Shawn E. Tuma

Posts Tagged ‘Data breach’

Cybersecurity Legal Issues: What You Really Need to Know (slides)

In Data Breach, Cybersecurity Law, Privacy, Corporate Governance, Cyber Issues on September 27, 2016 at 10:23 pm

Shawn Tuma delivered the presentation Cybersecurity Legal Issues: What You Really Need to Know at SecureWorld Expo Dallas on September 27, 2016. The following are the slides from Tuma’s presentation.

The opening Keynote speaker for the event was Dr. Larry Ponemon of the Ponemon Institute. Dr. Ponemon delivered a fabulous talk on the insider threat within organizations. Here are some pictures from day 1 of SecureWorld Expo Dallas.

_____________________

Shawn Tuma (@shawnetuma) is a business lawyer with an internationally recognized reputation in cybersecurity, computer fraud, and data privacy law. He is a Cybersecurity & Data Privacy Partner at Scheef & Stone, LLP, a full-service commercial law firm in Texas that represents businesses of all sizes throughout the United States and, through its Mackrell International network, around the world.

Yahoo Data Breach: US Senators Demand Answers – Still Think You Don’t Have to Disclose and Notify?

In Computer Fraud and Abuse Act, Cybersecurity Law, Data Breach, Privacy on September 27, 2016 at 6:45 pm

There is a grave and unfortunate misperception among many business leaders who believe that when their company has had a data breach, going through a response and notification of affected individuals is optional. To the educated readers of this blog, this sounds shocking. Sadly, it is something I see on a regular basis. What is worse is that there are far too many lawyers who do not practice in this area but, out of ignorance, advise such clients that it is really not as big of a deal as we are making out of it and that they can just ignore it.  Read the rest of this entry »

Data Breach Litigation: Who’s Gonna Get It? Will it be Yahoo! (or Verizon)?

In Cybersecurity Law, Data Breach on September 25, 2016 at 7:41 pm

ford-pintoBelow is a post that I wrote in 2011, back when we thought we were in the middle of the “Year of the Data Breach.” We weren’t — not even close. Yesterday I read an article referencing the Ford Pinto and the infamous cost-benefit analysis memo that led to the jury sending “the message” to Ford so I thought of re-sharing my golden oldie.

Now, here is the interesting part. Yahoo! has been in the final states of a deal to sell itself to Verizon for $4.8 billion and, if this were to happen, that means that Verizon would be inheriting the fallout from the massive Yahoo! 500,000,000 record data breach. So, it may not be Yahoo! that gets it — it may be Verizon so let’s see how this all plays out and whether the purchase price stays at or above $4.8 billion.

Here is my old post: Data Breach – Who’s Gonna Get It? Read the rest of this entry »

Video: What to do if you have a Yahoo account (Tuma on WFMJ News)

In Data Breach, Media on September 24, 2016 at 6:55 am

Video interview: Shawn Tuma discusses what to do if you believe your Yahoo account has been compromised – WFMJ NBC News, Youngstown-Warren, Ohio

Full news article: What to do if you believe your Yahoo account has been compromise – WFMJ.com News weather sports for Youngstown-Warren Ohio

______________________

Shawn Tuma (@shawnetuma) is a business lawyer with an internationally recognized reputation in cybersecurity, computer fraud and data privacy law. He is a Cybersecurity & Data Privacy Partner at Scheef & Stone, LLP, a full-service commercial law firm in Texas that represents businesses of all sizes throughout the United States and, through its Mackrell International network, around the world.

Yahoo Data Breach – Some Facts & Questions (i.e., was it really the Russians?)

In Cyber Issues, Cybersecurity Law, Media, Privacy on September 23, 2016 at 6:00 am

hacked-1The Basic Facts

Yahoo announced that it had a data breach in late 2014 and 500 million users’ account information was stolen. The account information may include names, email addresses, telephone numbers, date of birth, passwords (most encrypted with bcrypt, but apparently not all), security questions, and security question answers.

People who have Yahoo-based services should immediately change their passwords, change their security questions and answers, not use the same password on multiple accounts, and implement dual factor authentication where available.

The Message in the Message

In its notification message, Yahoo subtly invokes the “it’s not our fault, we were the victim of a state-sponsored actor attacking us” defense. I do not blame Yahoo, it works. It uses the words “state-sponsored actor” twice in the first paragraph and twice in the fourth paragraph: Read the rest of this entry »

%d bloggers like this: