Data from the Blackbaud incident continues to dribble in. Marco A. De Felice continues to track the incident as it impacted the education sector and he has another update: UPDATE (3) of 30.04.2021 Total number of people involved 7,975,221 (+66,641) In the update of 30.04.2021, 7 new Institutions affected by the Blackbaud Data Breach are…
RTF Report: Combatting Ransomware A Comprehensive Framework for Action: Key Recommendations from the Ransomware Task Force
From the Institute for Security & Technology: A Comprehensive Framework for Action Ransomware is no longer just a financial crime; it is an urgent national security risk that threatens schools, hospitals, businesses, and governments across the globe. This is not a problem that any one entity can solve. Over 60 experts from industry, government, law…
Seventh Annual Data Security Incident Response Report Released – Disruption and Transformation
Theodore J. Kobus III of BakerHostetler writes: Welcome to our seventh Data Security Incident Response Report (DSIR). It has been quite a year from many perspectives. Thank you to everyone we have continued to partner and work with to create this report. We are excited to soon launch a new digital platform version, and we intend…
UK: HMRC outlines late-filing penalty notices data breach
ICAEW [ Institute of Chartered Accountants in England and Wales] members in practice have been among thousands of agents who have received late-filing penalty notices which are not for their clients. HMRC has investigated and provided an update on what went wrong. […] The total number of individual penalty notices sent to the wrong agent…
NYDFS Issues Report on the SolarWinds Attack and Covered Entities’ Responses
Kate Hanniford of Alston & Bird writes: Following the SolarWinds cyber espionage attack (the “Attack”) and the resulting focus on supply chain risk, the New York Department of Financial Services (NYDFS) has issued a report detailing the impact on and responses by its regulated covered entities to the Attack. Although there have been no reported instances of…
Implementing the HIPAA Security Rule: Call for Comments on NIST SP 800-66, Revision 1
Implementing the HIPAA Security Rule: Call for Comments on NIST SP 800-66, Revision 1 The National Institute for Standards and Technology (NIST) is planning to update the NIST Special Publication (SP) 800—66, Revision 1, An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (“Resource Guide”). NIST is seeking stakeholder input…