Will Officers & Directors Be Held Legally Responsible for Companies’ Data Breaches and Cybersecurity Incidents?

Will Officers and Directors be held legally responsible for their companies’ data breaches and cybersecurity incidents? That is the question I addressed in Cybersecurity Risk: Law and Trends – A Director’s Duties Must Evolve With The Company’s, which was recently published in the Spring 2015 issue of Ethical Boardroom (see article below). The article is short …

A Few Thoughts on the Consumer Litigation Settlement in the Target Data Breach Case

Many thanks to CSO Online and Michael Santarcangelo (@catalyst) for his excellent synopsis of our conversation regarding the recent settlement of the Consumer Litigation in the Target data breach lawsuit (note, the more substantive Financial Institutions Litigation has not settled). Please give the full article a read and also give a shout-out to Michael on his Twitter …

Cyber Law is (the new) Practical Business Law

I have had a thing for simplicity lately. A couple of months ago I was on stage speaking and something really hit me. I was watching the audience and the looks on their faces made me realize that, while what I was saying was technically accurate, to most of the people in the crowd, it …

Practical ways your company’s contracts can help improve its cybersecurity odds

I am sharing two articles with you because, as you well know, cybersecurity is a really hot topic right now due to the threat it poses to virtually all businesses. I hope you find these helpful.   I was recently interviewed by CSO Magazine and asked to give one suggestion that companies could do to …

Low Hanging Fruit Can Make a Pretty Good Cybersecurity Pie

“Cybersecurity” just sounds like something that must be really complicated, right? Sure it does — it sounds exotic and cool — and complicated. And yes, when you get into the weeds of technical things that hackers (actually, crackers) do to monkey around with computers, it can be mind-boggling. But, must you really understand all of …

New Podcast: #DtSR Episode 130 – Where Law and Cyber Collide

I really appreciate the #DtSR Gang [Rafal Los (@Wh1t3Rabbit), James Jardine (@JardineSoftware), and Michael Santarcangelo (@Catalyst)] inviting me to tag along for another episode of the Down the Security Rabbit Hole podcast. In this episode we discuss the following: Traveler’s Insurance files suit against a web development company for failing to provide adequate security, resulting …

Executives & Board: The conversation security leaders need to have about Amy Pascal’s departure

This is an excellent article that covers a very important topic you need to consider. You — as in Executives and Board Members of Companies all around the world. Stop, close your eyes, and ask yourself these three questions that are in this article: “What did you think of the announcement?” (i.e., put yourself in …

Will Changes to the CFAA Deter Hackers? | Norse DarkMatters

Read my latest post on Norse’s DarkMatters: Will Changes to the CFAA Deter Hackers?  

7 Ideas for Security Leaders – What Do You Think About My Suggestion?

Many thanks to CSO Online and Michael Santarcangelo (@catalyst) for including my suggestion as one of 7 inspiring ideas for small changes that lead to big improvements in both security posture and leadership within organizations. The article is 7 Ideas for security leaders. Here is a teaser from my suggestion on slide 5 but please go check out …

Happy Data Privacy Day!

What are you doing to observe it? Today is Data Privacy Day! If you have been wondering “what is Data Privacy Day?” then this is your lucky day because not only is today Data Privacy Day, but here is the answer and an explanation for why it really matters to you and your company’s future …