Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts

Monday, January 28, 2019

How Much Do Cyber-criminals Make with Your Personal Data?


How Much Do Cyber-criminals Make with Your Personal Data? 
Security Magazine
According to a study from the Kapersky Lab, a global cybersecurity company, criminals can sell an individual’s complete digital life for less than $50.  The market for a single breached account is even lower.  You’ll be surprised to learn the various ways criminals are stealing and selling a person’s complete digital life on the dark web.

Monday, May 19, 2014

What If? What Then? Managing your Business Reputation in Today's Age of Social Media.


Social Media: 
Reputation Management for YOUR Business


What If? What Then?  
Managing your Business Reputation in Today's Age of Social Media 
 
How do employers monitor and enforce social media policies in and out of the workplace? Protecting trade secrets, maintaining data integrity and customer satisfaction are some of the key objectives of the standard business. One "Like" or "Retweet" is all it takes to damage the reputation of your business. Accessibility to Social Media is almost universal.

 Join the Tech/Ed Committee for a unique and timely panel discussion on Social Media in the Workplace. Learn from a team of experts how to effectively handle a Social Media fiasco and steps to take to ensure your organization's covered.

Thursday, May 22nd
7:30 - 10:00 a.m.
Princeton HealthCare Community Room at the Hamilton Area YMCA

   
Discussion topics:
1. Social Media Policy Implementation
2. Acceptable/Unacceptable Behaviors
3. Disciplinary Actions
4. Repairing Relationships with Customers
5. Legal Ramifications

Panelists include:
Michael DeCamillis
Dolvin Consulting
IT Specialist
Gene Underwood
Bluest Sky LLC
Marketing Professional
Dolores Kelley, Esq.
Stark & Stark
Legal Expert
Jennifer Gardella
Your Social Media Hour
Human Resources Professional

Early registration is recommended. Light Breakfast will be provided.

Do you have an old, unwanted PC or Laptop? Donate it to the 2014 Trenton Digital Initiative and Receive a Waived Entrance Fee. 
Contact Jeff Richardson for more information (609) 689-9960 x16.

Monday, October 21, 2013

Hot, Warm and Cold

Hot, Warm and Cold ERP (Enterprise Resource Planning) responses.

What constitutes the need for an emergency response?  A system failure can range from an inconvenience to a failed business.  Length of down time and the amount of data loss will typically factor heavily in the business impact.

 


In planning for disaster, roles must be defined in conjunction with the recovery procedures.  Who will be in charge, who will determine the impact, which person will be responsible for status updates?  Has the notification chain been created and tested?

 

The Hot zone is where the incident occurred.  In an online, virtual world this may not be your place of business.  Disasters can occur to cloud or hosted providers as well.  Up time and available time are two separate categories of availability.  In cases of natural disaster does the affected operation have a disaster recovery site geographically separated from business operations and the point of failure or disaster?  Have key personnel been identified and do they have access to the alternate site?

 

The Warm zone is a transitional area between Hot and Cold sites.  This may be a physical area or virtual area.  It may be the same location in cases where there is a system down, but no physical damage.  In cases of natural disaster is often a safe place near the disaster where status can be checked, yet far enough away to not be in harm’s way. 

 

The Cold zone is either a neutral area or the remote area where responsible people can delegate recovery tasks and notify users, customers, suppliers when necessary of status updates.  This is where press releases can be issued, personnel and resources coordinated and delegated.

 

Priorities varry depending on the extent of the disaster.  In cases of physical or natural disasters first priorities should be to the health and well being of personnel, then protection and recovery of resources.  In cases consisting of physical or operational equipment failures these steps are typically not necessary.  The next priorities are to assess the problem, determine its impact and to estimate recovery times for partial and full recovery.

 

First thoughts.  What is/was the hazard, disaster or affected resource?  Have the responsible people been notified?  What resources are at risk, what resources are likely to become at risk?  What is being done to contain the risk?  Who is coordinating the emergency response?  Are there others that need to be notified? 

 

Support functions.  What resources can be notified to provide support and recovery? Are emergency response personnel to be notified?  How and which communications methods can be used to notify employees, customers and suppliers?  Who and how are facility and equipment repair and remediation personnel notified?  What other resources can be contacted for immediate or future response?

 

Public relations.  Does the disaster or incident require a public relations media expertise to notify the affected parties and mitigate the loss of reputation?

 

There are many aspects to any critical interruption in service.  There are many ways to prepare.  The point to first consider is if your organization has acknowledged the possibility and has consulted with others to create a recovery and continuity plan. 

 

Businesses come in all shapes and sizes as due risks.

 

1.       What are you doing now to prepare? 

2.       What can you do now to prepare? 

3.       What will you do to prepare? 

 

We would like to hear your thoughts.   Please share your comments in this blog.  We would love to hear your feedback.

 

Friday, January 20, 2012

Zappos customer data accessed in security breach

Zappos is apparently one of the latest data breach victims.  Or, perhaps their customers are the latest victims.  Zappos feels that that the information was limited in scope, because the entire credit card number was not exposed (that is what they believe).  Many data thieves compile information from many sources to build complete profiles on people.  It just takes some patience and time to put together information that can be sold to the highest bidder.  It is a volume business and the 24 million customers are just bigger targets now.



You may read the CNET article by clicking this link:


There is no perfect solution, the mice get smarter and the traps more complex, but in time unless there is a proactive approach, “they” will get in and the damage will be done.

Here is the big message in the article and it applies to everyone, not just Zappos:

"We've spent over 12 years building our reputation, brand, and trust with our customers. It's painful to see us take so many steps back due to a single incident" Hsieh wrote in the letter.

An organization builds their reputation one satisfied customer at a time.  It takes years of effort to ensure your customers are happy.  It is evidenced by the referrals you get.  Then, in an instant your well earned reputation is gone. 

The data breach notification is the tip of the ice berg.  The piracy may have actually been going on for a time and the breach turns on the lights.  Other times it may be a single event.  As far as your customer cares, it puts them in jeopardy.  The only thing slightly in your favor is that people not directly affected are becoming numb to these news stories.  Never thinking it would happen to them, until it does and your company gets the blame and loss of business.

The bad publicity comes. The regulators come.  The forensic people come.  The remediation comes.  Then you try to rebuild your business. 

What comes after an event like this is what should have been in place in the first place.  A Written Information Security Program (WISP) plan.  You may think of a WISP plan in these simple terms.  It is a fire drill for a data breach.  You plan, practice, and protect hoping that you will never use what you have learned, but in the case when it is needed, it saves your life. 

A WISP plan is not a static document that sits on a shelf collecting dust.  That is what makes it different and what satisfies and creates a defensible position with the regulators.  A WISP plan involves a risk analysis of your organization and appropriate, best practice, measures are implemented.  It is different and scales for each organization.  Every company has some exposure, some more than others.

No one can promise you anything, not even us, but you should contact Dolvin Consulting to determine your Risk Quotient.  You cannot hide your head in the sand.  It is your responsibility to find out what you can to protect yourself and your customers, supplier, and employees.  Contact us today to see how we can help you mitigate the risks associated with the private information you are responsible for.



Friday, December 23, 2011

Santa Claus’ Workshop, Naughty/Nice List Databases Hacked

Proprietary Data and PII of Billions Exposed.  The Grinch, Disgruntled Elves, Anonymous Lead List of Suspects in Data Theft.





Well... just imagine it was your company that was breached.  Santa probably has a healthy bank account and can weather the storm of bad publicity.  After all if his organization fails, there is always mom and dad to do the shopping and delivery.  It is not like there is a lot of competition.  Where else are kids going to write at holiday time?

Maybe you do not consider your information all that valuable.  Perhaps your company has no proprietary information.  Is there employee information?  What about customer credit information?

What happens to your business’ reputation? 

It is hard enough finding a business, partner or supplier that you trust in the first place.  As a business, how hard is it to keep your customer’s happy?  What effect would a data breach have on your existing relationships?

It is very difficult to calculate the costs of a data breach on a business.  At least one that survives and does file for bankruptcy to protect itself.  The finance team can add up the fines, the cost of auditors and regulators, the pots of coffee consumed during the investigation, but what about the loss of reputation?

There is no perfect solution.  The criminals keep getting smarter and the mouse traps more sophisticated.  What you can do is prepare.  That is the role of a Written Information Security Program (WISP) plan.  It creates a defensible position with regulators. It is like a fire drill for data breaches.

Many companies provide technology solutions, but few provide a solution that will be approved by regulators.  Dolvin Consulting and Cyber Security Auditors and Administrators (CSA2) work with your team to prepare, create and maintain a working WISP plan.  A plan that is reviewed, tested, and updated each year.  A plan that will help mitigate the risks and let you sleep at night.

The ball is in your court.  Contact us today to see how we can help become compliant.  Do not let what happened to Santa happen to you.

Friday, December 9, 2011

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised | AIS Health

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised AIS Health

This is a well written article.  It identifies an ongoing issue that all organizations, not just those in healthcare struggle with on a daily basis.  How do we empower our employees, yet maintain control over social media to protect the private information for which we are responsible?



I support the premise of policies for employees as many do not take the time to think beyond the moment to consider the consequences of their actions.  Many postings as the article points out are innocently placed.  Most people do not realize that enterprising people can take these separate pieces of information and place them together.  In the wrong hands that information is sold to the highest bidder.

The article points out: “There are people who have grown up having everything posted on Facebook, and having no privacy,” Drummond says. “They are posting more” with little thought to the potential impact.

The solution is not to single out any specific social media forum, but rather to invest in education for all workers.  Many simply are ignorant of the consequences.  At the organizational level, the education becomes part of a Written Information Security Program (WISP) plan.

Think of a WISP plan as a fire drill for a data breaches.  It is not a static, shelf sitting, and dust collecting binder.  A working WISP plan is reviewed annually or at any change in business or organizational process.  A WISP plan provides the foundation for a secure environment.  There is no one perfect solution.  Any plan that incorporates humans has the potential to break down.  In the event of a breach, there are well documented procedures that will mitigate damages and help create a defensible position for the regulators that are sure to be involved.

Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help companies of all sizes manage the risk associated with private information.  Those companies are typically concerned with the threat of lawsuits related to the loss of personal information as well as the loss of their customer base due to the degradation of their reputation.

We cannot promise you that you will never have any problems, but we will do our best to understand your challenges and help you create a working WISP plan that matches your risk quotient.   Contact us today to see how we can help you manage your risk.


Friday, November 18, 2011

HIPPA Audits and Compliance

Alan Heyman, Managing Director of Cyber Security Auditors & Administrators LLC (CSA2) was contacted and quoted recently, because of his expertise in working with companies to help them determine their risk quotient. 

Automating HIPAA Compliance Tracking and Audit Preparation

The article is a quick read, but reading between the lines may take a bit longer.  Alan is of course talking about a Written Information Security Program (WISP) plan and a WISP-Vault which is a highly secured storage facility to keep the plan safe. 




There has never been a perfect mouse trap and the mice keep getting smarter.  You cannot engineer a perfectly secure environment when humans are involved.  A WISP plan is more than a fancy binder filled with out-of-date information sitting on a shelf in someone’s office collecting dust.  It is a process, not an event.  A real WISP plan is a living breathing environment which is kept up to date with the changes in your business.

Think of a WISP plan as a fire drill for data breaches.  You plan, prepare, and practice over and over so that in the case there is a data breach everyone stays calm and you implement the right corrective action in a timely manner.

You cannot keep the auditors away, but you can be prepared.  A working WISP plan creates a defensible position that will protect you and your business.  The preventative medicine might taste a little bitter, but is a lot less painful than cure.  You know the saying Ben Franklin made famous: “An ounce of prevention is worth a pound of cure”.  Ben made this observation long before there were computers or HIPPA concerns.

Every business has its own risk assessment and the solution is based on potential exposure.  You would prepare your home if you knew a storm was coming, so why not do the same with your business.  Start now by contacting us to see how we can help. 

Dolvin Consulting works with organizations that are worried about lawsuits related to the theft of personal information and are concerned about the loss of customers related to a data breach.

Friday, November 11, 2011

HIPPA Enforcement Promotes Compliance

Leon Rodriguez, the new director of the Department of Health and Human Services' Office for Civil Rights, describes his HIPAA enforcement agenda.


"As I've learned as a prosecutor and then as a defense lawyer, enforcement promotes compliance," Rodriguez says in an interview with HealthcareInfoSecurity's Howard Anderson. "The fact that covered entities out there know that they are at risk for penalties is something that, in fact, in many cases will promote compliance."


The full article can be found by clicking here.  Some excerpts are below. 


ANDERSON: In recent months, as you just alluded to, the Office for Civil Rights has significantly ramped up its HIPAA enforcement efforts.  Under your leadership can we expect to see your office announce more resolution agreements in civil monetary penalties and other enforcement actions?
RODRIGUEZ: I think you can expect that; absolutely you can expect that.

ANDERSON: The Office for Civil Rights recently hired KPMG to launch a HIPAA audit program. What would you like to see that program achieve, and is it possible that any of those audits will result in sanctions or penalties?
RODRIGUEZ: This is the first time we're doing it, so the first thing ... is for us to 'go to school' on how best we will run an audit program. In part, this is what you might call a pilot. We're going to look at it and learn: How do we use an audit program? How does an audit program best advance our enforcement goals?

The second purpose, and this is really different than enforcement, is to promote compliance among the covered entities that are subject to the audit.  Our first objective is not to go out there and start banging [organizations] with penalties; it's really to take a good look at them, find out where their opportunities for improvement are and help them improve.  Having said that, I think we know that there are cases where we're going to find some significant vulnerabilities and weaknesses.  And in those cases, we may be pursuing significant corrective action.  And in some of those cases, we may be actually pursuing civil monetary penalties.  But that's really not the primary goal of the audit program.



Rodriguez’s goal is to audit and learn, but even then he acknowledges they will pursue significant corrective action.  You can interpret the interview in several ways and they may all be correct to some extent.  What I suggest you walk away with is that the casual compliance days are over.  If you are found at-fault for a data breach, you will be subject to fines and other penalties.

In a post breach situation, there is no moderator.  Your organization will be held accountable.  Your client base will lose confidence in your operations and unless you are the only one performing that service, your clients will go elsewhere.  The publicity of the lawsuits will ensure a degradation of reputation and client base.

The only real course of action is to address your Risk Quotient in a pre breach environment.  Your organization will have the luxury of being able to take the time to plan and prevent data loss.  Preparation is like a fire drill for data security.  Plan and practice in the hopes you never need to use what you know.  But, if you do, then you will know what to do and when and the result will be a defensible position for the regulators.

Dolvin Consulting works with Cyber Security Auditors & Administrators (CSA2) and your organization to prepare, plan and implement a Written Information Security Program (WISP) plan.  The WISP plan is your key to sleeping well at night.  Contact us today to start a conversation that will help you connect with resources that can help with your compliance challenges.


Friday, October 28, 2011

Encryption 101


For many people, the word "encryption" invokes images of spies, clandestine operations and World War II code breakers feverishly working to decipher enemy messages. Actually, encryption is a priceless security tool that any business can easily use to keep sensitive information confidential and safe from prying eyes.



This article from IT Security highlights some important information about encryption.  As the article title implies, this is a basic overview of what encryption is and how and why you might want to take advantage of this technology. 

What would be nice is a link to an Encryption 202 article.  The article would cover corporate compliance and policies.  When the information we work on contains private information, information containing names, addresses, email addresses, social security, or credit card information we expose ourselves and our companies to global risk.  When the computer or storage device contains proprietary information that would benefit a competitor, then you have potential losses that mount quickly. 

These loses can encompass government intervention, audits, lawsuits, fines and the degradation of your customer base.  When the mix includes these loses, then the stakes are much higher.  The first thing the regulators will look for is a Written Information Security Plan (WISP).  A WISP plan is security fire drill to prevent data loss and a checklist resource to be used in post breach situations.

A WISP plan ensures that your devices are protected by encryption in addition numerous other attributes, including human resources, legal, and insurance compliance.  We are not trying to make it hard for you to sleep, we just want you to follow the best practices in the industry.  Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help you to determine your risk quotient and build and maintain your WISP plan to match your risk.  Contact us today to see how we can help you.

Friday, October 21, 2011

Are Firewalls Really Necessary?

People that have some familiarity with networking know what a Firewall is.  A lot of people really do not know anything about them.  It is not unusual for me to run into people that do not know what a Firewall is or if they are using this technology. 



One of the great things about today’s technology providers is that they make it very easy, even for a novice, to set up networking.  From a professional’s perspective, it gets frustrating.  Most of us would like to see equipment and software fully configured with the maximum security when delivered.  It is a lot easier to start secure and ease restrictions on trusted sources, than to try and remediate problems and make a network or computer secure after the fact. 

One supplier indicated that only about 40% of the people they spoke with had a firewall.  And too many who do have firewalls are not monitoring them.  Which means your network could be under attack or even breached, and you would not even know it.

They symptoms may not be that obvious.  Unprotected networks and computers have a short lifespan of productive use.  It is estimated that an unprotected system connected to the Internet will be compromised (hacked) in about 20 minutes.

There is more to security than just a Firewall.  A Firewall can either be software or hardware.  Many use both.  And just like a chain is only as strong as its weakest link, so is security.  There are many aspects to consider, this biggest vulnerability is people.  We can be our own worst enemy at times. 

A Firewall is still an important part and it must be configured properly, updated and monitored to ensure it is doing the right job.

So what exactly is a Firewall?   As we explain this, think of “Traffic” as information or data that is transmitted back and forth.  An example might be a Google search engine request for the capital city of New Jersey and the response would be “Trenton”.  A firewall is a device that allows some traffic to enter your network while rejecting other traffic not specifically allowed or data traffic in response to your request.   The challenge is to configure the firewall to allow only the traffic that you need for your work, and not to allow bad traffic, like unauthorized users, or traffic that contains programs that will secretly grab your passwords, or worse, grab control of your system or your entire network.
Firewalls need to be updated regularly with updates that help it to
identify new threats and protect against new vulnerabilities.
Firewalls need to be monitored periodically to check for unauthorized access or attacks of your network.

Many Firewalls can be configured to create and/or accept secure connections that are often referred to as Virtual Private Networks (VPN).   When configured properly, these VPN connections allow safe and secure access to your network from a home office or while you are traveling.

So what value is your information to others?  If you use online banking, check your pension or medical information online, or use a username and password for anything, then you absolutely have information that others want. Those usernames and passwords give hackers access not only to information, but can give hackers access to other systems and other networks.

It is important to understand that if your computer is compromised, it can be turned into a system that distributes software, movies, songs, photos, documents or other types of materials that are illegal to distribute.

It might not be that obvious that you system has been compromised.  Has your Internet connection slowed to a crawl?  Have you noticed unusual charges on your bank statement?

If you do not already have a Firewall, or are not sure, or have not checked its status or have no idea about what I am talking about, then you should contact a professional to help you determine what will work for your needs and fit your budget.  If you do have and know what a Firewall is, then make sure its settings are still correct for your needs, it has been updated recently, and turn on and monitor logging to check the log files for suspicious activity. 

There are also services available for no-charge that will test your security.  Just make sure that you select these carefully and they are from a reputable source.  And above all else, do not give out any passwords or personal information to an unknown source.

Contact Dolvin Consulting today to see how we can help with your security issues.


Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.

Friday, October 14, 2011

ERP Pitfall- Modifications.

A sure recipe for obsolescence and trouble is making too many modifications to your Enterprise Resource Planning (ERP) system.



Minimize modifications. 

Why did you select new software in the first place?  Many times it was to take advantage of a fully integrated system with new features needed to stay competitive.  Then why risk making changes?  Was the selection the correct one in the first place?  How well do you trust your advisor now?

Did you select a new system because you lost confidence in your existing system (that was heavily modified)?  Do you need a new system, because of all the modifications needed to integrate your separate systems?  “It works, but just barely and we cross our fingers every time we run the system or have to make an update”.

What prevents you from taking advantage of your software supplier’s updates?  Too many modifications which locked you to a specific release/level, a specific support person/group/company?  Too much time to replicate the changes in the new release?  Does the new release have the features you already paid someone else to make?

Small changes can result in a domino effect of repercussions.  Who will document the new procedures?  Have you just sacrificed your compliance with modifications?  What security exposures were created by the changes you just made?

It is hard to say what constitutes a valid modification.  Certainly, you want to be able to service your customers, accept payments, ship orders, and replenish stock.  It varies based on the situation.  For one organization it is a necessity to function, in another it creates an unmanageable monster. 

A lot of companies change the stock forms to meet their needs.  Perhaps to include some additional information, branding and logos, and electronic distribution.  These are somewhat common and do not typically create too much risk. 

Other changes may include more risk, for example, altering the storage and usage of credit card information.  You want to make it easy for your customers to click and order, but did you just invalidate your PCI compliance?  Maybe you just wanted to your customers to be able to perform more self service.  Did you just open your system up to hackers and data breaches?  The media is full of reports about breaches.  How many records were exposed and what is your reporting responsibility?  

No one is suggesting that you make no changes, but we do suggest that you take the time to review and test the results.  Compare the proposed benefits and review them with your trusted advisor and software supplier.  Ensure that you have not prevented your organization from taking advantage of new features and functions.

Dolvin Consulting works with small to midsize businesses to help them understand and manage the risks and complexities of today’s ERP solutions.  Contact us today to see how we can help you find and manage your solution.

Wednesday, October 12, 2011

Data breach exposes 4.9 million Tricare patients

A data breach affecting 4.9 million Tricare beneficiaries began when a government contractor left backup computer tapes in his car after parking it in downtown San Antonio one day this month. The worker had been given the job of taking the tapes from one federal facility to another when they were stolen.



“How does it happen? ... At one level, the answer's totally carelessness, obviously,” Stahl said.

“Let's take a medical facility. They've got a heart that needs to be transplanted into a patent and they give it to somebody to take from Point A to Point B. Is that person going to stop for eight hours along the way?” he said.

We are human and as humans we are subject to errors.  Errors in behavior, errors in judgment, errors in concentration.  It was on the way.  I was only going to stop for a few minutes.  What could possibly happen?  Who would even know what to do with these tapes?  No one will know. 

It just is not possible to know at this point where the system broke down, but there is a steady trend of these incidents.  It could also be that we are just hearing about them more now.  Bottom line is that you cannot be too careful or take enough care when handling information of this type. 

A Written Information Security Plan (WISP) establishes the guidelines for handling and securing private information.  A plan is only as good as its implementation.  That is why a WISP plan is not a static document that collects dust on a shelf.  It is monitored, updated, and reviewed every year and at any fundamental change in business operations.   It is not a catch all, but it is a necessity that the government looks for in cases like these.  A good WISP plan creates a defensible position. 

Dolvin Consulting works with industry experts Cyber Security Auditors & Administrators (CSA2) to assess your risk exposure and develop the solutions needed to protect your information and to give you the tools to manage your risk.

When your questions outnumber your answers it is time to contact us.


Friday, October 7, 2011

Attorneys General continue to increase legal standards for data privacy compliance

Many have written about it and several have contemplated it -- whether states will adopt private data security standards, such as the Payment Card Industry Data Security Standards (PCI DSS), and use them as legal standards that owners and holders of personal information (PI) must comply with.



That’s exactly what the Massachusetts Attorney General did when it recently filed suit against Briar Group, LLC and alleged, among several other things, that Briar was not PCI compliant at the time of its data breach in November 2009, affecting 53,000 MasterCard and 72,000 Visa accounts.

PCI DSS are private data security standards created by the Payment Card Industry Security Standards Council that apply to all organizations collecting credit cards. The Complaint alleged that Briar’s failure to implement basic data security measures on its computer system allowed hackers to gain access to Briar’s customers’ credit and debit card information.

Please see full article for more information.

Briar ultimately settled with Massachusetts through a consent judgment with the following penalties, in part:
Briar Group to pay State of Massachusetts $110,000;
Establish a Written Information Security Program;
Maintain PCI compliance and verify same within fourteen days;
Revise password management process; and
Implement various network system changes.


So here is a point that Briar Group or any company that is responsible for private information about their employees, suppliers or customers should consider.  Having a Written Information Security Plan (WISP) in place "Before" a breach happens is a worthwhile investment. 

So much so, that if they were compliant with a working WISP plan, they might not have been breached in the first place.  Fire drills save lives, because people are prepared and can stay calm in an emergency. 

A WISP plan prepares an organization.  The "plan" ensures that a company follows industry best practices.  Nothing is perfect, but the heavy fines and bad publicity are minimized by being prepared.  A WISP plan creates a defensible position.

Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work with organizations that are worried about the threat of lawsuits related to the loss of private information and concerned about the loss of their customer base from the erosion of confidence that results from data breaches.

Contact us today to see how we can help you sleep better at night.