information was stolen will be offered free credit …
Really??? Proposed legislation would allow companies to keep some data breaches secret
Let me make sure I have this right … the same company officials who are currently being warned about cyber risk but are not finding it significant enough to act are going to be the ones who determine whether there is a reasonable chance that customers will be harmed — from their data breach — …

You must be logged in to post a comment.