Podcast: CFAA, Shellshock and Cyber Security Research — What the Heck Do We Want?

Today I had a blast doing a podcast on the CFAA, Shellshock, and cyber security research with Rafal Los (@Wh1t3Rabbit), James Jardine (@JardineSoftware), and Michael Santarcangelo (@Catalyst) — in fact, we had so much fun that I suspect Raf had quite a time trying to edit it! The starting point for our discussion was a recent article …

Uncle Sam doesn’t have a clue on data privacy, cyber crime laws, and neither do we!

The point of the article that is the source of the quote below is exactly right: there is no consistency, cohesiveness, or harmony with the cyber crime and data privacy laws. I believe there are several reasons but these are the two that are most prominent: The cyber crime and data privacy laws are a patchwork collection …

Data Breach Judgment: Will Home Depot Be the One to “Get It”?

Will Home Depot be the one that’s “gonna get it”? Based upon the information we are learning, it could be. Way back in 2011 I wrote Data Breach — Who’s Gonna Get it? and it scared people. For good reason. In that piece I wrote of how one day, in the future, a company would come along that …

3 Steps the C-Suite Can Take to Strengthen Cyber Security

The C-Suite is ultimately responsible for failures of a company’s cyber security. A recent example of this is how Target’s CEO, CTO, and several Board Members were pushed out in the wake of its data breach. SEE BELOW FOR EVENT REGISTRATION! This puts leaders in a difficult position. It is almost a statistical certainty that …

Does Data Security Have Your Healthcare Practice “On the Hook”?

I recently had the pleasure of presenting in a webinar series titled Is Your Practice “On the Hook?” to members of the Texas Dental Association and the Oklahoma Dental Association. Key points of the presentation, which focused on cyber security and data breaches in the healthcare industry, explained why protected health information (PHI) and electronic healthcare …

Yes, an Employee Really Can Steal Your Data and Then SLAPP You for It?

Yes, in California it just happened!The fact that this happened in California should be of no comfort to Texas businesses, however, because the Texas Anti-SLAPP law comes from California and, therefore, California jurisprudence is considered persuasive authority in Texas. This means that in the not so distant future Texas employees could steal their employers’ data and …

Supreme Court: Private Information Is Worthy of Protection, Even on Cell Phones

In Riley v. California the Supreme Court made it clear that people’s private information is worthy of protection, even on their cell phones, in holding that cell phones are generally protected from searches without a warrant.  The Supreme Court ruled Wednesday that police cannot go snooping through people’s cell phones without a warrant, in a unanimous …

3 Important Questions the State Attorneys General Will Ask Your Company Following A Data Breach

In an earlier blog post I wrote about how [w]hen your company has a data breach, these are the top 3 questions that you will be required to answer: How did the breach happen? What steps did your company take before the breach to protect the data and keep it from happening? What steps is …

Two Step Data Breach Risk Test for Texas Businesses

Does your business have this digital information about other people? 1. last name + first name or first initial + social security number, driver’s license number, or other government issued identification, or account or card numbers + access codes, or 2. information that identifies an individual + concerns a health condition or healthcare  If you answered …

Why do cyber criminals want your healthcare data?

During a recent presentation a member of the audience asked me why cyber criminals would want to steal a person’s healthcare data. It is easy to understand why they would want to steal payment card data — but healthcare data — not so obvious. Here is a great answer: A crook would love [healthcare data] because, “in the world …