Data Security & Privacy

Lawmakers Press SEC to Make Companies Disclose Details of Cyber-Attacks

Posted on

The Wall Street Journal reported today that a group of U.S. lawmakers are pressing the Securities and Exchange Commission to make corporations, detail in their quarterly reports, any “material” cyber-attacks that they experience.  The purpose of this required disclosure is to create more transparency amongst regular investors.  The pressure is a result of the recent massive data […]

Business Law

Amazon’s Data Center Outage Highlights Cloud Computing Risks

Posted on

“Redundancy, Redundancy, Redundancy.” Any good risk management tool is predicated around this mantra, and yet today, in a highly unusual incident, Amazon Web Services (AWS) servers’ went blank.  Client sites from Foursquare to Reddit were rendered inaccessible Thursday, and there is no communication from AWS personnel as to why the system went down.  I wonder how much […]

Business Law

Como se dice “le Doit al’Oubli” en Espanol? “Right to be Forgotten” Debate Emerges in Spain

Posted on

A few weeks ago I blogged about how the French government is demanding information repository companies, like Google, Yahoo, et al, allow its citizenry to be completely wiped from oblivion on the Internet.  I think what is most intriguing about “le Doit al ‘Oubli” is how it highlights the distinct differences between European and American viewpoints […]

Data Security & Privacy

Round 2: NLRB Goes After Private Company for Reprimanding Reporter’s Twitter Comments

Posted on

The increase in frequency over firings related to public comments posted on social media sites is an emerging area in employment/labor law.  Recently, I followed the case of a Connecticut ambulance company who fired its employee over rants she made on Facebook about her supervisor.  The National Labor Relations Board (“NLRB”) asserted that such communications […]

Business Law

Lesson from Epsilon E-Mail Breach: Better Data Governance Need by Service Providers

Posted on

  Due to a “massive” breach by the marketing firm Epsilon, an unknown amount of names and e-mail addresses were exposed that could potentially lead to phishing attacks by organized criminal elements.  Epsilon is a service provider which handles e-mail marketing lists for hundreds of clients, including giants like JPMorgan Chase, Citibank, Target, and Walgreens.    The […]

Business Law

Rethinking “Personal Identifiable Information (PII)” and Encryption

Posted on

Most regulations define the term “personal identifiable information” to mean information about an individual that is recorded, which includes things like: name, address, e-mail, age, sex, marital status, social security number, health care history, religious or political beliefs, race, nationality, ethnicity, origin…you get my point.  However, with the evolving landscape of technological innovations related to online behavioral […]