From the Federal Trade Commission: The Federal Trade Commission will require Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC to implement a robust information security program to settle charges that the companies’ failure to implement reasonable data security led to three large data breaches from 2014 to 2020 impacting more than 344…
Category: Of Note
General Hospital Cybersecurity Requirements Take Effect in New York
Mark Furnish and Jane M. Preston of Greenberg Traurig, LLP write: A new regulation related to cybersecurity program requirements for all New York general hospitals licensed under Article 28 of the Public Health Law (PHL) took effect Oct. 2, 2024. All general hospitals must comply with the new provisions within one year of the adoption…
Qatar Financial Centre issues company $150,000 fine for data breach
Asmahan Qarjouli reports: The Qatar Financial Centre’s (QFC) Data Protection Office (DPO) has issued a $150,000 fine on a company under its license following a data breach that enabled access to personal data. The measures, the first of their kind in Doha, were taken by DPO on Tuesday following an investigation that detected breaches of…
Ex-Uber CISO Requests a New, ‘Fair’ Trial
Kristina Beek reports: Former Uber CISO Joseph Sullivan, convicted in 2023 of trying to cover up a data breach, is seeking a new trial, citing procedures omissions from his original trial that his lawyers said tainted the verdict. Sullivan was initially convicted on charges related to Uber’s 2016 data breach and was sentenced to three years of…
Australia Introduces First Standalone Cybersecurity Law
James Coker reports: The Australian government has introduced the country’s first standalone cybersecurity law to Parliament. The new legislation aims to better protect citizens and organizations against a heightened geopolitical and cyber threat environment. The Cyber Security Bill 2024 covers a range of areas, including mandating minimum cybersecurity standards for IoT devices and mandatory ransomware reporting for critical infrastructure…
Water supplier American Water Works says systems hacked
Kate Gibson reports: American Water Works — a supplier of drinking water and wastewater services to more than 14 million people — on Monday said hackers had breached its computer networks and systems, prompting it to pause billing to customers. The Camden, New Jersey-based utility became aware of the unauthorized activity on Thursday, and took…