Gov’t Contractors Must Notify of Data Breach Within 3 days

If your business is a contractor for the federal government, you had better have your data breach response ducks in a row. The moment you detect a breach, the clock starts ticking and you have only 3 days to notify of the breach. Yes, I said 3 days! You better already know who your legal counsel …

Hackers’ Cracked 10 Financial Firms in Major Assault – Russian Officials Involved?

There is nothing new about cyber attacks coming from Russia, however, to actually be able to tie them to Russian government officials — albeit loosely — would be another step. Is this a hunch or do they have something more? Related: US Indicts Chinese Army Officers for Hacking US Companies The huge cyberattack on JPMorgan Chase that …

Podcast: CFAA, Shellshock and Cyber Security Research — What the Heck Do We Want?

Today I had a blast doing a podcast on the CFAA, Shellshock, and cyber security research with Rafal Los (@Wh1t3Rabbit), James Jardine (@JardineSoftware), and Michael Santarcangelo (@Catalyst) — in fact, we had so much fun that I suspect Raf had quite a time trying to edit it! The starting point for our discussion was a recent article …

Possible Privacy Violations From New Corvettes Show Need For Legal Team to Include Privacy Experts

Doing business in the modern world’s regulatory environment is challenging. The number of rules and regulations that apply to almost every industry are so voluminous that no one person can know them all. That is why you need a team. A team of experts where each stays up to date on the current laws within their …

No, the CFAA Does Not Require Taking Actions to Prevent the Hacking of Others

For all of the things the CFAA may (or may not) require, it does not require taking actions to prevent the hacking of others. We are not (yet) the guardians of the hacking universe! In a factually interesting case that offers a great read on attorney professionalism, the United States Court of Appeals for the Seventh …

Uncle Sam doesn’t have a clue on data privacy, cyber crime laws, and neither do we!

The point of the article that is the source of the quote below is exactly right: there is no consistency, cohesiveness, or harmony with the cyber crime and data privacy laws. I believe there are several reasons but these are the two that are most prominent: The cyber crime and data privacy laws are a patchwork collection …

Data Breach Judgment: Will Home Depot Be the One to “Get It”?

Will Home Depot be the one that’s “gonna get it”? Based upon the information we are learning, it could be. Way back in 2011 I wrote Data Breach — Who’s Gonna Get it? and it scared people. For good reason. In that piece I wrote of how one day, in the future, a company would come along that …

3 Steps the C-Suite Can Take to Strengthen Cyber Security

The C-Suite is ultimately responsible for failures of a company’s cyber security. A recent example of this is how Target’s CEO, CTO, and several Board Members were pushed out in the wake of its data breach. SEE BELOW FOR EVENT REGISTRATION! This puts leaders in a difficult position. It is almost a statistical certainty that …

Does Data Security Have Your Healthcare Practice “On the Hook”?

I recently had the pleasure of presenting in a webinar series titled Is Your Practice “On the Hook?” to members of the Texas Dental Association and the Oklahoma Dental Association. Key points of the presentation, which focused on cyber security and data breaches in the healthcare industry, explained why protected health information (PHI) and electronic healthcare …

Expect the Celebrity Nude Photo Hacker to be Prosecuted Under CFAA–Just Like Revenge-Porn King Hunter Moore

How will the “hacker” who stole celebrity nude photos be prosecuted? Hacking is nothing new, scores of American businesses face it everyday. People could care less unless it is their own data that has been breached. But, when celebrities are involved — and nude photos of celebrities at that — it is a much different story.Now …