Joseph Conn reports: The potential legal liabilities from the unprecedented breach of some 80 million individuals’ records at Indianapolis-based insurance giant Anthem could entangle nearly 60 health insurance plans from Hawaii to Puerto Rico, legal experts say. More than 50 class-action lawsuits related to the breach already have been filed in less than a month. The plans could find…
Category: Of Note
Financial Industry Regulatory Authority Report on Cybersecurity Practices
via BeSpacific: FINRA Report on Cybersecurity Practices, February 2015 – Executive Summary: Like many organizations in the financial services and other sectors, broker-dealers (firms) are the target of cyberattacks. The frequency and sophistication of these attacks is increasing and individual broker-dealers, and the industry as a whole, must make responding to these threats a high priority….
It may look good, but that data breach report is not necessarily accurate
Two analyses of data breaches in 2014 have been released within the past month. One is Gemalto’s annual Breach Level Index report (pdf), which is based on 1,541 breach reports resulting in 1,023,108,267 breached records. The other is Risk Based Security’s Data Breach Quick View (pdf), which is based on 3,014 incidents exposing 1,068,191,345 records. How can an analysis that…
Say What? Required contents of notice in data breach notifications
Fer O’Neil did some comparisons of state laws on the content of notices. His write-up of what he found is well worth reading. Here’s a snippet from it: The first metric I looked at was the number of states and territories that had some required content of notice. I was a little surprised that 63% (31…
Microsoft Adopts ISO/IEC 27018 For Personal Data, Privacy Protection In Public Cloud
Quinten Plummer reports: Microsoft has adopted an international standard for certifying the security of its cloud offerings, making it the first major cloud services provider to do so, the company says. The company adopted the International Organization for Standardization and International Electrotechnical Commission’s standard 27018 to certify the security of its cloud offerings, using the…
CAVIRTEX shutting down following security issues
Katherine Fletcher reports: Canadian Bitcoin exchange CAVIRTEX announced Tuesday that it is ceasing operations next month following a possible security breach. The Calgary-based company will cease trading on March 20 and stop processing withdrawals on March 25, reported the Georgia Straight. CAVIRTEX said that on Sunday, “we found reason to believe that an older version of…