Explaining Third Party Cyber Risk and the Role of Contracts to Business Lawyers

This morning I am in Austin, TX about to speak to a room full of business lawyers about the importance of understanding and managing third party cyber risk and the role that contracts have in this process. I recognize that they are not aspiring to be cyber or privacy lawyers and have plenty to keep …

Healthcare Providers – Are You Prepared for Hackers to Tell Your Patients About Your Ransomware and Data Breach?

If you are a healthcare provider, you need to prepare yourself now for the new reality that, when hackers get into your network, they will contact your patients to put pressure on you to pay their ransom demands — usually after they have encrypted your network. Here is an example from a recent case that …

Is #ShameHacking Coming Next? Hackers Breach Search Engine for Japanese Sex Hotels

Life is short - it is shorter when hackers tell your spouse Shame hacking -- the use, or threatened use, of purportedly hacked data for embarrassing or extorting people by threatening to expose such compromising data if they do not comply with the demands made of them -- is a thing. A search engine for …

2 Decades Later: Cyber Risk Isn’t Y2K–It Is An Unsolved Risk That You Must Take Seriously

12/31/19 Two decades ago to the day, I sat right here in my home study and thought about how my career as a cyber incident responder was surely about to blast off. Though I had only been licensed to practice law for under two months, I just knew this subject matter was it -- my …

Ransomware + Publicize Victim Companies + Expose Stolen Data = Bad Cyber Extortion Trifecta

Cybercriminals are using a bad cyber extortion trifecta of (1) using ransomware to encrypt victim companies' data, (2) publicizing the names of those companies that don't pay up, and (3) then exposing the data they stole from the companies. This is bad stuff and companies had better be ready to protect themselves. Read more: Ransomware …

Why is the FBI Warning About Smart TVs?

Why is the FBI warning about smart TV cybersecurity? Because a smart TV is a computer -- it is just built into a really large monitor -- and it should be secured like a computer because hackers can hack it just like any other computer. (See FBI Warning)Listen to Shawn Tuma discuss this issue on …

Sharing the Load: What are Chief Privacy Officers, Chief Information Security Officers, and General Counsel Doing in Real Life to Divide Up Roles and Responsibilities? (conference panel discussion)

Business leaders are beginning to understand that cyber is not just an IT issue, a legal issue, or any other silo-ed issue, but that it is an overall business risk issue and that makes managing cyber risk a team sport. This week I had the privilege of moderating a panel discussion that was titled "Sharing …

Making Sure It’s Covered: Cyber Insurance — What are the Practical Things In-House and Outside Attorneys Need to Know? (conference panel discussion)

Cyber insurance is a hot topic among many but unfortunately, far too many companies are not getting any cyber coverage or are not getting the coverage they need for their risks. This week I had the privilege of moderating a panel discussion targeted for in-house counsel that was titled "Making Sure It's Covered: Cyber Insurance …

Was the ransomware attack on 20+ Texas local governments an attack on a single service provider? [UPDATE: YES!]

The Texas local governments attack seems to me to be more akin to the trend we have been seeing in 2019 with attackers targeting one MSP and then using that access and the MSP’s tools to attack / encrypt the MSP’s individual clients. If I’m not mistaken (and, I could be), the Texas DIR often …

***URGENT*** MEMO TO: “THE IT GUY” RE: #RANSOMWARE / WIPING DATA

***URGENT MEMORANDUM*** TO: "The IT Guy" FROM: Your clients' Incident Response Coach SUBJECT: Your clients affected by ransomware STOP OVERWRITING / WIPING / DELETING OR OTHERWISE DESTROYING YOUR CLIENTS' DATA WHEN THEY ARE AFFECTED BY RANSOMWARE!!! PLEASE!!! PRETTY PLEASE!!! PRETTY PLEASE WITH SUGAR ON TOP!!! JUST STOP IT!!! Seriously, everyone understands that ransomware is scary …